Assign Role to Users
Applicable for Manager Roles
Use the Administration module to view and manage users and grant access to the application. On the User Management tab, you will see the apps each user can access. Access is role-based.
You can also refer to the online help available in the Administration utility for detailed information.
Tell me the steps
In the Administration utility, go to Users > Role Management. This is where you create new roles and change the permissions for existing ones. You can also quickly assign roles to users from here.
Don't see this tab?
You need to have
- Full permissions and scope
Or, - A role with the "Access Role Management Section" permission enabled in the Administration utility.
Tell me about various roles?
You can configure two types of user roles:
- User with all privileges: We provide a predefined role named "TOTALCLOUD user". Assign the role to the required user, and the user is granted full access. Learn more
- User with Reader privileges: The user with the Reader role can only view the data displayed in the module. Click New Role. Give the role a name and description, then select the modules and permissions to grant to a user when the role is assigned. Learn more
For Policy, Control, and Exception governance specifically, two additional predefined roles are available:
- TotalCloud Policy Admin: Full create, edit, and delete access to Policy, Control, and Exception management.
- TotalCloud Policy Reader: Read-only visibility into Policy, Control, and Exception configuration, without the broader module access granted by the standard Reader role.
You are not limited to these predefined roles - every Policy and Control permission is individually selectable when building a custom role. See Scope Based Access Control for the full permission list and how to optionally scope a role's visibility using tags.
How do I assign roles to users?
Select the role you want to assign, then choose "Add To Users" from the Quick Actions menu. Select the users to assign the role to, then click Save. You can remove roles from users similarly by selecting the Remove From Users action.
How do I edit a role?
Select any role in the list and choose Edit from the Quick Actions menu.
You can change the role name and description and edit the assigned permissions. Any changes you make to a role will apply to all users assigned that role.
Be careful when removing the UI access permission from a role. A user cannot log into the UI if they don't have at least one role with the UI access permission assigned.
Tell me about permissions
When you're editing the permissions for a role, you'll notice that you can define application access, modules to be accessible, and permissions within the module for the users with the current role. Currently, you can configure two types of users. Depending on the permissions you assign to the role, you could categorize the users with all permissions or read-only permissions.
Ensure that you have assigned the module to be accessible for the users. Click the title of a group to expand its permissions. Then select the permissions you want to assign to the role.
- All privileges: User will have all the privileges in except creating and managing other users.
- Reader privileges: User with Reader role can only view the data displayed in module.
The Policy, Control and Exceptions group lets you assign view, create/clone, edit, and delete permissions independently for Policies, Controls, and exceptions. The read permission (Policy, Control, and Exception Access) is mandatory and must be granted to a role to see the Policy and Posture tabs at all; it can also be granted on its own to create a read-only role. These permissions can optionally be combined with tag-based scoping so a role only applies to a defined subset of Policies and Controls. See Scope Based Access Control for the full permission list and scoping details.

Add / Remove permissions for multiple roles at once
You can add or remove permissions from multiple roles in a single action. Select the roles you want to change and then select Add Permissions or Remove Permissions from the Quick Actions menu. Then, tell us which permissions the action applies to and click Save.
Can I delete a role?
Yes. Select the role and choose Delete from the Quick Actions menu. The role you delete will no longer be assigned to users. It is removed automatically from all users' accounts (that had it previously assigned), and those users will no longer have the permissions granted by the role.
If you edit permissions for a pre-defined role or delete a pre-defined role, the user associated with the roles you edit can experience difference in access behavior.