Complete list of permissions applicable for user roles

Permission

Default binded to role

Mandatory

Optional

Description

Cross Application Administrators

Configurable

admin | app admin |

Associated by default

Yes


Administrators have cross applications privileges
Operational note: treated as super-admin.

Application Administrators

Configurable

app admin |

Associated by default

Yes


Application Administrators have permision to manage accounts,devices and see reports Operational note: treated as super-admin

System Administrators

Configurable

sysconfig |

Associated by default


yes


System Administrators manage system settings, device settings, run scripts Operational note: treated as super-admin

Certificate Administrators

Configurable only


Yes

Certificate Administrators manage system and devices certificates

ACL Administrator

Configurable only


Yes


License Administrators

Configurable only


Yes

User can manage license agreement

Configuration settings administrators

Configurable only


Yes

User can manage system settings and device configuration settings

Invitation code management

Configurable only


Yes

User can do invitation code management

Enrolment tracker control

Configurable only


Yes

User can do enrolment tracker control

Reset user PIN

techsupport

Yes


User can reset independent PIN for any identity

Run configuration settings

Configurable only


Yes

User can run scripts to update system settings and device settings

Write license agreement

Configurable only


Yes

User can update license agreement

Write configuration settings

Configurable only


Yes

User can write system settings and device configuration settings

Full Access to Orchestrator

Configurable only


Yes

Grants the user permission to view and modify orchestrator data.

Read license agreement

Configurable only 


Yes

User has read only access to license agreement

Read configuration settings

Configurable only 


Yes

User has read only access to system settings and device configuration settings

Monitoring data

Configurable only 


Yes

User can visualize monitoring part under tools

Dashboard data

Configurable only 


Yes

User can visualize dashboard screen

View AD details

Configurable only 


Yes

User can visualize AD details

View location

Configurable only 


Yes

User can visualize location

View ILP info

Configurable only 


Yes

User can visualize ILP info

View session details raw

Configurable only 


Yes

User can visualize session details raw

View history details

Configurable only 


Yes

User can visualize history details

Read-Only Access to Orchestrator

Configurable only 


Yes 

Grants the user permission to view orchestrator data without making any modifications.

Unblock identity

techsupport |

Yes



Technical Support

techsupport |

Yes



Devices administrators



Yes

User can manage devices

Accounts administrators

Configurable only 


Yes

User can manage accounts

Permissions administrators

Configurable only 


Yes

User can manage permissions

Members profiles administrators

Configurable only 


Yes

User can manage members profiles

Early warning system administrators

Configurable only 


Yes

User can manage data of Early Warning System

Mobile settings administrators

Configurable only 


Yes

User can manage mobile settings

Accounts sites administrators

Configurable only 


Yes

User can manage accounts sites

Alerts Administrators

alerts

Yes


User can manage alerts

Run test

tester 

Yes


User can run maintenance tests

Analyse data

analyst

Yes


User can analyse statistics data

Deprovision identities

Configurable only


Yes

User can view and deprovision current identities

View all users

Configurable only 


Yes

User does not have user segregation rule applied Disables user segregation when segregation is enabled.

Execute EWS job

Configurable only 


Yes

User can execute EWS jobs

Run mobile settings

Configurable only 


Yes

User can run scripts to update mobile settings

Write devices

Configurable only 


Yes

User can write devices definitions

Write accounts

Configurable only 


Yes

User can write accounts definitions

Write permissions

Configurable only 


Yes


Write members profiles

Configurable only 


Yes


Write EWS data

Configurable only 


Yes


Write mobile settings

Configurable only 


Yes


Wrote accounts sites

Configurable only 


Yes


Write alerts

Configurable only 


Yes


Read devices

Configurable only 


Yes


Read accounts

Configurable only 


Yes


Read permissions

Configurable only 


Yes


Read members profiles

Configurable only 


Yes


Read EWS data

Configurable only 


Yes


Read mobile settings

Configurable only 


Yes


Read accounts sites

Configurable only 


Yes


Read alerts

Configurable only 


Yes

User has read only access to alerts

Infrastructure operations

Configurable only 


Yes

User perform changes on Infrastructure Review flag: used by infrastructure endpoints;

Write device status

Configurable only 


Yes

User can change device status Review flag: used by device status endpoints;

Write account status

Configurable only 


Yes

User can change account status Review flag: used by identity status endpoints;

ILP View Statistics

appadmin, admin, sysconfig 

Yes


User can visualize ILP statistics Review flag: used by Kibana/ILP statistics endpoints

System history

Configurable only 


Yes

User can access system history

System logging

Configurable only 


Yes

User can access system logs

User can load reports

reports



User can load reports

View accounty History





View Device History

Configurable only 


Yes

User can view the device history table and details

Use invitation contact details

Configurable

appadmin, admin 

Associated by default

Yes


Dedicated permission to manage Enrollment Code generation to use invitation contact details. Used when enrollment code generation validates invitation contact details.

Users sessions

Configurable only 


Yes

User read sessions statistics

Default client access

active

Yes


Default user access to application functionalities

Shared device access

shareddevice |

Yes


Shared device access to application functionalities

Default user

active | default | shareddevice |

Yes


User is registered in the system with no access to application functionalities

SSP access

| default |

Yes


User is registered in the system with no access to application functionalities

Enroll Account

default |

Yes


User can enroll account Used by delegated SSP enrollment checks.

Configuration examples:

Role: active

Example 1: Configuration of active role ( including group access : e.g: Users)

→ limited access of functions of Administrator Dashboard (wesecadmin) due to role being binded to group Users

image-20260616-111643.png


Access example :

image-20260616-111501.png

View of active role access in Admin Dashboard

image-20260616-111535.png


Management of this access role after creation:

image-20260616-111854.png

Example 2: Configuration of active role ( including group access : e.g: Administrators)

image-20260616-112102.png


Management of this access role after creation:

→ full access rights because the group associated is Administrators

image-20260616-112222.png



Role: admin

Configuration examples:

Example : Configuration of Admin role ( including group access : e.g: Users)

Access example :

image-20260616-123015.png
image-20260616-123027.png


Management of this access role after creation:

image-20260616-123118.png


Role: alerts

Configuration examples:

Example : Configuration of Alerts role ( including group access : e.g: Alerts)

→ Restricted access due to group Alerts

Access example :

image-20260616-113701.png

Management of this access role after creation:

image-20260616-113737.png


Example 2: Configuration of Alerts role ( including group access : e.g: SystemAdmins)

Access example :

image-20260616-114308.png


Management of this access role after creation:

→ Full access rights due to group SystemAdmins

image-20260616-114417.png


image-20260616-114142.png


Role: analyst

Role:

Example : Configuration of Analyst role ( including group access : e.g: Analyst)

Access creation example:

image-20260616-114700.png


Access example :

image-20260616-114747.png


image-20260616-114807.png


Management of this access role after creation:

image-20260616-114907.png


Role: appadmin

Configuration examples:

Role: AppAdmin

Configuration of AppAdmin role ( including group access : e.g: AppAdmin)

Access example :

image-20260616-115155.png
image-20260616-115211.png


Management of this access role after creation:

image-20260616-115226.png


Role: default

Configuration examples:

Configuration of Default role ( including group access : e.g: AutoTest)

Access example :

image-20260616-123544.png
image-20260616-123601.png


Management of this access role after creation:

image-20260616-123620.png

Role: autotest

Configuration examples:

Role: Autotest

Configuration of Autotest role ( including group access : e.g: Autotest)

Access example :

image-20260616-115634.png
image-20260616-115643.png


Management of this access role after creation:

Example : Configuration of Autotest role ( including group access : e.g: Autotest)

image-20260616-115719.png


Role: reports

Configuration examples:

Role: Reports

Configuration of Reports role ( including group access : e.g: Reports)

Access example :

image-20260616-120309.png
image-20260616-120325.png


Management of this access role after creation:

Example : Configuration of Autotest role ( including group access : e.g: Reports)

image-20260616-120357.png


Role: shareddevice

Configuration examples:

Configuration of SharedDevice role ( including group access : e.g: Finance)

Access example :

image-20260616-120714.png


image-20260616-120731.png


Management of this access role after creation:

Example : Configuration of SharedDevice role ( including group access : e.g: Finance)

image-20260616-120810.png


Role: sysconfig

Configuration examples:

Example : Configuration of Sysconfig role ( including group access : e.g: Sales)

image-20260616-121545.png



Access example :

image-20260616-121528.png


image-20260616-121626.png


Management of this access role after creation:


Example : Configuration of Sysconfig role ( including group access : e.g: Sales)

image-20260616-121640.png


Role: techsupport

Configuration examples:

Example : Configuration of TechSupport role ( including group access : e.g: TechSupport)

Access example :

image-20260616-121938.png
image-20260616-122014.png

Management of this access role after creation:

image-20260616-121913.png


Role: tester

Configuration examples:

Example : Configuration of Tester role ( including group access : e.g: Testers)

Access example :


image-20260616-122213.png
image-20260616-122235.png


Management of this access role after creation:

image-20260616-122254.png

Last updated: