Skip to main content
Version: v44

Role Permissions

Permission
UsageScope
access-groups-manageAllow creating and modifying access groups.Global
access-roles-manageAllow creating and editing access roles within the specified access group.Access group
api-clients-manageAllow creating and modifying API Clients for scripted access via REST API.Global
api-targets-manageAllow adding, editing, deleting, and viewing api targetsAccess group
api-targets-viewAllow viewing API targetsAccess group
authorized-keys-manageAllow importing and modifying current user's authorized keys for SSH Bastion login.Global
connections-authorizeEnable fetching access credentials from authorizer REST API. API clients require this permission to be able to fetch access credentials. PrivX users can fetch access credentials also without this permission.Global
connections-manageEnable access-role grant, revoke and listing for the connections.Global
connections-manualEnable manual connections.Global
connections-playbackEnable connection playback and playback search Access groups are taken into account.Access group
connections-terminateEnable ongoing connection termination.Access group
connections-trailEnable viewing connection logs. Logs reveal all user inputs some of which may not be revealed in connection playback. Enable viewing transferred files in the connection. Enable viewing clipboard contents in RDP connection. Access groups are taken into account.Access group
connections-viewEnable connection monitoring view, show the connection metadata. Access groups are taken into account.Access group
hosts-manageAllow modifying existing hosts' configuration for the access group defined for the role.Access group
hosts-viewAllow viewing existing hosts for the access group defined for the role.Access group
idp-clients-manageAllow managing IDP clients via the PrivX API.Global
idp-clients-viewAllow viewing IDP clients via the PrivX API.Global
licenses-manageAllow modifying PrivX license.Global
logs-manageAllow creating and modifying cloud log collectors.Global
logs-viewAllow viewing audit event logs.Global
mobilegw-manageAllow registering/unregistering PrivX from Mobile Application Gateway. Multi-Factor Authentication with PrivX AuthorizerGlobal
mobilegw-viewAllow viewing the current Mobile Application Gateway registration status. Required for Multi-Factor Authentication with PrivX Authorizer.Global
network-targets-manageAllow adding, editing, deleting, and viewing network targetsGlobal
network-targets-viewAllow viewing network targetsGlobal
requests-viewAllow displaying and searching the user's requests via the PrivX APIGlobal
role-target-resources-manageAllow modifying AWS role - PrivX role mappings.Global
role-target-resources-viewAllow viewing AWS role - PrivX role mappings.Global
roles-manageAllow creating and modifying roles. NOTE: this will give permissions to grant roles to any user, so granting this permission will be effectively the same as granting superuser permissions.Global
roles-viewAllow viewing existing roles and role configurations.Global
settings-manageAllow viewing and modifying PrivX settingsGlobal
settings-viewAllow viewing PrivX settingsGlobal
sources-data-pushAllow SCIM integrationGlobal
sources-manageAllow creating and modifying user and host directories, bringing new users and hosts to PrivX.Global
sources-viewAllow viewing user and host directory configuration.Global
target-domains-manageAllows managing target domains.Global
target-domains-viewAllows viewing target-domain data. NOTE: Also required for modifying target domains in host settings.Global
ueba-manageAllow managing UEBA configurations via the PrivX API.Global
ueba-viewAllow viewing UEBA configurations via the PrivX API.Global
users-manageAllow modifying existing local users. Does not apply to users from third party user directories, like AD.Global
users-viewAllow viewing existing users.Global
vault-addAllow creating global secrets. Allow granting read/write access to user's own personal secrets to others.Global
vault-manageAllow creating and modifying existing global and personal vault secrets.
webauthn-credentials-manageAllow users to manage their own Passkeys.Global
workflows-manageAllow creating and modifying workflows. NOTE: this can be used for granting approval access to restricted roles. Use carefully.Global
workflows-requests-on-behalfAllow creating role approval request on behalf of other user. For example, manager can ask more permissions on behalf of employee.Global
workflows-requestsAllow creating role approval requests via workflows.Global
workflows-viewAllow viewing existing workflows and permissions.Global