# Role-Based Access Control (RBAC) Reference

Role-Based Access Control (RBAC) provides a structured approach to managing permissions within the Apono UI. By aligning access rights with specific job responsibilities, RBAC prevents unauthorized or conflicting administrative actions.

RBAC is especially powerful for enabling collaboration across multiple teams and professionals with different objectives. Each team member receives precisely the access they need to perform their specific tasks. At the same time, RBAC maintains overall system security and operational integrity.

{% hint style="info" %}
To learn more about managing user roles in Apono, click [here](https://docs.apono.io/docs/user-administration/manage-identities#edit-an-identity).
{% endhint %}

***

### Role Overview

You can assign any of the following roles to each user.

<table><thead><tr><th width="178">Role</th><th>Description</th></tr></thead><tbody><tr><td><strong>Admin</strong></td><td><p>Full access to all features and functionalities</p><p><strong>Usage</strong>: Only role authorized to create, delete, and assign roles to users</p></td></tr><tr><td><strong>Space Owner</strong></td><td><p>Management of membership and access objects within a specific space, with view-only access outside that space</p><p><strong>Usage:</strong> Invites members, assigns member roles, and manages access objects</p></td></tr><tr><td><strong>Space Manager</strong></td><td><p>Management of access objects within a specific space, with view-only access outside that space</p><p><strong>Usage:</strong> Handles day-to-day management of access objects within a specific space</p></td></tr><tr><td><strong>Power User</strong></td><td><p>Access to most features except some user and account settings</p><p><strong>Usage</strong>: Manages daily administrative tasks</p></td></tr><tr><td><strong>Deployment</strong></td><td><p>Permissions focused on infrastructure and deployment management</p><p><strong>Usage</strong>: Ensures seamless deployment and infrastructure integrity</p></td></tr><tr><td><strong>Viewer</strong></td><td><p>Read-only access to reports and auditing functionalities</p><p><strong>Usage</strong>: Monitors compliance and administrative activity without modifying resources</p></td></tr><tr><td><strong>Grantee</strong></td><td><strong>(</strong><a href="#portal"><strong>Portal UI</strong></a> <strong>only)</strong> Permissions focused on requesting and accessing resources<br><strong>Usage</strong>: Requests resources and connects to granted resources</td></tr></tbody></table>

***

### Permissions

The following tables detail the permissions available to each role within the Apono UI.

#### Overview

Dashboard

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="100">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr></tbody></table>

Right Sizing

*Ensures your access flows grant the least-privileged access to users.* [*Learn more*](https://docs.apono.io/docs/access-flows/manage-access-flows/right-sizing)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Filter</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr></tbody></table>

Access Graph

*Visualizes how access is granted to resources, whether JIT, via group membership or with standing access*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Filter</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr></tbody></table>

Anomalies

*Safeguards against potential risky access to your tools.* [*Learn more*](https://docs.apono.io/docs/architecture-and-security/anomalies)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Filter</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr></tbody></table>

Access Discovery

*Assesses and remediated standing access to improve your cloud security posture.* [*Learn more*](https://docs.apono.io/docs/getting-started/access-discovery)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>Explore</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Revoke Standing Access</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr></tbody></table>

#### Access Management

Access Flows

*Enables creating automated, dynamic permission workflows that define access to sets of resources.* [*Learn more*](https://docs.apono.io/docs/access-flows/access-flows)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the access flow list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Filter the access flow list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Get an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Create an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Edit an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Enable an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Disable an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Delete an access flow</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr></tbody></table>

Bundles

*Manages access to integrations, roles, and resources by grouping them together.* [*Learn more*](https://docs.apono.io/docs/access-flows/create-bundles)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the bundles list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Get a bundle</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Create a bundle</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Edit a bundle</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Delete a bundle</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr></tbody></table>

#### Environment

Integrations

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the integration list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Get an integration</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>View the catalog</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Connect an integration</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Edit an integration</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Refresh an integration</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td></tr><tr><td>Delete an integration</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr></tbody></table>

Connectors

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the connector list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Connect a connector</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Edit a connector</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Delete a connector</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr></tbody></table>

Identities

*Allows restricting resource access by creating specified, authenticated users or groups.* [*Learn more*](https://docs.apono.io/docs/user-administration/create-identities)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View users</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Add a user</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Create a group</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr><tr><td>Edit a group</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr><tr><td>Delete a group</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr></tbody></table>

Inventory

*Enables creating and managing queries of dynamic, reusable groups of resources.* [*Learn more*](https://docs.apono.io/docs/inventory/access-scopes)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the access scope list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Filter the access scope list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Create an access scope</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Edit an access scope</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr><tr><td>Delete an access scope</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td></td></tr></tbody></table>

#### Administration

Activity

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the activity list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Filter the activity list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Revoke access in drawer</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr><tr><td>Revoke all</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr></tbody></table>

Reports

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the report list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Get a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Create a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Edit a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Export a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Schedule a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr><tr><td>Delete a report</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td></td><td>✅</td></tr></tbody></table>

Session Audit

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View a session audit</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>

Audit Log (Syslog)

*Tracks system changes with a clear, chronological audit log for accountability and quick investigation.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the audit log list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Filter the audit log list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Click the audit log drawer</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Export the audit log</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>

Webhooks

*Sends Apono access request data to your internal systems with event-triggered HTTP messages.* [*Learn more*](https://docs.apono.io/docs/webhook-integrations/intro-to-apono-outbound-webhooks)*.*

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View the webhook list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>View webhook history</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Create a webhook</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Edit a webhook</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Enable a webhook</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Disable a webhook</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr><tr><td>Delete a webhook</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td></td></tr></tbody></table>

#### Identity and Access Management (IAM) Administration

General (Settings)

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View settings</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td>✅</td></tr><tr><td>Manage settings</td><td>✅</td><td></td><td></td><td>✅</td><td></td><td></td></tr></tbody></table>

Profile

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>Edit profile (individual)</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>

Privacy & Security

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td><a href="../../architecture-and-security/multi-factor-authentication#enable-mfa-for-a-requester-account">Enable MFA</a> (individual)</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>

Account Details

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View account details</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Edit account details</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr></tbody></table>

Users

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View users list</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Resend invitation email</td><td>✅</td><td></td><td></td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Invite users</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Edit roles of users</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Log out user sessions</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Disable user</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Delete user</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr></tbody></table>

#### API Tokens

Personal API Tokens

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>View an API token</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Create an API token</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Delete an API token</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>

Service Account API Tokens

<table data-full-width="false"><thead><tr><th width="150.0703125">Action</th><th width="100.51953125">Admin</th><th width="100.0078125">Space Owner</th><th width="99.96484375">Space Manager</th><th width="99.78515625">Power User</th><th width="107.9296875">Deployment</th><th width="100">Viewer</th></tr></thead><tbody><tr><td>List API tokens</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Create an API token</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Edit an API token</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Delete an API token</td><td>✅</td><td></td><td></td><td></td><td></td><td></td></tr></tbody></table>

<sup>*1*</sup>*A user with a Power User, Deployment, or Viewer role can view a service account token only if the token is explicitly scoped to that role.*

#### Portal

<table><thead><tr><th width="237">Action</th><th width="85">Admin</th><th width="118">Power User</th><th width="126">Deployment</th><th width="87">Viewer</th><th>Grantee</th></tr></thead><tbody><tr><td>Request access</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>Access granted resources</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>
