I wanted to share that these roles are a bug in the system reported to me from the Acumatica RnD team.
These roles (BRANCH CAP, BRANCH HQ, BRANCH VA, DEMO, EMPLOYEE, SALES, SUPPORT, etc.) are Sales Demo roles that were unintentionally included in an earlier version of the PDF Annotator integration customization (maybe some other one too). When that customization was published, the system created these roles.
Although the PDF Annotator customization is not in the Customization Projects (SM204505) list for my tenant, unpublishing or removing a customization does not delete database entities that were created by it (including roles), so the roles remain in the system.
Impact and cleanup:
- The presence of these roles alone does not grant any extra permissions; users only get additional access if they are explicitly assigned to these roles.
- As a cleanup step, please:
- Open User Roles (SM201005) / User Role Descriptions.
- Locate the Sales Demo roles (BRANCH CAP, BRANCH HQ, BRANCH VA, CONSULTANT, DEMO, EMPLOYEE, PURCHASING, READONLY, SALES, SALESMGR, SERVICEMGR, SERVICETECH, SHIPPING, SUPPORT).
- Make sure no users are assigned to them.
- Delete these roles from the system.
This is the recommended workaround for this issue.
Starting from 26R1, PDF Annotator will be delivered as part of the product core (not as a separate customization) with a dedicated built‑in security role. In this model, the integration will no longer include Sales Demo roles, so this problem will not reoccur on future versions.