Roles
Updated
MFT includes roles that contain permissions that can be assigned to users, enabling limited access for instance members or providing comprehensive self-service capabilities for partners.
Several predefined System Roles are available. You cannot alter them directly, but you can duplicate and modify as needed, serving as a customizable foundation. You can assign role types to a user or create entirely new custom roles.
Implementing custom security roles
- Add your roles in a lower environment
- Plan a role naming schema for your custom roles for easy administration
- Date your roles by adding the creation date to the name
- Back up your roles by keeping a manual hard copy of your roles in a document
- Test your roles in a lower environment before going live with your roles
- Notify users about the change
- Add the new roles to the Production Environment and assign them to users
- Follow up with the users to ensure the roles are working correctly
caution
Many combinations of sub-roles are available. You must test your roles before you use them.
MFT includes the following pre-defined system roles. For information about individual permissions, refer to Permissions.
- (USER TYPE) Instance Admin
- (USER TYPE) Instance User
- (USER TYPE) Org User
- (USER TYPE) Thru Ops
- (USER TYPE) Transfer User
- Admin - Audit Log: Read
- API Key: CRUD
- Basic Auth
- Basic Auth Test
- Customer: CRUD
- File Activity
- File Download
- File Upload
- Flow - Endpoint: CRUD + Run Flow EP Now
- Flow - History: Read / Rollback
- Flow - Schedule: Read
- Flow - Subscriptions: CRUD
- Flow: CRUD
- Global Search: Read
- Instance Admin API
- MFA: RU
- Organization - Certificate: CRUD
- Organization - Endpoint: CRUD
- Organization - PGP Key: CRUD
- Organization - SSH Key: CRUD
- Organization - Subscription: CRUD
- Organization - Thru Node: CRUD
- Organization manager
- Organization: CRUD
- Overview Page: Read
- Retention: CRU
- Roles: CRUD
- SSO Auth
- SSO Auth Test
- System Alerts: Read / Ack
- User Management