User (Reader Privileges)

You can create a new user role “Reader” (read-only-access permissions), and assign it to users. The user with the Reader role can only view the data displayed in the module.

Permissions: Only users with access to the Administration module can create users with the reader role.

A new sub-user will take at least 5 minutes for their privileges to be reflected in .

What can the Reader User do?

The user with reader role can

  • View connectors
  • Monitor controls, policies, and resources
  • Create and edit dashboards
  • Access to reports (inherits permissions assigned by the Manager user)

The user with the reader role cannot create a connector or evaluate controls or policies.

To view Policy, Control, and Exception data, the role must include the Policy, Control and Exception Access permission - without it, the Policy and Posture tabs are hidden entirely, regardless of other Reader permissions. If the user needs read-only visibility into Policy, Control, and Exception data specifically (without the rest of the module's Reader access), assign the predefined TotalCloud Policy Reader role instead. Visibility can also be limited to a subset of Policies and Controls using tags. See Scope Based Access Control.

Quick Steps

  1. Create a Reader User: Navigate to Administration module > User Management > Create User > Create Reader User.
    Navigation to create Reader User in Administration utility.
  2. Create a role in Administration utility and ensure that the role has UI access permission and all permissions listed enabled.
    Permissions to be configured for reader role.
  3. Select Assign Global Reporting Permissions from the Reporting permissions to provide the Reader access to Reports. For more information, refer to Reporting Permission.
  4. Assign the role to the newly created user.

The new reader user is ready to use with monitoring capabilities.