Skip to main content

Settings: creating and managing roles

Create a custom role, set its permissions family by family, edit it and delete it.

In brief: The four standard roles cannot be edited. Any need that falls outside them goes through a custom role, whose permissions you set family by family.

Creating a role

  1. Open the configuration menu from the navigation bar header, then Settings.

  2. In the Roles and permissions block, click Roles.

  3. At the top of the screen, open the dropdown carrying the displayed role's name.

The roles dropdown

  1. At the very bottom of the list, click Add a role.

  2. Give the role a name your colleagues will understand without explanation. "Security manager" reads, "Role 3" does not.

  3. Set the permissions, family by family (see the next section).

  4. Click Save.

Setting a role's permissions

Setting the permissions

Permissions are grouped into seven families, shown in this order: Applications, Segments, Automations, Guidance, Settings, Web Browser Extension, Complementary Sources.

Each family is set with one of three buttons:

  • No access: closes the whole family.

  • Full access: opens the whole family, including the features that will be added to it later.

  • Advanced selection: opens the permission list one by one, to tick.

⚠️ The difference between "Full access" and "ticking everything" is not cosmetic. With "Full access", a new feature shipped in that family becomes available to the role holders automatically. With an advanced selection where everything is ticked, it does not: the interface reminds you with a banner as soon as you switch to advanced selection.

What each family holds:

Family

Permissions, in the order shown on screen

Applications

View applications, Create applications, Edit applications data, Delete an application, Archive an application, Edit authorizations, Split an application, Export applications data, Share analysis scopes

Segments

View segments, Manage segments

Automations

Manage automations

Guidance

View campaigns, Create campaigns, Live Debug

Settings

Configure Zscaler integration, Manage custom taxonomy

Web Browser Extension

View WBE settings, Edit WBE settings, Configure catalogue, View catalog feedbacks & promotions

Complementary sources

Access to complementary sources, Edit the import results

ℹ️ Two boxes are ticked and greyed out, for every role: "View applications" and "View segments". They are granted outright because the platform does not work without them. You cannot remove them.

ℹ️ Two permissions only appear if your platform has them open: "Manage the custom taxonomy" and "Share analysis scopes". If you do not see them in the list, the matching feature is not enabled for you.

Editing a role

ℹ️ Only custom roles can be edited. A standard role shows "This role is standard and cannot be modified".

  1. Settings then Roles and permissions then Roles.

  2. Open the dropdown at the top of the screen.

  3. In the Custom roles section, click the role to edit.

  4. Change the permissions.

  5. Click Save, then confirm.

⚠️ The confirmation is not a formality: the change applies immediately to everyone carrying the role. Someone mid-session can lose access to a screen between two clicks.

Deleting a role

  1. Open the custom role concerned.

  2. At the bottom of the page, expand the Delete the role block.

  3. Read the warning, then click Delete the role.

Deleting a custom role

⚠️ Check who carries the role first. Deleting it hits everyone concerned at once. The users table filters by role: use it before deleting, not after.

Related articles

Did this answer your question?