Skip to main content

RBAC permission catalog

Every toggle you can grant under Settings → Organization → Roles & Permissions, organised by module group. Look here when you're building a custom role and want to know exactly what each switch does.

For the customer-facing how-to (creating roles, scoping data, inviting users), see Roles and permissions. That page is the workflow. This page is the catalog.

No UI on this page

This is a reference catalog, not a UI walkthrough. Every toggle listed here is set in the Roles & Permissions UI documented in Roles and permissions.

How to read the catalog

Each row pairs two things:

  • The UI toggle label, in bold. This is the exact string shown in the Roles & Permissions permission picker.
  • A one-sentence description of what flipping the toggle on grants the role.

The two flavours of view toggles (the View all… vs only for assigned… variants) are the scope-flagged pair. Enabling any one of the only for assigned toggles activates the Data Scope picker on the role page, where you choose which cloud accounts, identity sources, or devices the role can read. See Data scope: scoped vs all.

Tenant-admin bypass

The tenant-admin role bypasses every check on this page

The tenant-admin role short-circuits every per-permission check. Users with this role see every module, every record, and every action regardless of the toggles listed below. This is by design (the role is the workspace owner) and is not configurable.

If you need a user to have less than full access, build a custom role from the toggles below and assign them that role instead.

Permissions, by module

CSPM (Cloud Security)

UI toggleGrants
View all CSPM findings across all cloud accountsRead every CSPM finding across every connected cloud account.
View CSPM findings only for assigned cloud accountsRead CSPM findings only for cloud accounts assigned to the role via the Data Scope picker.

ISPM (Identity Security)

UI toggleGrants
View all ISPM findings across all accountsRead every ISPM finding across every identity source.
View ISPM findings only for assigned accountsRead ISPM findings only for identity sources assigned to the role.

SCM (Security Configuration)

UI toggleGrants
View all SCM findingsRead every SCM finding regardless of source.
View SCM findings only for assigned accountsRead SCM findings only for sources assigned to the role.

Active Directory

UI toggleGrants
View all Active Directory findingsRead every AD finding across every domain.
View AD findings only for assigned accountsRead AD findings only for domains assigned to the role.

FortiGate

UI toggleGrants
View all FortiGate findingsRead every FortiGate finding across every device.
View FortiGate findings only for assigned devicesRead FortiGate findings only for devices assigned to the role.

Compliance Frameworks

UI toggleGrants
View compliance frameworks (NIST, CIS, MITRE)Open the Compliance Hub and the three framework dashboards.
Export compliance reportsExport framework-level compliance reports.

Kanban Board

UI toggleGrants
View the remediation Kanban boardOpen the Hardening Kanban.
Move cards and manage Kanban workflowDrag cards between columns, use bulk actions, and run any status transition (also the prerequisite for self-claiming a finding).

Vulnerability Assignment

UI toggleGrants
Assign findings to other users (delegate)Assign findings to other tenant users (delegate ownership).
Force-release or reassign someone else's claimForce-release a stuck claim, take over someone else's assignment, and clean up assignments left by deactivated users.

Remediation Projects

UI toggleGrants
View remediation projectsOpen the Remediation Projects index and any project's detail page.
Create new remediation projectsOpen the create wizard and save a new project.
Edit, delete, and manage remediation projectsMark items resolved, accept risk on items, finalise a project, delete a project.

Security Exceptions

UI toggleGrants
View security exceptions registryRead the Security Exceptions registry.
Approve, reject, and manage security exceptionsCreate exceptions via Accept Risk, edit their lifecycle, revoke them.

Reports & Exports

UI toggleGrants
Generate and download PDF/SOW reportsTrigger every Executive, Technical, per-project, and drift export.
Who sees the Reports nav link

The Reports nav link is visible to workspace admins and to any custom role with the Generate and download PDF/SOW reports toggle on. The Executive Report dashboard further narrows what each user sees based on their Data Scope assignments. Workspace admins always see everything; scoped users see only their assigned cloud accounts.

Scans & Uploads

UI toggleGrants
Upload scan result filesUpload scan result files (Retrievy Agent submissions or manual uploads).
Trigger on-demand security scansTrigger an on-demand scan via Scan Now.

Settings: Cloud Accounts

UI toggleGrants
View cloud account configurationsRead cloud account configurations under Settings → Cloud Accounts.
Create, edit, and delete cloud accountsCreate, edit, and delete cloud accounts.

Settings: Sites

UI toggleGrants
Create, edit, and delete deployment sitesCreate, edit, and delete deployment sites used to group Retrievy Agent installations.

Settings: Agent Tokens

UI toggleGrants
View agent tokens and statusRead Retrievy Agent tokens and fleet status.
Create, rotate, and revoke agent tokensCreate, rotate, and revoke Retrievy Agent tokens.

Settings: FortiGate

UI toggleGrants
View FortiGate device configurationsRead FortiGate device configurations.
Manage FortiGate device connectionsAdd, edit, and remove FortiGate device connections.

Settings: SSO

UI toggleGrants
View SSO/SAML configurationRead the SSO / SAML provider list and configuration.
Configure SSO providers and enforcementAdd SSO providers, change enforcement mode, and remove providers.

Settings: Tenant

UI toggleGrants
View tenant configurationRead tenant configuration (name, timezone, basics).
Modify tenant name, timezone, and settingsModify tenant configuration.

Audit Trail

The Audit Trail permission group is only present in the role builder when the tenant's plan includes Detailed Audit Trail. On plans without it, the entire group is removed from the picker.

UI toggleGrants
View tenant audit logsOpen Settings → Organization → Audit Trail and read tenant audit events.

User Management

UI toggleGrants
View tenant user list and profilesRead the tenant user list and individual user profiles.
Invite, edit roles, and remove tenant usersInvite users, change a user's assigned role, remove a user. Also required to open the Roles & Permissions page.

Module access

Module access is governed automatically by whether your role holds any toggle inside that module's group. There is no separate switch to flip. If a role holds at least one toggle in, for example, the CSPM group, members of that role can open the CSPM dashboard; if every CSPM toggle is off, the module's nav entry is hidden and direct URLs return a permission error.

Plan-gated features

A handful of capabilities also depend on the workspace plan, regardless of any role toggle. Even a workspace admin cannot use these on a plan that does not include them.

FeatureWhere the limit shows upPlans that include it
Executive and Technical PDF ReportsThe Executive PDF and Technical PDF buttons on the Reports page return an upgrade message on Essentials. The per-project PDF export is not affected.Advanced, Build Your Own
FortiGate X-Ray Dependency GraphThe graph panel on the FortiGate Policy X-Ray and AD GPO X-Ray dashboards is hidden on Essentials.Advanced, Build Your Own
Single Sign-On (SSO)The SSO provider list on Settings → SSO shows a plan-upgrade banner on Essentials.Advanced, Build Your Own
Detailed Audit TrailThe Audit Trail nav entry and the Audit Trail permission group in the role builder are both hidden on Essentials.Advanced, Build Your Own

For the full per-plan matrix, see Plan feature matrix.