Platform Administration
Permissions reference
Permissions used to delegate Organization Control and platform-administration tasks.
Built-in organization roles are owner, administrator, and helpdesk. Built-in platform roles are platform_owner and platform_admin. Custom roles can be assigned only the permissions needed for their responsibilities.
| Area | Permissions |
|---|---|
| Organization users | users.view, users.edit, users.invite |
| Organization configuration | config.tenant, config.preferences, audit.view, analytics.view |
| Base Templates | template.view.main, template.edit.main, template.publish.main |
| Modules | template.view.addtl, template.edit.addtl, template.publish.addtl |
| Template and Module Assignments | The assignment view or edit permission for the required template type and user, group, or domain scope. |
| Attributes | The attribute view or edit permission for the required user, group, or domain scope. |
| Platform administration | license.view, platform.preferences, platform.users.view, platform.users.edit, nodes.view, nodes.edit, certificates.manage, organizations.view, organizations.edit, platform.analytics.view, audit.view |
Grant the minimum permissions needed for the user’s work. Review custom roles after a personnel change or when introducing a new administrative process.