Skip to main content
Version: 3.3

Roles

Roles define the permissions that Users have in UDMG. Users can perform all functions permitted by their assigned Role, which defines their system access boundaries.

Each User must be assigned exactly one predefined Role. Custom roles are not available.

info

For restricting action permissions at the Configuration Item level, see Business Services.

Assigning Roles

Users are assigned a Role upon creation. Admins can also change a User's Role by editing the User record. For more information, see Adding a User and Editing a User.

List of Roles

The following table summarizes the available Roles. For a full list of permissions for each Role, see Role Permissions.

info

System Administrators and Domain Administrators both have administrative permissions within their Domain. For simplicity, both Roles are often referred to collectively as "Admins" throughout the docs.

NameDescription
System Administrator

Manages global settings and creates new Domains. Exercises complete configuration and management control within the Primary Domain.

The System Administrator Role includes all permissions of the Domain Administrator for the Primary Domain.

info

This Role is only available in the Primary Domain.

Domain AdministratorExercises complete configuration and management control within a specific Domain.
OperatorMonitors Transfers, troubleshoots issues, and performs limited operational actions such as enabling or disabling Configuration Items.
Pipeline ManagementConfigures core Configuration Items (Accounts, Account Groups, Endpoints, and Pipelines) to facilitate file transfers within the Domain.
Read-only

Views all Configuration Items within the Domain without modification rights.

info

This Role is automatically given to all LDAP-created Users.

Role Permissions

The following tables show the full list of permissions for each Role. The tables are organized according to the UDMG Admin UI sidebar structure.

Key Definitions
  • C: Create
  • R: Read
  • U: Update
  • D: Delete
  • E/D: Enable/Disable
  • T: Test
  • S/S: Start/Stop

Monitoring

PagePermission or UI HandlingSystem AdminDomain AdminOperatorPipeline ManagementRead-only
TransfersPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewView/EditView
Task InstancesPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewView/EditView
Shared FilesPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewView/EditView

Configuration

PagePermission or UI HandlingSystem AdminDomain AdminOperatorPipeline ManagementRead-only
AccountsPermission(s)CRUD + E/DCRUD + E/DR + E/DCRUD + E/DR
UIView/EditView/EditViewView/EditView
Account GroupsPermission(s)CRUD + E/DCRUD + E/DRCRUD + E/DR
UIView/EditView/EditViewView/EditView
EndpointsPermission(s)CRUD + E/D + S/SCRUD + E/D + S/SR + E/D + S/SCRUD + E/D + S/SR
UIView/EditView/EditViewView/EditView
PipelinesPermission(s)CRUD + E/DCRUD + E/DR + E/DCRUD + E/DR
UIView/EditView/EditViewView/EditView
TasksPermission(s)CRUDCRUDRCRUDR
UIView/EditView/EditViewView/EditView
CredentialsPermission(s)CRUD + E/DCRUD + E/DR + E/DCRUD + E/DR
UIView/EditView/EditViewView/EditView

General

PagePermission or UI HandlingSystem AdminDomain AdminOperatorPipeline ManagementRead-only
UsersPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewNoneView
Business ServicesPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewViewView
Settings > LDAP Authentication - UsersPermission(s)CRUD + TCRUD + TR + TNoneR
UIView/EditView/EditViewNoneView
Settings > LDAP Authentication - AccountsPermission(s)CRUD + TCRUD + TR + TCRUD + TR
UIView/EditView/EditViewView/EditView
Settings > Banner CustomizationPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewViewView
Settings > ICAP ScannerPermission(s)CRUD + E/D + TestCRUD + E/D + TestR + E/D + TestNoneR
UIView/EditView/EditViewNoneView
Settings > IP Filtering - EndpointsPermission(s)CRUD + TCRUD + TR + TCRUD + TR
UIView/EditView/EditViewView/EditView
Settings > Single Sign-On (SSO) - UsersPermission(s)CRUD + E/DCRUD + E/DR + E/DNoneR
UIView/EditView/EditViewNoneView
Settings > Single Sign-On (SSO) - AccountsPermission(s)CRUD + E/DCRUD + E/DR + E/DCRUD + TR
UIView/EditView/EditViewView/EditView
Settings > Security - SecurityPermission(s)CRUDCRUDRRR
UIView/EditView/EditViewViewView
Settings > Forward ProxyPermission(s)CRUD + E/D + TestCRUD + E/D + TestR + E/D + TestNoneR
UIView/EditView/EditViewNoneView

Global

PagePermission or UI HandlingSystem AdminDomain AdminOperatorPipeline ManagementRead-only
DomainsPermission(s)CRDCRDRNoneR
UIView/EditView/EditView; only in Primary DomainNoneNone
Cluster NodesPermission(s)CRUDCRUDRNoneR
UIView/EditView/EditView; only in Primary DomainNoneNone
Settings > LicensingPermission(s)CRUDCRUDRNoneR
UIView/EditView/EditView; only in Primary DomainNoneNone
Settings > IP Filtering - Admin UIPermission(s)CRUD + TNoneRNoneNone
UIView/EditNoneView; only in Primary DomainNoneNone

Others

ScopeSystem AdminDomain AdminOperatorPipeline ManagementRead-only
AuditRRNoneNoneNone
Sessions EndpointCRUD (Stop)CRUD (Stop)RRR
Transfers Schedules EndpointCRUDCRUDRRR
Reveal EndpointRRRRNone