Access to the Manager is controlled by Context Access ACL entries. If there is at least one ACL entry of that type connecting a user group (e.g., Administrator) to the 'mgr' context, that context is "protected."
The default ACL entries should cover that unless you've deleted one.
Once that condition exist, the only users who can log in to the Manager are users who belong to a user group that has been given access to the 'mgr' context with a Context Access ACL entry.
IOW, you have a Context Access ACL entry with a context of 'mgr' that shouldn't be there.
Tip: Forget about roles. Put users with different rights in different user groups and put nobody but admin Super Users in the Administrator group. A user can belong to more than one user group.
If you have the time, here's an hour's worth of info on MODX security permissions:
http://modxpo.eu/2012/schedule/sessions/modx-revolution-security-permissions-system