Skip to main content

Role-Based Access Control (RBAC)

Forward Enterprise supports Role-Based Access Control (RBAC), enabling organizations to manage user permissions with precision and align access with job responsibilities. This ensures that users only have access to the data and actions necessary for their role, improving both security and operational efficiency.

The following roles are available:

  • Org Admin: Admin user with full access to the platform and all its settings, including Network creation, and user account management.
  • Network Admin: A Network Admin has full access to all Forward applications for the network and can configure the network, including its collection settings.
  • Network Operator: A Network Operator has full access to all Forward applications for the network, but they cannot configure network settings or trigger Snapshot collection.
  • Workspace Operator: Assigned automatically when you create a workspace network (when credential copying is enabled). Has all Network Operator capabilities plus the ability to trigger snapshot collection, copy and delete sources, view credentials, proxies, and jump servers, and edit or delete snapshots and networks. Cannot add or edit devices or credentials, or upload or invalidate snapshots. See Workspace Network RBAC for details.
  • Read-only: A Read-only user has only view (read) access to the network. They cannot create new data, nor change any settings.
  • Limited Read-only: Limited Read-only users are restricted Read-only users, with no access to sensitive data like configuration and state files of the network devices, nor to any application that could expose them (NQE, Inventory+, and Security applications).

Settings

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorWorkspace OperatorNetwork AdminOrg Admin
Personal
Personal - PreferencesYesYesYesYesYesYes
Personal - AccountYesYesYesYesYesYes
Personal - NotificationsYesYesYesYesYesYes
Accounts
Accounts - User accounts (includes accounts creation/editing/deleting)NoNoNoNoNoYes
Accounts - Login (includes 2FA)NoNoNoNoNoYes
Accounts - Login NoticeNoNoNoNoNoYes
Accounts - TACACSNoNoNoNoNoYes
Accounts - SSONoNoNoNoNoYes
System
System - General (includes session mgmt, password strength, experimental features)NoNoNoNoNoYes
System - Software UpdateNoNoNoNoNoYes
System - Backup / RestoreNoNoNoNoNoYes
System - Database Import / ExportNoNoNoNoNoYes
System - IntegrationsNoNoNoNoNoYes
System - License KeyNoNoNoNoNoYes
System - Licensed DevicesNoNoNoNoNoYes
System - Notification SettingsNoNoNoNoNoYes
System - SMTP SettingsNoNoNoNoNoYes
System - System OverviewNoNoNoNoNoYes
System - WebhooksNoNoNoNoNoYes

Network

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorWorkspace OperatorNetwork AdminOrg Admin
Devices
Devices - ViewYesYesYesYesYesYes
Devices - EditNoNoNoNoYesYes
Virtualization (NSX, ESX)
Virtualization (NSX, ESX) - ViewYesYesYesYesYesYes
Virtualization (NSX, ESX) - EditNoNoNoNoYesYes
Cloud Accounts
Cloud Accounts - ViewYesYesYesYesYesYes
Cloud Accounts - EditNoNoNoNoYesYes
Cloud Account Proxy - ViewNoNoNoYesYesYes
Cloud Account Proxy - EditNoNoNoNoYesYes
Access Credentials
Credentials - ViewNoNoNoYesYesYes
Credentials - EditNoNoNoNoYesYes
Jump Servers - ViewNoNoNoYesYesYes
Jump Servers - EditNoNoNoNoYesYes
Collection
Collection Schedule - ViewNoNoNoYesYesYes
Collection Schedule - EditNoNoNoYesYesYes
Collection TriggeringNoNoNoYesYesYes
Platform
Dashboard - ViewYesYesYesYesYesYes
NQE (create/edit/delete query)NoMaybe*Maybe**Maybe**Maybe**Yes
NQE (run query, Verify checks)NoYesYesYesYesYes
Snapshots - RestoreNoNoYesYesYesYes

* By default, No, but permission can be granted for specific directories

** By default, Yes, but permission can be revoked for specific directories


Network Snapshots (Forward Apps)

FunctionalityLimited Read-OnlyRead-OnlyNetwork OperatorWorkspace OperatorNetwork AdminOrg Admin
Search
SearchYesYesYesYesYesYes
Search - Path AnalysisYesYesYesYesYesYes
Search - View device configuration and stateNoYesYesYesYesYes
Verify
Verify - View NQE checksNoYesYesYesYesYes
Verify - View other checksYesYesYesYesYesYes
Verify - Add/edit/delete checksNoNoYesYesYesYes
Security
Security Matrix - ViewNoYesYesYesYesYes
Security Matrix - Add/edit/deleteNoNoYesYesYesYes
Security Blast RadiusNoYesYesYesYesYes
Security VulnerabilityNoYesYesYesYesYes
Security ExposureNoYesYesYesYesYes
Platform
DiffsYesYesYesYesYesYes
InventoryNoYesYesYesYesYes
Objects - ViewYesYesYesYesYesYes
Objects - Add/edit/deleteNoNoYesYesYesYes

Workspace Network RBAC

The Workspace network follows the role-based access control (RBAC) outlined for the parent network. The role assigned to the workspace creator depends on their role in the parent network and whether credential copying is enabled:

  • Org Admin or Network Admin in the parent network — Always receives Network Admin on the workspace, regardless of the credential copying setting.
  • Network Operator in the parent network, credential copying enabled — Elevated to Workspace Operator. This role sits between Network Operator and Network Admin. Workspace Operators can trigger and cancel collections, run connectivity tests, copy sources from the parent network, delete sources and snapshots, view credentials and jump servers (but not edit them), edit collection schedules, and edit snapshot and network metadata (name, note). They cannot add or edit devices, edit credentials, upload or invalidate snapshots, or modify network-level settings.
  • Network Operator in the parent network, credential copying disabled — Elevated to Network Admin, since credentials must be provided manually and cannot be copied from the parent network.

Read-only and Limited Read-only users cannot create workspace networks.

note

The Workspace Operator role applies only to newly created workspace networks. Existing workspaces are not migrated — users who were previously elevated to Network Admin on an existing workspace retain that role.

Workspace Operator Permissions

The Workspace Operator role sits between Network Operator and Network Admin. The following table summarizes what you can and cannot do as a Workspace Operator:

ActionAllowed
All Network Operator actionsYes
Trigger snapshot collection and connectivity testsYes
Copy sources from parent network to workspaceYes
Delete sourcesYes
View credentials, proxies, and jump serversYes
Edit and delete snapshotsYes
Edit and delete networksYes
Assign roles to workspace network (up to Workspace Operator)Yes
Add or edit devicesNo
Edit credentialsNo
Upload or invalidate snapshotsNo

Copying Sources Between Networks

The required roles for copying sources depend on the type of networks involved:

Source NetworkTarget NetworkRequired Role in SourceRequired Role in Target
RegularRegularNetwork AdminNetwork Admin
ParentWorkspaceNetwork Operator or higherWorkspace Operator or higher
note

As a Network Operator, you can no longer copy sources between two regular (non-workspace) networks. This operation now requires Network Admin in both the source and target networks.

For more details, visit the Workspace Networks page.