Roles and permissions reference
Roles determine what a user or service account can do within Itential Cloud and its licensed components. All available roles are listed below, organized by product and application.
To learn how Itential Cloud uses roles to govern permissions, see Manage users and groups.
Roles marked with an asterisk (*) are currently non-functional as they undergo further development.
Cloud API
Roles in the Cloud API collection govern permissions for the Itential Cloud portal UI and API.
FlowAI roles
FlowAI uses application-level permissions to control access to agent projects, decorators, and agent sessions. These permissions are independent of project-level roles such as Owner, Editor, and Viewer, and must be explicitly assigned. For information about project-level roles, see Agent Projects.
Grant FlowAI access
FlowAI permissions span four applications: Agent Projects, Agent Sessions, Tool Registry, and Model Registry. Grant permissions for the application and action a user actually needs, rather than as a single bundle. For example, managing Model Registry profiles doesn’t require any Agent Sessions permissions, and monitoring sessions doesn’t require any Agent Projects permissions.
Agent Projects
Agent Sessions
Model Registry
Gateway Manager
Roles in the Gateway Manager collection govern permissions for the Gateway Manager UI and API.
Inventory Manager
Roles in the Inventory Manager collection govern permissions for the Inventory Manager UI and API.
Itential Platform
Roles in the Itential Platform collection govern permissions for a specific Itential Platform instance.