Permissions
Updated
Granular permissions refer to roles that can be assigned to users to limit their access. An admin user can configure these user roles by navigating to a user (Admin > User ) or during the user creation process. While default roles are generally adequate for most customers, in specific scenarios, customers may opt to create their own roles.
tip
You can layer your security roles for easy administration.
For example, a XYZ user has rights to manage flows and organizations under a role called “Worker”. When you want to provide the XYZ user with a limited administrator role, you can create an admin role called “Worker Admin” and assign it to the user by layering both “Worker” and “Worker Admin” roles.
System & Account
| Permission | Description |
|---|---|
| Audit APIs | View audit log entries recording user and system actions on the account. |
| Billing APIs | View billing and usage data for the account. |
| Global Search | Search across organizations, flows, and other objects from a single search bar. |
| Instance Admin APIs | Access administrative APIs for managing instance-level settings. |
File Activity
| Permission | Draft Description |
|---|---|
| File Activity | View file transfer activity and history records. |
| File Activity: Replay Files | Resend or reprocess a previously transferred file. |
| File Activity: Download Files | Download a file from its activity record. |
| File Activity: Delete Files | Delete a file from its activity record. |
Alerts
| Permission | Description |
|---|---|
| Alert: Get / List | View configured alerts and their current status. |
| Alert: Update Status | Change the status of an alert (for example, acknowledge or resolve it). |
Content API
| Permission | Description |
|---|---|
| Content API: File Upload | Upload files through the Content API. |
| Content API: File Download | Download files through the Content API. |
Organization
| Permission | Description |
|---|---|
| Organization: Get / List | View organization records. |
| Organization: Create | Create new organizations. |
| Organization: Update | Edit existing organization details. |
| Organization: Delete | Delete organizations. |
| Organization - Endpoint: Get / List | View endpoints configured under an organization. |
| Organization - Endpoint: Create | Create endpoints under an organization. |
| Organization - Endpoint: Update | Edit an organization's endpoint settings. |
| Organization - Endpoint: Delete | Delete an organization's endpoints. |
| Organization - Subscription: Get / List | View an organization's event/notification subscriptions. |
| Organization - Subscription: Create | Create subscriptions for an organization. |
| Organization - Subscription: Update | Edit an organization's subscriptions. |
| Organization - Subscription: Delete | Delete an organization's subscriptions. |
| Organization - PGP Key: Get/List | View PGP encryption keys stored for an organization. |
| Organization - PGP Key: Create | Add a PGP key to an organization. |
| Organization - PGP Key: Update | Edit an organization's PGP key. |
| Organization - PGP Key: Delete | Remove a PGP key from an organization. |
| Organization - SSH Key: Get / List | View SSH keys stored for an organization. |
| Organization - SSH Key: Create | Add an SSH key to an organization. |
| Organization - SSH Key: Update | Edit an organization's SSH key. |
| Organization - SSH Key: Delete | Remove an SSH key from an organization. |
| Organization - Certificate: Get / List | View certificates stored for an organization. |
| Organization - Certificate: Create | Add a certificate to an organization. |
| Organization - Certificate: Update | Edit an organization's certificate. |
| Organization - Certificate: Delete | Remove a certificate from an organization. |
| Organization - Thru Node: Get / List | View the MFT Runtimes in an organization |
| Organization - Thru Node: Create | Create an MFT Runtime in an organization |
| Organization - Thru Node: Update | Edit an MFT Runtime's configuration |
| Organization - Thru Node: Delete | Delete an MFT Runtime |
| Organization - Machine User: Get / List | View machine (non-interactive/API) user accounts for an organization. |
| Organization - Machine User: Create | Create a machine user for an organization. |
| Organization - Machine User: Update | Edit a machine user's settings. |
| Organization - Machine User: Delete | Delete a machine user. |
Flow
| Permission | Description |
|---|---|
| Flow: Get / List | View flows. |
| Flow: Create | Create new flows. |
| Flow: Update | Edit flow configuration. |
| Flow: Delete | Delete flows. |
| Flow: Export FileZilla Config | Export a flow's endpoint settings as a FileZilla client configuration file. |
| Flow: Export | Export a flow definition, for example for backup or migration. |
| Flow: Import | Import a flow definition. |
| Flow - Transfer Request: Get / List | View transfer requests generated by a flow. |
| Flow - Client Response: Get / List | View client response records for a flow. |
| Flow - Active Schedule: Get / List | View a flow's currently active schedules. |
| Flow - Endpoint: Get / List | View endpoints attached to a flow. |
| Flow - Endpoint: Create | Create endpoints for a flow. |
| Flow - Endpoint: Update | Edit a flow's endpoint settings. |
| Flow - Endpoint: Delete | Delete a flow's endpoints. |
| Flow - Endpoint: Run | Manually trigger a flow endpoint. |
| Flow - Subscription: Get / List | View a flow's event subscriptions. |
| Flow - Subscription: Create | Create subscriptions for a flow. |
| Flow - Subscription: Delete | Delete a flow's subscriptions. |
| Flow - History: Get / List | View a flow's version/change history. |
| Flow - History: Rollback | Revert a flow to a previous version. |
Flow Endpoint Configuration
| Permission group | Description |
|---|---|
| Alert Config | Configure alerts triggered by endpoint activity. |
| Anti Virus Config | Configure antivirus scanning for transferred files. |
| Compression Config | Configure file compression/decompression settings. |
| Main Config | Configure the endpoint's core/general settings. |
| Email Notification Config | Configure email notifications for endpoint events. |
| Encryption Config | Configure encryption settings (for example, PGP) applied to transferred files. |
| Processing Config | Configure rules for processing files after transfer. |
| Schedule Config | Configure the endpoint's transfer schedule. |
| Rename Option Config | Configure rules for renaming files during transfer. |
| Server Path Mapping Config | Configure mappings between logical and physical server paths. |
| Server Path Config | Configure the server path(s) the endpoint uses. |
| Server User Config | Configure server user accounts/credentials the endpoint uses. |
| Server User Config: FTP Auth Password | Allow FTP authentication using a password. |
| Server User Config: FTP Auth Certificate | Allow FTP authentication using a certificate. |
| Server User Config: FTP Auth Certificate & Password | Allow FTP authentication using both a certificate and a password. |
| Server User Config: SFTP Auth Password | Allow SFTP authentication using a password. |
| Server User Config: SFTP SSH Key | Allow SFTP authentication using an SSH key. |
| Triggers Config | Configure triggers that kick off actions on endpoint events. |
| Connection | Configure the endpoint's connection settings. |
User Management
| Permission | Description |
|---|---|
| User Management: Get / List | View user accounts. |
| User Management: Create | Create user accounts. |
| User Management: Update | Edit user account settings. |
| User Management: Delete | Delete user accounts. |
| User Management: Unban | Restore access to a banned/locked-out user account. |
| User Management: Resend Activation Email | Resend the account-activation email to a user. |
Admin
| Permission | Description |
|---|---|
| Admin - Thru Nodes: List | View MFT Runtimes configured for the instance |
| Admin - Feature Flag: Get | View feature flags controlling platform functionality. |
| Admin - Feature Flag: Create | Create a feature flag. |
| Admin - Feature Flag: Update | Edit a feature flag. |
| Admin - Feature Flag: Delete | Delete a feature flag. |
| Admin - Roles: Get | View permission roles. |
| Admin - Roles: Create | Create permission roles. |
| Admin - Roles: Update | Edit permission roles. |
| Admin - Roles: Delete | Delete permission roles. |
| Admin - Roles: Assign Role to User/Group | Assign a role to a user or group. |
| API Key: Get | View API keys. |
| API Key: Create | Create an API key. |
| API Key: Update | Edit an API key. |
| API Key: Delete | Delete an API key. |
| Admin - Retention: Get | View data-retention policy settings. |
| Admin - Retention: Create | Create a data-retention policy. |
| Admin - Retention: Update | Edit a data-retention policy. |
| Admin - MFA: Get | View multi-factor authentication settings. |
| Admin - MFA: Update | Update multi-factor authentication settings. |
Login / self-service permissions
| Permission | Description |
|---|---|
| User Basic Auth | Lets the user log in with a username and password. |
| User Profile Password Management (Forgot/Reset/Change) | Lets the user use the forgot-password, reset-password, and change-password self-service flows. |
| User SSO Auth | Lets the user log in through single sign-on. |