Infrastructure permissions by role and by action

Infrastructure permissions cover adding assets to your organization's infrastructure and managing that infrastructure. A user's role determines who can add assets and who can change infrastructure settings. This article lists the infrastructure permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do with infrastructure. For a breakdown by action instead, see By action below.

What can an Admin do with infrastructure?
  • Can add assets to the infrastructure.
  • Can add a connection for Cloud Infrastructure Sync.
  • Can create a self-published rating.
  • Can delete custom infrastructure.
  • Can set which self-published company is the primary rating.
  • Can identify a company relationship as company managed.
  • Can view and set an expiration date for company-provided assets.
  • Can state the parent and subsidiary company relationship (subsidiary attribution).
What can a Group Admin do with infrastructure?
  • Can add assets to the infrastructure.
  • Cannot manage infrastructure.
What can a Portfolio Manager do with infrastructure?
  • Cannot add assets to the infrastructure.
  • Cannot manage infrastructure.
What can an Operations user do with infrastructure?
  • Infrastructure permissions do not apply to this role.
What can an Internal Business User do with infrastructure?
  • Infrastructure permissions do not apply to this role.
What can a User do with infrastructure?
  • Cannot add assets to the infrastructure.
  • Cannot manage infrastructure.
What can a View Only user do with infrastructure?
  • Infrastructure permissions do not apply to this role.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Add assets

✅ Admins and Group Admins can do this.

❌ Portfolio Managers and Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Add a connection for 
Cloud Infrastructure Sync

✅ Only Admins can do this.

❌ No other role can add a Cloud Infrastructure Sync connection.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Create a self-published 
rating

✅ Only Admins can do this.

❌ No other role can create a self-published rating.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Delete custom 
infrastructure

✅ Only Admins can do this.

❌ No other role can delete custom infrastructure.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Highlight which 
self-published company 
is the primary rating

✅ Only Admins can do this.

❌ No other role can set the primary self-published company.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Identify a company 
relationship as company 
managed

✅ Only Admins can do this.

❌ No other role can identify a company relationship as company managed.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

View and set an 
expiration date for 
company-provided assets

✅ Only Admins can do this.

❌ No other role can set an expiration date for company-provided assets.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

State the parent and subsidiary 
company relationship 
(subsidiary attribution)

✅ Only Admins can do this.

❌ No other role can state the parent and subsidiary company relationship.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Publish Date or Recent Edits
  • January 3, 2025: State the parent and subsidiary company relationship (subsidiary attribution); Identify company relationship (company managed).
  • November 25, 2024: Separated from User Permissions and added VRM/TMH roles.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.