To ensure that the Appranix managed service principal has all necessary permissions to discover, protect and recover either in the same region or in a different region, we made sure that we introduce few custom roles and group permissions specific to each operation under the custom roles and assign it back to the service principal. 

The Role Names are carefully designed to be self-explanatory so that our customers can be sure of why particular permission is assigned to the service principal.

The details on the roles and the permission are given in this document