Enhanced RBAC Permission Reference
use this reference to see what each permission grants, how access rights combine, and which related resources a feature also needs for creating and editing roles in the ui, see enhanced role based access control (rbac) https //docs swimlane com/enhanced role based access control rbac choose your path goal where to go understand users, groups, roles, and how access is granted how permissions are structured /#how permissions are structured look up what an access right means (create, execute, bypass restrictions, and so on) access rights glossary /#access rights glossary see what an account level resource permission controls account level permissions /#account level permissions see what a tenant level resource permission controls tenant level permissions /#tenant level permissions trace why a feature needs more than one permission cross resource dependencies /#cross resource dependencies diagnose a user who cannot open a feature troubleshoot access issues /#troubleshoot access issues plan a move from legacy rbac move from legacy rbac to enhanced rbac https //docs swimlane com/move from legacy rbac to enhanced rbac how permissions are structured permissions are grouped into roles users get access through roles assigned to them or to their groups core concepts concept description user an identity that logs in and performs actions managed under admin panel β users the user must belong to the account and have at least one role group a collection of users used to assign roles and record restrictions a user can belong to several groups; one may be the primary group groups can nest in a parentβchild hierarchy role a named set of permissions assigned to users or groups roles are account level one role can grant access across multiple tenants managed under admin panel β roles resource the item being secured, such as applications, application records, playbooks & components, users, or roles permission an access rule on a resource in the role editor, each permission is a resource row with one or more access rights selected access right the action allowed on a resource, such as create, read, update, delete, execute, restrict, or lock external user a user from another swimlane account who is invited to this account external users follow the same rbac rules manage external on the users resource controls who can administer external user accounts how access is granted a user can perform an action when all of the following are true the user is associated with the account (or invited as an external user) a role is assigned to the user directly or to a group of which the user is a member that role includes the required permission (resource plus access right) for the action permission level applies to account level administrative resources across the whole account (for example, users, roles, tenants) tenant level operational resources in specific tenants or all tenants the same role can grant different access in different tenants group role assignment under enhanced rbac, a role assigned to a group applies only to direct members of that group roles are not propagated through the group hierarchy if group a is a child of group b, each group's roles apply only to that group's own direct members group hierarchy role inheritance applies only to legacy rbac enhanced rbac roles are never propagated through the group hierarchy global versus resource level access scope behavior global applies to all current and future instances of a resource type (for example, all dashboards) resource level applies only to the individual instances you select when global access is selected, it overrides resource level selections resource level selections are retained and can be restored if you later prefer resource level access over global required access and auto check behavior some access rights do not work alone the role editor auto checks related access rights when you select certain options when you check the editor also checks create read, update update read delete read, update (read only for connectors, connector public keys, and ca certificates) export (tenant) read import (tenant) create, read, update execute (playbook/component) read test (asset) read, update install (connector) read create personal (dashboard/report) create, read, update override locks read, update, lock restrict / lock / workflow history / bypass restrictions / moderate comments / run details read (plus update for most) assign / assign roles read, update update membership (group) read manage external (user) create, read, update, delete auto check runs only when you select an access right deselecting one right does not auto deselect rights that were checked with it what you save on the role is exactly what applies; there is no hidden logic that re adds required access later cross resource dependencies are not auto checked for example, viewing a dashboard may also need read on the reports it contains, and application records need at least read on the associated application see cross resource dependencies /#cross resource dependencies before you replace a role on working users, copy role and test with a non production user confirm every required action end to end, then assign the role broadly access prerequisites before account and tenant permissions take effect the user must be associated with the account or invited as an external user the user must have a role (directly or through a group) that grants the needed permissions, including tenants β read to use resources inside a tenant without both, the user cannot reach account resources and may be unable to log in access rights glossary these meanings are the same wherever the access right appears resource specific notes appear in the account and tenant sections below access right what it lets the user do create create new instances of the resource read view or list the resource almost every other action requires read update modify an existing resource delete remove the resource export (tenant only, on tenants ) export tenant content such as applications, applets, and playbooks import (tenant only, on tenants ) import content into a tenant execute run the resource for playbooks & components , run the playbook test (assets) run a connection or validation check selecting it also checks read and update install (connectors) install a connector replaces create for connectors restrict (records) restrict a record so only selected users or groups can see it lock (records) lock a record to prevent concurrent edits override locks (records) edit or unlock a record locked by another user workflow history (records) view workflow run history for a record bypass restrictions (records, dashboards, reports) act on a resource that is restricted to other users or groups, including restricted fields on application records the user still needs read (and update to edit) moderate comments (records) edit or delete comments left by other users run details (playbooks & components) view the detailed run log create personal (dashboards, reports) create personal items visible only to the creator or users with bypass restrictions assign (roles) assign a user or group to a role assign roles (users, groups) assign a role to a user or group update membership (groups) change group members or group hierarchy manage external (users) manage external (shared account) users bulk update assets / bulk delete assets (configuration manager) update or delete configuration assets in bulk account level permissions account level permissions control administrative resources across the whole account admin panel access purpose read shows the admin panel menu and opens admin pages admin panel β read is a gate, not a master key each admin page also needs permissions for that page's resource for example, the users page needs admin panel β read plus users β read account settings access purpose read view account settings under admin panel β settings β account update change account settings (general, security & compliance, directory services, sso/saml, mail, license, git integration) account audit logs access purpose read retrieve account audit log entries programmatically there is no audit log screen in the admin panel usage access purpose read view usage reporting in the admin panel separate from tenant application reports and dashboards some usage dashboards need an extra permission dashboard also required hero ai (credits, prompts, tokens) and notifications usage β read only playbook runs and actions playbooks & components β run details (any tenant) events events β read (any tenant) without the extra permission, that dashboard stays hidden even if usage β read is granted tenants access purpose create, read, update, delete manage tenants read is required to enter a tenant and reach its resources export export tenant content also needs read on each resource type included in the package unreadable items are omitted import import tenant content also needs create (new items) or update (overwrite) on each resource type written users access purpose read view users in lists and pickers every user has implicit read on their own user record create, update, delete create, change, or remove users assign roles attach a role to a user manage external manage external or shared users (also checks create, read, update, delete) read, update, delete, and assign roles can be granted on specific users (resource level) for mssp or multi customer separation create is account wide only roles access purpose read see and select roles where roles appear create, update, delete create, change, or remove roles assign grant a role to a user or group read, update, delete, and assign can be scoped to specific roles inline permissions on other resources dashboards, reports, workspaces, applications, and applets expose a permissions tab on their own screens task required permissions open the permissions tab (dashboards, reports, workspaces) roles β read , or create personal alone when configuring a personal dashboard or report add or change a role in the picker roles β update on each role listed save access on the resource update on that resource (for example, reports β update) full role editing remains under admin panel β roles groups access purpose read see and select groups across the product create, update, delete create, change, or remove groups update membership change group members and hierarchy assign roles add a role to the group read, update, delete, and assign roles can be scoped to specific groups configuration manager access purpose read open configuration manager bulk update assets / bulk delete assets apply bulk changes to configuration assets visible only when configuration manager is enabled for the account a user with configuration manager β read but without admin panel β read gets a separate configuration manager entry under the user avatar content (library) access purpose create, read, update, delete access the library menu library access is account level only content cannot be restricted per tenant even when associated with a tenant tenant level permissions tenant level permissions control operational resources configure them per tenant, or for all tenants global tenant permissions can be copied from one tenant to others resource level selections cannot be copied across tenants and cannot be used with all tenants applications access purpose create, read, update, delete manage applications read is required for records, dashboards, and reports related to that application inline access application settings β administration configures per role application access the tab requires application records β update changing role access also requires roles β update on each affected role applets access purpose create, read, update, delete manage applets read is needed alongside parent resources that use the applet inline access applet permissions tab requires applets β update plus roles β update on each affected role application records access purpose create, read, update, delete manage records restrict limit a record to selected users or groups lock / override locks lock a record; override another user's lock (override locks also checks lock) workflow history view a record's workflow run history bypass restrictions open, edit, and delete records and fields that are otherwise restricted still needs record β read and update for those actions can be global or per application moderate comments edit other users' comments on a record depends on application β read, any applets the application uses, and playbook β read plus execute for playbook buttons on a record inline access application settings β records requires application records β update plus roles β update on each affected role field level permissions (application builder β field properties β permissions) override application level record permissions for that field only read and update can be granted per role field permission task required open app builder and save applications β update on the application load roles in the picker roles β read save field permission changes roles β update on each role whose permissions changed dashboards access purpose create, read, update, delete manage shared dashboards create personal create dashboards visible only to the creator (also checks create, read, update) bypass restrictions view, edit, and delete dashboards the user is not on the access list for, including personal dashboards global only depends on read on the applications, reports, and application records the dashboard uses inline access permissions tab opens with dashboards β create personal or roles β read changing role access requires roles β update reports access purpose create, read, update, delete manage shared reports create personal same semantics as dashboards bypass restrictions same semantics as dashboards depends on applications and application records the report draws from inline access shared reports need roles β read and reports β update personal reports can open the tab with create personal alone changing role access requires roles β update workspaces access purpose create, read, update, delete manage workspaces depends on applications, dashboards, and application records in the workspace inline access requires roles β read and workspaces β update changing role access requires roles β update home page access purpose read view other users' home pages (with users β read for that owner) update edit other users' home pages (with users β read for that owner) every user can view and configure their own home page without home page permission read and update are account wide only (not per instance) and apply to other users' home pages and bulk home page actions playbooks & components access purpose create, read, update, delete author and manage playbooks and components execute run a playbook or component (also checks read) run details open the detailed run log read plus execute are required to use playbook buttons on records connectors access purpose install install a connector (also checks read) replaces create read, delete view and remove connectors no create or update connector public keys access purpose read show connector trust keys under tenant settings and list keys create / delete add or remove a key also needs admin panel β read and tenant settings β read to reach the ui assets access purpose create, read, update, delete manage assets used in playbooks and applications test run a connection or validation check (also checks read and update) webhooks access purpose create, read, update, delete manage webhook triggers while authoring playbooks events access purpose read show the events tab in operational health (operational health must be enabled; also needs playbook β create, update, or delete) also required for admin panel β usage β events with admin panel β read and usage β read playbook alerts access purpose read view playbook alerts in operational health when that feature is enabled pools access purpose read list pools and open a pool create / update / delete add, edit, or remove a pool delete also needs remote agent β update and playbook β update managed under admin panel β settings β tenant settings (nodes / remote agents) needs admin panel β read and tenant settings β read selecting a pool inside a playbook action is not separately gated by pool permission remote agents access purpose read list agents and open details update rename, enable or disable, and change pool assignments delete remove an agent create agents register when deployed with the install script; day to day management uses read, update, and delete same tenant settings page as pools deleting a pool needs remote agent β update viewing a pool's linked agents needs remote agent β read ca certificates access purpose read show the ca certificates tab and list certificates create upload a pem string or file delete remove a certificate no update β replace by delete and create managed under tenant settings distribution to remote agents when an agent is enabled uses remote agent β update and does not require ca certificate permission tenant settings access purpose read open tenant settings and see tenants in the selector also needs tenants β read update save tenant settings tab additional gate system, email & pdf tenant settings read / update connector trust keys connector public key β read ca certificates ca certificate β read (create/delete for add/remove) agents (remote agents and pools) remote agent and pool permissions features super admins or users allowed to manage tenant feature settings orchestration alerts shown when operational health is enabled tenant audit logs access purpose read retrieve tenant audit logs programmatically no ui cross resource dependencies a parent resource never auto grants its dependencies missing any link blocks the feature goal also required read a record application β read; application records β read; applet β read if the app uses applets see users or groups in user/group fields on a record users β read and/or groups β read (account level) names already stored may still display; unresolved entries can render blank run a playbook from a record playbook β read and execute use a dashboard, report, or workspace read on the applications, reports, and application records they surface configure access on a resource's own screen update on that resource (or create personal for personal dashboards/reports); roles β update to change which roles have access set field level permissions in the app builder applications β update; roles β read to load roles; roles β update to save open any admin page admin panel β read plus the page's resource permission export tenant content tenants β export plus read on each exported resource import tenant content tenants β import plus create or update on each imported resource troubleshoot access issues check what to verify 1 role assignment direct role assignment and group membership under enhanced rbac, roles apply to direct group members only group hierarchy role inheritance applies only to legacy rbac 2 target resource the role includes the required access right on the specific resource (and tenant, if tenant level) 3 dependent resources related permissions from cross resource dependencies /#cross resource dependencies record β read alone does not unlock dashboards or playbook buttons for new or changed roles, copy the role and test with a non production user before broad assignment next steps enhanced role based access control (rbac) https //docs swimlane com/enhanced role based access control rbac β create and edit roles in the ui move from legacy rbac to enhanced rbac https //docs swimlane com/move from legacy rbac to enhanced rbac β migration mapping and support request test connector assets https //docs swimlane com/test connector assets β assets β test permission configuration manager https //docs swimlane com/configuration manager β bulk asset actions and permissions