Skip to main content

Role-Based Access Control (RBAC)

Forward Enterprise provides support for Role-Based Access Control (RBAC). The following roles are available for the Org Admin to assign when creating users:

  • Org Admin: Admin user with full access to the platform and all its settings, including Network creation, and user account management.
  • Network Admin: A Network Admin has full access to all Forward applications for the network and can configure the network, including its collection settings.
  • Network Operator: A Network Operator has full access to all Forward applications for the network, but they cannot configure network settings or trigger Snapshot collection. An exception is made for Workspace Networks, where the Network Operator role is upgraded to Network Admin for the specific workspace network.
  • Read-only: A Read-only user has only view (read) access to the network. They cannot create new data, nor change any settings.
  • Limited Read-only: Limited Read-only users are restricted Read-only users, with no access to sensitive data like configuration and state files of the network devices, nor to any application that could expose them (NQE, Inventory+, and Security applications).

Settings

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorNetwork AdminOrg Admin
Personal
Personal - PreferencesYesYesYesYesYes
Personal - AccountYesYesYesYesYes
Personal - NotificationsYesYesYesYesYes
Accounts
Accounts - User accounts (includes accounts creation/editing/deleting)NoNoNoNoYes
Accounts - Login (includes 2FA)NoNoNoNoYes
Accounts - Login NoticeNoNoNoNoYes
Accounts - TACACSNoNoNoNoYes
Accounts - SSONoNoNoNoYes
System
System - General (includes session mgmt, password strength, experimental features)NoNoNoNoYes
System - Software UpdateNoNoNoNoYes
System - Backup / RestoreNoNoNoNoYes
System - Database Import / ExportNoNoNoNoYes
System - IntegrationsNoNoNoNoYes
System - License KeyNoNoNoNoYes
System - Licensed DevicesNoNoNoNoYes
System - Notification SettingsNoNoNoNoYes
System - SMTP SettingsNoNoNoNoYes
System - System OverviewNoNoNoNoYes
System - WebhooksNoNoNoNoYes

Network

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorNetwork AdminOrg Admin
Devices
Devices - ViewYesYesYesYesYes
Devices - EditNoNoNoYesYes
Virtualization (NSX, ESX)
Virtualization (NSX, ESX) - ViewYesYesYesYesYes
Virtualization (NSX, ESX) - EditNoNoNoYesYes
Cloud Accounts
Cloud Accounts - ViewYesYesYesYesYes
Cloud Accounts - EditNoNoNoYesYes
Cloud Account Proxy SettingsNoNoNoYesYes
Access Credentials
Credentials - View and EditNoNoNoYesYes
Jump Servers - View and EditNoNoNoYesYes
Collection
Collection Schedule - ViewNoNoNoYesYes
Collection Schedule - EditNoNoNoYesYes
Collection TriggeringNoNoNoYesYes
Platform
Dashboard - ViewYesYesYesYesYes
NQE (create/edit/delete query)NoMaybe*Maybe**Maybe**Yes
NQE (run query, Verify checks)NoYesYesYesYes
Snapshots - RestoreNoNoYesYesYes

* By default, No, but permission can be granted for specific directories

** By default, Yes, but permission can be revoked for specific directories


Network Snapshots (Forward Apps)

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorNetwork AdminOrg Admin
Search
SearchYesYesYesYesYes
Search - Path AnalysisYesYesYesYesYes
Search - View device configuration and stateNoYesYesYesYes
Verify
Verify - View NQE checksNoYesYesYesYes
Verify - View other checksYesYesYesYesYes
Verify - Add/edit/delete checksNoNoYesYesYes
Security
Security Matrix - ViewNoYesYesYesYes
Security Matrix - Add/edit/deleteNoNoYesYesYes
Security Blast RadiusNoYesYesYesYes
Security VulnerabilityNoYesYesYesYes
Security ExposureNoYesYesYesYes
Platform
DiffsYesYesYesYesYes
InventoryNoYesYesYesYes
Objects - ViewYesYesYesYesYes
Objects - Add/edit/deleteNoNoYesYesYes
note

Workspace networks inherit the permissions configured for their parent network except that a Network Operator is effectively promoted to a Network Admin for any Workspace Network that they create for a period of time that can be configured by an Org Admin.

For more details, visit the Workspace Networks page.