Roles and permissions reference

Roles determine what a user or service account can do within Itential Cloud and its licensed components. All available roles are listed below, organized by product and application.

To learn how Itential Cloud uses roles to govern permissions, see Manage users and groups.

Roles marked with an asterisk (*) are currently non-functional as they undergo further development.

Cloud API

Roles in the Cloud API collection govern permissions for the Itential Cloud portal UI and API.

RoleDescription
clusters:readView which cluster Itential Platform instances are assigned to.
deployments:deleteDelete Itential Platform instances.
groups:readView groups.
groups:writeCreate, update, and delete groups.
insights:viewAccess Insights.
jobs:view-detailView job details. See Access control in Job Viewer.
jobs:view-metadataView all job and task information except variables. See Access control in Job Viewer.
organizations:readRetrieve license information including the current Itential Platform instance limit. Required to create new Itential Platform instances.
*organizations:writeN/A
security:readView security information of user accounts.
security:writeEdit security permissions of user accounts.
training-deployments:readView Itential Academy training environments. Required to launch a training environment.
training-deployments:writeCreate and delete Itential Academy training environments. Required to launch a training environment.
users:readView user accounts.
users:writeCreate, update, and delete user accounts.

FlowAI roles

FlowAI uses application-level permissions to control access to agent projects, decorators, and agent sessions. These permissions are independent of project-level roles such as Owner, Editor, and Viewer, and must be explicitly assigned. For information about project-level roles, see Agent Projects.

NameDescription
agents:readAccess to Agent Projects and agents. Users see only the projects they have project-level membership on. Without this permission, Agent Projects isn’t visible in the UI even if a user has project-level membership.
agents:writeRequires agents:read. Create and edit agents and projects, or import a project package. Doesn’t grant access to any existing project; project-level membership is governed separately. For information, see
agents:deleteRequires agents:read. Delete agents and projects permanently.
agents:adminAccess to all /admin/-prefixed endpoints. Grants administrative access to every agent project regardless of project-level membership, so admins can manage orphaned or inaccessible projects. All actions are recorded in the audit log.
tool-decorators:readView available decorators when creating or editing an agent, and export decorator definitions via API.
tool-decorators:writeIncludes tool-decorators:read. Create, clone, and import decorator definitions. Available only in the API.
tool-decorators:deleteIncludes tool-decorators:read. Delete decorator definitions via API.
sessions:readAccess to Agent Sessions. Required to view any session. Without this permission, Agent Sessions isn’t visible in the UI.
sessions:writePause, resume, and cancel sessions. Requires sessions:read.
sessions:deleteDelete sessions permanently, including the session record and audit trail. Requires sessions:read.
tool-registry:readAccess tool information.
tool-registry:discoverDiscover tools.
provider-profiles:readView all provider profiles in Model Registry.
provider-profiles:writeCreate and edit all provider profiles in Model Registry.
provider-profiles:deleteDelete all provider profiles in Model Registry.

Grant FlowAI access

FlowAI permissions span four applications: Agent Projects, Agent Sessions, Tool Registry, and Model Registry. Grant permissions for the application and action a user actually needs, rather than as a single bundle. For example, managing Model Registry profiles doesn’t require any Agent Sessions permissions, and monitoring sessions doesn’t require any Agent Projects permissions.

Agent Projects

To do thisGrant
Create and edit agents and projects, and browse available tools and decoratorsagents:read, agents:write, tool-decorators:read, tool-registry:read, tool-registry:discover
Also create, clone, and delete decoratorstool-decorators:write, tool-decorators:delete
Also manage any project regardless of membership, including orphaned or inaccessible onesagents:delete, agents:admin

Agent Sessions

To do thisGrant
Monitor agent session activitysessions:read
Also pause, resume, cancel, and delete sessionssessions:write, sessions:delete

Model Registry

To do thisGrant
View provider profilesprovider-profiles:read
Also create, edit, and delete profilesprovider-profiles:write, provider-profiles:delete

Gateway Manager

Roles in the Gateway Manager collection govern permissions for the Gateway Manager UI and API.

RoleDescription
certificate:readView certificates.
certificate:createAdd certificates to the certificate store.
certificate:updateUpdate the certificate alias.
certificate:deleteDelete a certificate.
gateway:readView a specific gateway. Requires assignment to an authorization group with gateway:read that is assigned to the gateway.
gateway:createCreate a gateway.
gateway:updateUpdate a specific gateway. Requires assignment to an authorization group with gateway:update that is assigned to the gateway.
gateway:deleteDelete a specific gateway. Requires assignment to an authorization group with gateway:delete that is assigned to the gateway.
service-group:readView service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:read that is assigned to the gateway.
service-group:createCreate a service group associated with a specific gateway. Requires assignment to an authorization group with service-group:create that is assigned to the gateway.
service-group:updateUpdate service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:update that is assigned to the gateway.
service-group:deleteDelete service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:delete that is assigned to the gateway.
service:runRun a service via the runService workflow task or API. Requires assignment to an authorization group with service:run assigned to the gateway or a service group.
service:readView a specific service via the runService workflow task or API. Requires assignment to an authorization group with service:read assigned to the gateway or a service group.

Inventory Manager

Roles in the Inventory Manager collection govern permissions for the Inventory Manager UI and API.

RoleDescription
inventory:readView inventories, nodes, and actions.
inventory:createCreate inventories, nodes, and actions.
inventory:updateModify existing inventory resources and manage actions.
inventory:deleteDelete inventories, nodes, and actions.
inventory:runExecute actions against inventory nodes.

Itential Platform

Roles in the Itential Platform collection govern permissions for a specific Itential Platform instance.

Admin Essentials

RoleDescription
adapters:deleteDelete adapters, integrations, and integration models.
adapters:readView information about adapters, integrations, and integration models.
adapters:writeCreate and update adapters, integrations, and integration models.
groups:readView user groups.
indexes:readView information in Admin Essentials.
prebuilts:deleteUninstall pre-builts.
prebuilts:readView installed pre-builts.
prebuilts:writeInstall pre-builts.
prebuilts:repositories:deleteDelete pre-built repositories.
prebuilts:repositories:readView pre-built repositories.
prebuilts:repositories:writeCreate and edit pre-built repositories.
roles:readView user roles.
tags:deleteDelete tags.
tags:readView tags.
tags:writeCreate and edit tags.
users:readView user accounts.

Configuration Manager

RoleDescription
compliance:readView device compliance reports.
compliance:runRun compliance checks against devices.
configurations:readView current device configurations.
configurations:writeEdit current device configurations.
configurations:golden:deleteDelete golden configurations.
configurations:golden:readView golden configurations.
configurations:golden:writeCreate and edit golden configurations.
configurations:parsers:deleteDelete configuration parsers.
configurations:parsers:readView configuration parsers.
configurations:parsers:writeCreate and edit configuration parsers.
configurations:templates:deleteDelete configuration templates.
configurations:templates:readView configuration templates.
configurations:templates:writeCreate and edit configuration templates.
devices:backups:deleteDelete device backups.
devices:backups:readView device backups.
devices:backups:writeCreate, edit, and import device backups.
devices:groups:deleteDelete device groups.
devices:groups:readView device groups.
devices:groups:writeCreate and edit device groups.
devices:readView devices.
devices:writeEdit devices.
pins:deleteDelete pinned items.
pins:readView pinned items.
pins:writeCreate and edit pinned items.

Dashboard

RoleDescription
bookmarks:deleteDelete bookmarks.
bookmarks:readView bookmarks.
bookmarks:writeCreate and edit bookmarks.
system:readView system information about Itential Platform.

Miscellaneous roles

RoleApplicationDescription
AGManager:adminAG ManagerDiscover and interact with modules, scripts, and playbooks sourced from Gateway. Required to view Gateway-sourced content.
cloud:config:readItential Cloud PortalView Itential Platform roles available for assignment.
cloud:config:writeItential Cloud PortalAdd, remove, and update Itential Platform roles.
cloud:directconnect:adminDirect ConnectConnect to Gateway instances from Itential Platform. Required to view Gateway-sourced content.
cloud:encrypt:readApp-EncryptUse encryption features in Itential Platform.
datasets:deleteData SetsDelete a data set export.
datasets:readData SetsView and search data set exports.
datasets:writeData SetsCreate a data set export.
search:readSystem SearchSearch for resources using the System Search feature.
tags:assignMultipleAssign tags to resources.
workcenter:writeWork CenterAccess Work Center and act on manual tasks in your queue.

NSO Manager

RoleDescription
nso:cdb:adminSet items in NACM groups.
nso:cdb:readExecute REST queries.
nso:cdb:writeSet leaf values and execute REST actions.
nso:commitqueue:readView the commit queue.
nso:commitqueue:writeEdit the commit queue.
nso:devices:readView devices.
nso:devices:writeRun actions and commands on devices.
nso:groups:readView authorization groups.
nso:neds:readView NEDs.

Operations Manager and Workflow Engine

RoleApplicationDescription
jobs:adminOperations ManagerCreate, view, update, and delete job groups.
jobs:deleteOperations Manager and Workflow EngineCancel jobs.
jobs:readOperations Manager and Workflow EngineView jobs.
jobs:writeOperations Manager and Workflow EngineCreate, start, and work jobs.
tasks:adminOperations ManagerFull control of any tasks.
tasks:readOperations ManagerView tasks.
tasks:workOperations ManagerInteract with actionable tasks.
workflows:engine:readWorkflow EngineView the status of Workflow Engine.
workflows:engine:writeWorkflow EngineActivate and deactivate Workflow Engine.
workflows:triggers:deleteOperations ManagerDelete triggers.
workflows:triggers:readOperations ManagerView triggers.
workflows:triggers:writeOperations ManagerCreate and edit triggers.

Service Catalog and Service Catalog Builder

RoleApplicationDescription
services:instances:deleteService Catalog BuilderDelete services.
services:instances:orderService CatalogCreate and invoke service orders.
services:instances:readService CatalogView services.
services:instances:writeService Catalog BuilderCreate and edit services.
services:models:deleteService CatalogDelete service models.
services:models:readService CatalogView service models.
services:models:writeService CatalogCreate and edit service models.

Studio

RoleDescription
forms:adminCreate, update, and delete form groups.
forms:deleteDelete forms.
forms:readView forms.
forms:writeCreate and edit forms.
mops:deleteDelete command templates.
mops:readView command templates.
mops:runExecute command templates.
mops:writeCreate and edit command templates.
templates:deleteDelete templates.
templates:readView templates.
templates:writeCreate and edit templates.
transformations:deleteDelete transformations.
transformations:readView transformations.
transformations:writeCreate and edit transformations.
workflows:adminFull control of workflows.
workflows:deleteDelete workflows.
workflows:readView workflows.
workflows:writeCreate and edit workflows.