Roles and permissions reference

Roles determine what a user or service account can do within Itential Cloud and its licensed components. All available roles are listed below, organized by product and application.

To learn how Itential Cloud uses roles to govern permissions, see Manage users and groups.

Roles marked with an asterisk (*) are currently non-functional as they undergo further development.

Cloud API

Roles in the Cloud API collection govern permissions for the Itential Cloud portal UI and API.

RoleDescription
clusters:readView which cluster Itential Platform instances are assigned to.
deployments:deleteDelete Itential Platform instances.
groups:readView groups.
groups:writeCreate, update, and delete groups.
insights:viewAccess Insights.
jobs:view-detailView job details. See Access control in Job Viewer.
jobs:view-metadataView all job and task information except variables. See Access control in Job Viewer.
organizations:readRetrieve license information including the current Itential Platform instance limit. Required to create new Itential Platform instances.
*organizations:writeN/A
security:readView security information of user accounts.
security:writeEdit security permissions of user accounts.
training-deployments:readView Itential Academy training environments. Required to launch a training environment.
training-deployments:writeCreate and delete Itential Academy training environments. Required to launch a training environment.
users:readView user accounts.
users:writeCreate, update, and delete user accounts.

Gateway Manager

Roles in the Gateway Manager collection govern permissions for the Gateway Manager UI and API.

RoleDescription
certificate:readView certificates.
certificate:createAdd certificates to the certificate store.
certificate:updateUpdate the certificate alias.
certificate:deleteDelete a certificate.
gateway:readView a specific gateway. Requires assignment to an authorization group with gateway:read that is assigned to the gateway.
gateway:createCreate a gateway.
gateway:updateUpdate a specific gateway. Requires assignment to an authorization group with gateway:update that is assigned to the gateway.
gateway:deleteDelete a specific gateway. Requires assignment to an authorization group with gateway:delete that is assigned to the gateway.
service-group:readView service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:read that is assigned to the gateway.
service-group:createCreate a service group associated with a specific gateway. Requires assignment to an authorization group with service-group:create that is assigned to the gateway.
service-group:updateUpdate service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:update that is assigned to the gateway.
service-group:deleteDelete service groups associated with a specific gateway. Requires assignment to an authorization group with service-group:delete that is assigned to the gateway.
service:runRun a service via the runService workflow task or API. Requires assignment to an authorization group with service:run assigned to the gateway or a service group.
service:readView a specific service via the runService workflow task or API. Requires assignment to an authorization group with service:read assigned to the gateway or a service group.

Inventory Manager

Roles in the Inventory Manager collection govern permissions for the Inventory Manager UI and API.

RoleDescription
inventory:readView inventories, nodes, and actions.
inventory:createCreate inventories, nodes, and actions.
inventory:updateModify existing inventory resources and manage actions.
inventory:deleteDelete inventories, nodes, and actions.
inventory:runExecute actions against inventory nodes.

Itential Platform

Roles in the Itential Platform collection govern permissions for a specific Itential Platform instance.

Admin Essentials

RoleDescription
adapters:deleteDelete adapters, integrations, and integration models.
adapters:readView information about adapters, integrations, and integration models.
adapters:writeCreate and update adapters, integrations, and integration models.
groups:readView user groups.
indexes:readView information in Admin Essentials.
prebuilts:deleteUninstall pre-builts.
prebuilts:readView installed pre-builts.
prebuilts:writeInstall pre-builts.
prebuilts:repositories:deleteDelete pre-built repositories.
prebuilts:repositories:readView pre-built repositories.
prebuilts:repositories:writeCreate and edit pre-built repositories.
roles:readView user roles.
tags:deleteDelete tags.
tags:readView tags.
tags:writeCreate and edit tags.
users:readView user accounts.

Automation Studio

RoleDescription
forms:adminCreate, update, and delete form groups.
forms:deleteDelete forms.
forms:readView forms.
forms:writeCreate and edit forms.
mops:deleteDelete command templates.
mops:readView command templates.
mops:runExecute command templates.
mops:writeCreate and edit command templates.
templates:deleteDelete templates.
templates:readView templates.
templates:writeCreate and edit templates.
transformations:deleteDelete transformations.
transformations:readView transformations.
transformations:writeCreate and edit transformations.
workflows:adminFull control of workflows.
workflows:deleteDelete workflows.
workflows:readView workflows.
workflows:writeCreate and edit workflows.

Configuration Manager

RoleDescription
compliance:readView device compliance reports.
compliance:runRun compliance checks against devices.
configurations:readView current device configurations.
configurations:writeEdit current device configurations.
configurations:golden:deleteDelete golden configurations.
configurations:golden:readView golden configurations.
configurations:golden:writeCreate and edit golden configurations.
configurations:parsers:deleteDelete configuration parsers.
configurations:parsers:readView configuration parsers.
configurations:parsers:writeCreate and edit configuration parsers.
configurations:templates:deleteDelete configuration templates.
configurations:templates:readView configuration templates.
configurations:templates:writeCreate and edit configuration templates.
devices:backups:deleteDelete device backups.
devices:backups:readView device backups.
devices:backups:writeCreate, edit, and import device backups.
devices:groups:deleteDelete device groups.
devices:groups:readView device groups.
devices:groups:writeCreate and edit device groups.
devices:readView devices.
devices:writeEdit devices.
pins:deleteDelete pinned items.
pins:readView pinned items.
pins:writeCreate and edit pinned items.

Dashboard

RoleDescription
bookmarks:deleteDelete bookmarks.
bookmarks:readView bookmarks.
bookmarks:writeCreate and edit bookmarks.
system:readView system information about Itential Platform.

NSO Manager

RoleDescription
nso:cdb:adminSet items in NACM groups.
nso:cdb:readExecute REST queries.
nso:cdb:writeSet leaf values and execute REST actions.
nso:commitqueue:readView the commit queue.
nso:commitqueue:writeEdit the commit queue.
nso:devices:readView devices.
nso:devices:writeRun actions and commands on devices.
nso:groups:readView authorization groups.
nso:neds:readView NEDs.

Operations Manager and Workflow Engine

RoleApplicationDescription
jobs:adminOperations ManagerCreate, view, update, and delete job groups.
jobs:deleteOperations Manager and Workflow EngineCancel jobs.
jobs:readOperations Manager and Workflow EngineView jobs.
jobs:writeOperations Manager and Workflow EngineCreate, start, and work jobs.
tasks:adminOperations ManagerFull control of any tasks.
tasks:readOperations ManagerView tasks.
tasks:workOperations ManagerInteract with actionable tasks.
workflows:engine:readWorkflow EngineView the status of Workflow Engine.
workflows:engine:writeWorkflow EngineActivate and deactivate Workflow Engine.
workflows:triggers:deleteOperations ManagerDelete triggers.
workflows:triggers:readOperations ManagerView triggers.
workflows:triggers:writeOperations ManagerCreate and edit triggers.

Service Catalog and Service Catalog Builder

RoleApplicationDescription
services:instances:deleteService Catalog BuilderDelete services.
services:instances:orderService CatalogCreate and invoke service orders.
services:instances:readService CatalogView services.
services:instances:writeService Catalog BuilderCreate and edit services.
services:models:deleteService CatalogDelete service models.
services:models:readService CatalogView service models.
services:models:writeService CatalogCreate and edit service models.

Miscellaneous roles

RoleApplicationDescription
AGManager:adminAG ManagerDiscover and interact with modules, scripts, and playbooks sourced from IAG. Required to view IAG-sourced content.
cloud:config:readItential Cloud PortalView Itential Platform roles available for assignment.
cloud:config:writeItential Cloud PortalAdd, remove, and update Itential Platform roles.
cloud:directconnect:adminDirect ConnectConnect to IAG instances from Itential Platform. Required to view IAG-sourced content.
cloud:encrypt:readApp-EncryptUse encryption features in Itential Platform.
datasets:deleteData SetsDelete a data set export.
datasets:readData SetsView and search data set exports.
datasets:writeData SetsCreate a data set export.
search:readSystem SearchSearch for resources using the System Search feature.
tags:assignMultipleAssign tags to resources.