Skip to main content
Feedback

Permissions

Updated 

Granular permissions refer to roles that can be assigned to users to limit their access. An admin user can configure these user roles by navigating to a user (Admin > User ) or during the user creation process. While default roles are generally adequate for most customers, in specific scenarios, customers may opt to create their own roles.

tip

You can layer your security roles for easy administration.

For example, a XYZ user has rights to manage flows and organizations under a role called “Worker”. When you want to provide the XYZ user with a limited administrator role, you can create an admin role called “Worker Admin” and assign it to the user by layering both “Worker” and “Worker Admin” roles.

System & Account

PermissionDescription
Audit APIsView audit log entries recording user and system actions on the account.
Billing APIsView billing and usage data for the account.
Global SearchSearch across organizations, flows, and other objects from a single search bar.
Instance Admin APIsAccess administrative APIs for managing instance-level settings.

File Activity

PermissionDraft Description
File ActivityView file transfer activity and history records.
File Activity: Replay FilesResend or reprocess a previously transferred file.
File Activity: Download FilesDownload a file from its activity record.
File Activity: Delete FilesDelete a file from its activity record.

Alerts

PermissionDescription
Alert: Get / ListView configured alerts and their current status.
Alert: Update StatusChange the status of an alert (for example, acknowledge or resolve it).

Content API

PermissionDescription
Content API: File UploadUpload files through the Content API.
Content API: File DownloadDownload files through the Content API.

Organization

PermissionDescription
Organization: Get / ListView organization records.
Organization: CreateCreate new organizations.
Organization: UpdateEdit existing organization details.
Organization: DeleteDelete organizations.
Organization - Endpoint: Get / ListView endpoints configured under an organization.
Organization - Endpoint: CreateCreate endpoints under an organization.
Organization - Endpoint: UpdateEdit an organization's endpoint settings.
Organization - Endpoint: DeleteDelete an organization's endpoints.
Organization - Subscription: Get / ListView an organization's event/notification subscriptions.
Organization - Subscription: CreateCreate subscriptions for an organization.
Organization - Subscription: UpdateEdit an organization's subscriptions.
Organization - Subscription: DeleteDelete an organization's subscriptions.
Organization - PGP Key: Get/ListView PGP encryption keys stored for an organization.
Organization - PGP Key: CreateAdd a PGP key to an organization.
Organization - PGP Key: UpdateEdit an organization's PGP key.
Organization - PGP Key: DeleteRemove a PGP key from an organization.
Organization - SSH Key: Get / ListView SSH keys stored for an organization.
Organization - SSH Key: CreateAdd an SSH key to an organization.
Organization - SSH Key: UpdateEdit an organization's SSH key.
Organization - SSH Key: DeleteRemove an SSH key from an organization.
Organization - Certificate: Get / ListView certificates stored for an organization.
Organization - Certificate: CreateAdd a certificate to an organization.
Organization - Certificate: UpdateEdit an organization's certificate.
Organization - Certificate: DeleteRemove a certificate from an organization.
Organization - Thru Node: Get / ListView the MFT Runtimes in an organization
Organization - Thru Node: CreateCreate an MFT Runtime in an organization
Organization - Thru Node: UpdateEdit an MFT Runtime's configuration
Organization - Thru Node: DeleteDelete an MFT Runtime
Organization - Machine User: Get / ListView machine (non-interactive/API) user accounts for an organization.
Organization - Machine User: CreateCreate a machine user for an organization.
Organization - Machine User: UpdateEdit a machine user's settings.
Organization - Machine User: DeleteDelete a machine user.

Flow

PermissionDescription
Flow: Get / ListView flows.
Flow: CreateCreate new flows.
Flow: UpdateEdit flow configuration.
Flow: DeleteDelete flows.
Flow: Export FileZilla ConfigExport a flow's endpoint settings as a FileZilla client configuration file.
Flow: ExportExport a flow definition, for example for backup or migration.
Flow: ImportImport a flow definition.
Flow - Transfer Request: Get / ListView transfer requests generated by a flow.
Flow - Client Response: Get / ListView client response records for a flow.
Flow - Active Schedule: Get / ListView a flow's currently active schedules.
Flow - Endpoint: Get / ListView endpoints attached to a flow.
Flow - Endpoint: CreateCreate endpoints for a flow.
Flow - Endpoint: UpdateEdit a flow's endpoint settings.
Flow - Endpoint: DeleteDelete a flow's endpoints.
Flow - Endpoint: RunManually trigger a flow endpoint.
Flow - Subscription: Get / ListView a flow's event subscriptions.
Flow - Subscription: CreateCreate subscriptions for a flow.
Flow - Subscription: DeleteDelete a flow's subscriptions.
Flow - History: Get / ListView a flow's version/change history.
Flow - History: RollbackRevert a flow to a previous version.

Flow Endpoint Configuration

Permission groupDescription
Alert ConfigConfigure alerts triggered by endpoint activity.
Anti Virus ConfigConfigure antivirus scanning for transferred files.
Compression ConfigConfigure file compression/decompression settings.
Main ConfigConfigure the endpoint's core/general settings.
Email Notification ConfigConfigure email notifications for endpoint events.
Encryption ConfigConfigure encryption settings (for example, PGP) applied to transferred files.
Processing ConfigConfigure rules for processing files after transfer.
Schedule ConfigConfigure the endpoint's transfer schedule.
Rename Option ConfigConfigure rules for renaming files during transfer.
Server Path Mapping ConfigConfigure mappings between logical and physical server paths.
Server Path ConfigConfigure the server path(s) the endpoint uses.
Server User ConfigConfigure server user accounts/credentials the endpoint uses.
Server User Config: FTP Auth PasswordAllow FTP authentication using a password.
Server User Config: FTP Auth CertificateAllow FTP authentication using a certificate.
Server User Config: FTP Auth Certificate & PasswordAllow FTP authentication using both a certificate and a password.
Server User Config: SFTP Auth PasswordAllow SFTP authentication using a password.
Server User Config: SFTP SSH KeyAllow SFTP authentication using an SSH key.
Triggers ConfigConfigure triggers that kick off actions on endpoint events.
ConnectionConfigure the endpoint's connection settings.

User Management

PermissionDescription
User Management: Get / ListView user accounts.
User Management: CreateCreate user accounts.
User Management: UpdateEdit user account settings.
User Management: DeleteDelete user accounts.
User Management: UnbanRestore access to a banned/locked-out user account.
User Management: Resend Activation EmailResend the account-activation email to a user.

Admin

PermissionDescription
Admin - Thru Nodes: ListView MFT Runtimes configured for the instance
Admin - Feature Flag: GetView feature flags controlling platform functionality.
Admin - Feature Flag: CreateCreate a feature flag.
Admin - Feature Flag: UpdateEdit a feature flag.
Admin - Feature Flag: DeleteDelete a feature flag.
Admin - Roles: GetView permission roles.
Admin - Roles: CreateCreate permission roles.
Admin - Roles: UpdateEdit permission roles.
Admin - Roles: DeleteDelete permission roles.
Admin - Roles: Assign Role to User/GroupAssign a role to a user or group.
API Key: GetView API keys.
API Key: CreateCreate an API key.
API Key: UpdateEdit an API key.
API Key: DeleteDelete an API key.
Admin - Retention: GetView data-retention policy settings.
Admin - Retention: CreateCreate a data-retention policy.
Admin - Retention: UpdateEdit a data-retention policy.
Admin - MFA: GetView multi-factor authentication settings.
Admin - MFA: UpdateUpdate multi-factor authentication settings.

Login / self-service permissions

PermissionDescription
User Basic AuthLets the user log in with a username and password.
User Profile Password Management (Forgot/Reset/Change)Lets the user use the forgot-password, reset-password, and change-password self-service flows.
User SSO AuthLets the user log in through single sign-on.
On this Page