Skip to main content

Roles

Roles define the permissions that Users have in UDMG. Users can perform all functions permitted by their assigned Role, which defines their system access boundaries.

Each User must be assigned exactly one predefined Role. Custom roles and granular permission management are not available. For details on each Role, see the List of Roles.

Assigning Roles

Users are assigned a Role upon creation. Admins can also change a User's Role by editing the User record. For more information, see Adding a User and Editing a User.

List of Roles

The following table summarizes the available Roles. For a full list of permissions for each Role, see Role Details.

info

System Administrators and Domain Administrators both have administrative permissions within their Domain. For simplicity, both Roles are often referred to collectively as "Admins" throughout the docs.

NameDescription
System Administrator

Manages global settings and creates new Domains. Exercises complete configuration and management control within the Primary Domain.

The System Administrator Role includes all permissions of the Domain Administrator for the Primary Domain.

info

This Role is only available in the Primary Domain.

Domain AdministratorExercises complete configuration and management control within a specific Domain.
OperatorMonitors Transfers, troubleshoots issues, and performs limited operational actions such as enabling or disabling Configuration Items.
Pipeline ManagementConfigures core Configuration Items (Accounts, Account Groups, Endpoints, and Pipelines) to facilitate file transfers within the Domain.
Read-only

Views all Configuration Items within the Domain without modification rights.

info

This Role is automatically given to all LDAP-created Users.

Role Details

This table shows a full list of permissions for each Role:

Key
  • R: Read
  • C: Create
  • U: Update
  • D: Delete
  • E/D: Enable/Disable/Test
  • S/S: Start/Stop
  • V: Reveal (for credentials)
  • All: All applicable permissions (R, C, U, D, E/D, S/S, V)
  • Implicit: Session management is not controlled via direct role-based permissions. Session information is only accessible via the API.
ScopeRead-onlyOperatorPipeline ManagementDomain AdminSystem Admin
TransfersRRRAllAll
Shared FilesRRRAllAll
AccountsRR, E/DAllAllAll
Account GroupsRRAllAllAll
EndpointsRR, S/SAllAllAll
PipelinesRR, E/DAllAllAll
CredentialsRR, E/D, VAllAllAll
UsersRR-AllAll
Domain - BannerRRRAllAll
Domain - User LDAPRR, E/D-AllAll
Domain - Account LDAPRR, E/DAllAllAll
Domain - User SSORR, E/D-AllAll
Domain - Account SSORR, E/DAllAllAll
Domain - IP Filtering - EndpointsRR, E/DAllAllAll
Domain - ICAP ScanningRR, E/D-AllAll
Domain - Forward ProxyR--AllAll
Global - Domains-R--All
Global - Cluster Nodes-R--All
Global - Settings----All
Sessions---ImplicitImplicit