> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.itential.com/itential-gateway/4/rbac/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server. # RBAC in Gateway > Overview of role-based access control configuration for Itential Gateway, including roles, groups, and user management. ## Role-based authorization and access This article provides information on role-based access control (RBAC) for Itential Gateway, which entails configuration of roles and groups for users of Gateway. In the context of Gateway, a role enables user access to a single route or multiple routes. They are auto-generated at the time of server initialization using information provided for each route found in the Gateway API documentation. The name of a role is derived using the tag name (i.e., **modules, playbooks, nornir, terraform**, etc.) defined for a set of routes along with the action categories **read, write, exec, and history**. Note that multiple routes can fall under a given action category. ### Action categories These categories specify the actions that the role allows to be performed. | Action | Description | | ------- | ----------------------------------------------- | | read | User has access to read API calls. | | write | User has access to write API calls. | | exec | User has access to execute API calls. | | history | User has access to execution history API calls. | ### Sample role names The following provides a sample list of role names. * `modules:read` * `playbooks:write` * `terraform:exec` * `nornir:history` Along with roles, RBAC groups contain a set of users. Users that are members of a particular group will have access to the routes defined by the roles that have been configured for the group. Users and roles can be members of multiple groups. > **Warning** > > The RBAC group `admin` is automatically created by the Gateway server upon the first boot up of a release with RBAC support. When doing an upgrade from a previous release that does not contain RBAC support, all existing users will automatically be added to the admin group upon first boot up of the server. The admin group contains all roles that are made available by the server. Users that are members of the admin group have access to all available routes. ## Manage users and groups in Gateway Groups are used to manage users who need the same permissions or restrictions. A summary of how to create, edit, and delete groups is presented below, along with how to manage user roles and permission sets that control access to areas and features within Gateway. ### Create groups To create groups within Gateway: #### Log in as an administrator Log in to Gateway as an administrator (a user with the `admin` role). #### Navigate to Authorization Navigate to **Authorization**. #### Select Groups Select **Groups** from the sidenav menu on the left. A list of all defined groups is displayed. #### Open the Create Group dialog Click **View All Groups** and select the blue plus icon **(+)** in the top left corner of the page. The **Create Group** dialog displays. #### Enter group information Enter the new group information, i.e. name and description. #### Assign roles Assign appropriate roles to the group. #### Save the group Click **Save** to finalize your changes. ![](/_fern-img/20ed750602ac7c69f467d85d4a73fea99912197c18114e54f8159e070377229c.webp) ### Edit groups To edit groups within Gateway: #### Log in as an administrator Log in to Gateway as an administrator (a user with the `admin` role). #### Navigate to Authorization Navigate to **Authorization**. #### Select Groups Select **Groups** from the sidenav menu. A list of all defined groups is displayed. #### Locate the group Locate the group in the list. You can filter the list by typing in the **Search Groups** field. #### Select and edit the group Select the group in the list to view or edit. #### Edit the description Edit the description, as desired. #### Edit roles and members Edit roles and members, as desired. #### Save your changes Click **Save** to finalize your changes. ![](/_fern-img/c110ae25be8f6473018bd04a8bf3ced7c47e1d5dfcc4f89a6267e003b139a507.webp)![](/_fern-img/e4cc7b9af93b92c8ae29905357c3699913f2567e7052a85e7dd04a5272c3a38c.webp) ### Delete groups Only Gateway groups created by end users can be deleted. The `admin` group cannot be deleted or modified. > **Warning** > > This is a hard delete. Deleting a group will remove the role from all users and groups assigned to it. #### Select the group Select the group. #### Open the options menu Click the blue icon (stacked dots) in the upper-right corner of the page to reveal the Clone and Delete options. #### Select Delete Select **Delete**. A prompt displays to confirm deletion of the group from the application. #### Confirm deletion Click **Delete**. ### Edit users To edit users within Gateway: #### Log in as an administrator Log in to Gateway as an administrator (a user with the `admin` role). #### Navigate to Users Navigate to **Users**. #### Locate the user Locate the user in the list. Optionally, filter the list by typing in the **Search Users** field and pressing **Enter**, or click the search icon. #### Select the user Select the appropriate user from the list to view or edit. #### Edit attributes Edit attributes, as desired. #### Edit groups Edit **Groups**, as desired. #### Save your changes Click **Save** to finalize your changes. ![](/_fern-img/41076cbcbb33737cbd663d964baa14ad0e52949fca54281145cb3e85ed02dc05.webp)![](/_fern-img/fedc5303c9cc5aae58f04be0b74b870d7aa44bb6cb90637c6e5e78909341cf06.webp) ### Add LDAP users and groups For LDAP users to appear in the Itential Gateway **Authorization Users** list, you will need to: * Manually create each LDAP user; make sure the username matches the LDAP username. * Manually create the groups in Gateway to which the LDAP users will be added. Groups are added as members to a role, and group members are listed as user members for the role. Therefore, once you have created the LDAP users and LDAP groups manually in Gateway, and assigned all necessary permissions to each group, whenever an LDAP user of the same matching username logs in, that user is automatically added to the group to which the user is a member and whatever role permissions are assigned to the group. > Overview of role-based access control configuration for Itential Gateway, including roles, groups, and user management.