Every toggle you can grant under Settings → Organization → Roles & Permissions, organised by module group. Look here when you're building a custom role and want to know exactly what each switch does.
For the customer-facing how-to (creating roles, scoping data, inviting users), see Roles and permissions. That page is the workflow. This page is the catalog.
No UI on this page
This is a reference catalog, not a UI walkthrough. Every toggle listed here is set in the Roles & Permissions UI documented in Roles and permissions.
The UI toggle label, in bold. This is the exact string shown in the Roles & Permissions permission picker.
A one-sentence description of what flipping the toggle on grants the role.
The two flavours of view toggles (the View all… vs only for assigned… variants) are the scope-flagged pair. Enabling any one of the only for assigned toggles activates the Data Scope picker on the role page, where you choose which cloud accounts, identity sources, or devices the role can read. See Data scope: scoped vs all.
The tenant-admin role bypasses every check on this page
The tenant-admin role short-circuits every per-permission check. Users with this role see every module, every record, and every action regardless of the toggles listed below. This is by design (the role is the workspace owner) and is not configurable.
If you need a user to have less than full access, build a custom role from the toggles below and assign them that role instead.
Trigger every Executive, Technical, per-project, and drift export.
Who sees the Reports nav link
The Reports nav link is visible to workspace admins and to any custom role with the Generate and download PDF/SOW reports toggle on. The Executive Report dashboard further narrows what each user sees based on their Data Scope assignments. Workspace admins always see everything; scoped users see only their assigned cloud accounts.
The Audit Trail permission group is only present in the role builder when the tenant's plan includes Detailed Audit Trail. On plans without it, the entire group is removed from the picker.
UI toggle
Grants
View tenant audit logs
Open Settings → Organization → Audit Trail and read tenant audit events.
Module access is governed automatically by whether your role holds any toggle inside that module's group. There is no separate switch to flip. If a role holds at least one toggle in, for example, the CSPM group, members of that role can open the CSPM dashboard; if every CSPM toggle is off, the module's nav entry is hidden and direct URLs return a permission error.
A handful of capabilities also depend on the workspace plan, regardless of any role toggle. Even a workspace admin cannot use these on a plan that does not include them.
Feature
Where the limit shows up
Plans that include it
Executive and Technical PDF Reports
The Executive PDF and Technical PDF buttons on the Reports page return an upgrade message on Essentials. The per-project PDF export is not affected.
Advanced, Build Your Own
FortiGate X-Ray Dependency Graph
The graph panel on the FortiGate Policy X-Ray and AD GPO X-Ray dashboards is hidden on Essentials.
Advanced, Build Your Own
Single Sign-On (SSO)
The SSO provider list on Settings → SSO shows a plan-upgrade banner on Essentials.
Advanced, Build Your Own
Detailed Audit Trail
The Audit Trail nav entry and the Audit Trail permission group in the role builder are both hidden on Essentials.