Note: The ENS App and ENS Explorer are both currently on Sepolia testnet. Behaviour and available features may change before mainnet.
Every ENSv2 name has a set of roles controlling who can do what — renew it, change its resolver, manage subnames, even remove it. The Roles tab on a name's page shows who holds which permissions. These roles cover the name itself; who can edit its records is controlled separately by the resolver's own roles — see who can edit my records? Resolver roles in ENS Explorer.
Reading the Roles tab
The tab lists each user (an address or name) against the roles they hold, with Admin and Manager columns showing the level each role is held at. A freshly registered name has one role holder: you.
You start with three roles: Can Transfer at Admin only, and Set Resolver and Set Subregistry at both levels — five ticks across the two columns. Nothing else is set until you grant it.
The table shows only roles assigned directly on this name — inherited or parent-level access doesn't appear here. Each name's own Roles tab is the source of truth for its directly-assigned permissions.
One role behaves differently from the rest: Can Transfer shows a tick under Admin and nothing under Manager — that's correct, not a missing value. It's set when the name is registered and can't be granted afterwards, which is why it doesn't appear in the Add user form.
Below the table, a Role History section lists role changes on the name, with Date, Account, Changes and Roles columns. Until a role changes hands it shows No role history found.
What do Manager and Admin mean?
Manager means the user can carry out that action themselves — a Renew manager can extend the name, an Unregister manager can delete it.
Admin means the user controls who holds that permission: they can grant it to others or take it away. The Admin tick alone doesn't perform the action — but an Admin can grant the permission to themselves, so treat both levels as powerful.
Granting a role
As the owner:
Open your name's Roles tab. Under Parent registry roles, click Add user.
Enter the person's name or address.
Tick the roles to grant — each has a plain description: Renew ("Can renew name registrations"), Set Subregistry, Set Resolver, and Unregister ("Can unregister (delete) the name") — choosing Manager and/or Admin for each.
Click Save. Explorer shows the estimated cost; click Start, then Open wallet, and approve the transaction.
The ticks only become active for roles the name currently holds to pass on, so some may appear greyed out — enter the user's address first to make the form live.
Grant carefully: Unregister — at either level — ultimately lets the holder delete the name.
Revoking a role
To revoke a role, open the name's Roles tab and click the icon at the end of the user's row to open their role panel. Their current roles show as ticked boxes — untick a role to remove just that one, or click Remove user to strip every role at once. For the name's owner, Explorer warns that removing or changing roles can lock you out of managing the name. Click Save; Explorer shows the transaction (a Revoke roles step with the estimated cost), then click Start, Open wallet, and approve.
Common questions
Anyone can extend my name — is that a problem?
No. Extending only adds registration time; it never changes who owns or controls the name.
I see a Fuses tab instead of Roles — why?
Older names wrapped under ENSv1 use fuses (one-way permission locks) instead of roles. The sidebar shows whichever system applies to the name you're viewing.
