Roles¶
Overview¶
Use Roles to review existing roles and create custom roles for your tenant.
Who can use this¶
You need:
role:viewto open theRolestab.role:addto create a custom role.role:modifyto edit a custom role.role:deleteto delete a custom role.
Before you begin¶
Decide which product areas the role should access and whether the role needs read-only or read/write access.
View roles¶
- Open
Organization > Overview. - Select the
Rolestab. - Review the table columns:
ROLE NAMEDESCRIPTIONPERMISSIONSROLE TYPEACTIONS
Filter roles¶
Use the role filter to narrow the list by:
PERMISSIONS:ReadorRead/WriteROLE TYPE:Built InorCustom
Open role details¶
- Select a value in the
ROLE NAMEcolumn. - Review
Role Details. - Review the role name, description, permissions, and
Users Assigned to this Role.
From role details, users can be selected for removal from the role. Select Save to apply the change.
Permission areas¶
CloudVerse roles can include permissions for organization access and product modules such as users, roles, reports, budgets, recommendations, integrations, and data exploration.
| Area | Confirmed permission keys |
|---|---|
| Access management | navigator:access-management:view |
| Users | user:view, user:add, user:modify, user:activate, user:deactivate, user:delete, user:leave |
| Roles | role:view, role:add, role:modify, role:delete |
| SSO | idp-sso-authentication:view, idp-sso-authentication:add, idp-sso-authentication:modify, idp-sso-authentication:delete |
| Accounts | account:view, account:add, account:modify, account:delete, account:activate, account:deactivate |
| Organization | organization:view, organization:add, organization:modify, organization:delete |
| Policies | policy:view, policy:add, policy:modify, policy:run, policy:activate, policy:deactivate, policy:delete |
| Reports | report:view, report:add, report:modify, report:delete |
| Budgets | budget:view, budget:add, budget:modify, budget:activate, budget:deactivate, budget:delete |
| Recommendations | recommendation:view, recommendation:modify |
| Integrations | integration:view, integration:add, integration:modify, integration:delete |
| Currency | currency:view, currency:add, currency:modify, currency:delete |
| Data Explorer | data-explorer:view |
Expected result¶
Admins can see which roles exist, whether each role is built in or custom, and which users are assigned to each role.
Notes and limitations¶
- Built-in roles do not show edit or delete actions.
- Custom roles can be edited or deleted when your role includes the required permissions.
- If a custom role is deleted, the UI states that assigned users revert to the default
Tenant Userrole.
Troubleshooting¶
If Add Custom Role is missing, confirm your role includes role:add.
If edit or delete actions are missing, confirm the role is a custom role and that your role includes role:modify or role:delete.