A role is a named set of permissions. Three exist always and cannot be deleted: Admin, Member, Guest. All three are editable, and you can add your own.
What a role controls
The memory default matters: without it, a new category would silently be invisible to a role, or silently visible. You choose which.
Creating a role
Build it on the Roles page, then apply it on the Members page.
How permissions are enforced
Roles rank as admin, member, guest. The rank is what the system checks when deciding whether an action is allowed.
Guests
Guests are for people who need to see some of a directory without being part of it — a client, an advisor. Give them read on the categories they need and nothing else.