Skip to main content

Managing User Access

Flexera provides many different roles for access control to the features in Automation that should align well to the users in your organization. The following subsections describe how to manage user access in Flexera One Automation.

Policy Roles and Access Controls

info

Your account’s user with the Administer organization role provides user access to Automation roles. For complete descriptions of each role available in Flexera One, see Flexera One Roles.

To access the Automation user interface in Flexera One, you must be granted at least one of the Automation roles in at least one account. If you need access to an Automation role, contact your account’s user with the Administer organization role.

Access Levels

For all policy roles except Publish policies, the role can be granted to a user or group at either the organization or the account level. When a role is granted at the organization level, it effectively grants that role to every account that exists now and in the future in the organization. Another effect of organization-level roles is that those users will be able to use the Organization Summary view on many policy pages, which rolls up all information about policies and incidents into a single overview. For users with account-level access, they will only be able to see content on an account-by-account basis.

Granting Policy Roles

The account’s user with the Administer organization role is responsible for inviting and granting roles to Flexera One Automation users. For details, see Access Management.

Detailed Feature to Role Mapping

The following table describes which roles are needed to use the various features of Flexera One Automation.

Automation ScreenAutomation FeatureRoles that can use the Automation feature
CatalogView CatalogPublish policies
Create policies
Manage policies
Publish a Policy TemplatePublish policies
Un-Publish a Policy TemplatePublish policies
Delete Custom Policy TemplatePublish policies
Apply a PolicyCreate policies
Manage policies
Automation DashboardView DashboardCreate policies
Manage policies
View policies
Organizational SummaryOrganizational Roles:
Manage organization
Create policies
Manage policies
View policies
Applied PoliciesView Applied PoliciesCreate policies
Manage policies
View policies
Update a PolicyCreate policies
Manage policies
Terminate a PolicyCreate policies
Manage policies
Apply a Similar PolicyCreate policies
Manage policies
IncidentsView IncidentsCreate policies
Manage policies
View policies
Approve or Deny an ActionApprove policies
TemplatesView TemplatesPublish policies
Create policies
Update a Custom PolicyCreate policies
Apply a PolicyCreate policies
Delete a Custom Policy TemplateCreate policies
Publish a Policy TemplatePublish policies
CredentialsCreate/Edit/Delete CredentialsAdminister organization
List/Use CredentialsCreate policies
Manage policies

Policy-Specific Permissions

The policy roles described above grant users access to Flexera One Automation and its features. However, policies themselves have the ability to interact with any API which, in many cases, require permissions on that target API. The user that applies the policy must have the underlying privileges to access the resources needed by the policy. Each policy provided by Flexera documents its required permissions.