Guides
HomeHomeLog In
Guides

DRAFT - RBAC Permissions in Cyolo

Overview

Cyolo uses role-based access control (RBAC) to ensure administrators and managers have access only to the Cyolo components relevant to their responsibilities. Each admin role has predefined permissions across Cyolo components.

These permissions determine what each role can view or modify in the platform.

  • See the table below for specific permission details.
  • See Role Summaries for an overview of the permissions assigned to each Role.

RBAC Permission Matrix

The table below shows the permissions granted to each admin role across Cyolo components.

Permissions are shown as:

  • R/W – Read and write (full management access)
  • R – Read-only
  • Blank – No access
ComponentSuper AdminOperational AdminRead Only AdminHelp DeskLogs ViewerAccess Manager
ApplicationsR/WR/WRRR
IdentitiesR/WR/WRR/WR
DevicesR/WR/WRR
PoliciesR/WR/WRR
VaultR/WR/WRR/W
SessionsR/WR/WRRR/W
TopologyR/WRR
LogsR/WR/WRRRR/W
IntegrationsR/WRR
ConfigurationsR/W
Roles/Supervisors and Roles/AuditorsR/WR/WR
Roles/AdminsR/W
AssetsR/WR/WR
File TransferR/W
Remote AssistanceR/WR/W

Role Summaries

Super Admin

Full administrative access across all components, including system configuration and role management.

Operational Admin

Broad administrative access to applications, identities, policies, assets, and sessions. Suitable for day-to-day operational management.

Read Only Admin

Visibility into most components without the ability to make changes. Suitable for audit and oversight.

Help Desk

Focused access for user support workflows. Can view and modify sessions and identities. No access to administrative configuration.

Logs Viewer

Read-only access to logs and auditing data only.

Access Manager

Manages access flows and session-related controls. Has R/W access to vault, sessions, logs, and applications.