Skip to main content
Regulaxy

Permission catalog

The permission catalog by category: what each key allows, which permissions it carries with it, and why a few are described here rather than printed.

A permission is a fixed key — servers.view, events.cancel — with a name beside it. The key is what is stored on a role and what is checked on every request; the name is what the permissions screen shows. The same keys are also the scopes an access token can be given, so this list does two jobs.

The console renders these permission names in Hebrew in both interface languages. The English names below are for reading; the keys are identical either way.

Three rules that shape the catalog

Every key belongs to exactly one category. The categories below are in the order the permissions screen renders them.

A category carries at most one access ladder. Where there is one, choosing a level also grants every level beneath it. In most categories the ladder is view → edit. The system register has three rungs — view → edit → merge — because a merge changes the identity of the system every other screen joins to, which is a larger decision than an edit.

An implication never crosses a category. A permission can carry another permission from the same category — edit carries view, export carries view — and never one from another module. That is what stops a grant on one screen from quietly opening another.

The two roles the product ships with

RoleWhat it holds
System administratorThe whole catalog, including keys added in later versions. The role holds no explicit permission list at all, so an upgrade never leaves an administrator without a new permission nobody remembered to add.
OperatorThe default role — a user assigned to no role gets it. It carries read access to the operational screens, export, and the day-to-day operating actions: updating an event's status, filling in a checklist, marking a server as handled.

Further roles are built on the permissions screen out of the same catalog. There is no permission that exists in the product and not there.

Events and calendar

KeyPermissionWhat it allowsAlso carries
events.viewView eventsThe calendar, the event list and the history
events.createCreate an eventCreating an update event through the wizardevents.view
events.editEdit an eventChanging an existing event, including updating the calendar invitation and the ticket
events.cancelCancel an eventCancelling an event and sending the cancellation to the invitees
events.delete_permanentDelete permanentlyPermanently deleting a cancelled event
events.statusUpdate event statusMarking an event completed or failed
events.checklistFill in a checklistCompleting the event checklist after the work
events.exportExport eventsExporting the event list to CSV or Excel
tasks.viewView tasksThe task list for events
tasks.manageManage tasksCreating, editing and deleting tasks and task templatestasks.view

Server inventory

KeyPermissionWhat it allowsAlso carries
servers.viewView the server inventoryThe server table, the systems and the system managers
servers.commentEdit server commentsWriting and deleting a note in the comment columnservers.view
servers.exportExport serversExporting the inventory to CSV or Excelservers.view
cmdb.viewView the server recordOpening a server's record — values, sources and field historyservers.view
cmdb.editEdit fields on the server recordChanging field values on the record, including setting a value that differs from a discovered sourcecmdb.view
cmdb.qualityData quality boardThe completeness score of the record store and the quality findings — duplicates, contradictions between sources, records never observed and records with no ownercmdb.view
capacity.viewView capacity managementThe capacity headroom of compute clusters, racks and reclaimable capacityservers.view
capacity.planCapacity planningRunning "is there room" scenarios against clusters, sites and rackscapacity.view
capacity.exportExport capacity dataExporting capacity data to CSV or Excelcapacity.view

System register

KeyPermissionWhat it allowsAlso carries
systems.viewView the system registerThe register, the owners, patch coverage and the system record
systems.editEdit a systemCreating and editing a system record, its aliases, membership and declared dependenciessystems.view
systems.mergeMerge and split systemsMerging two records into one, splitting a record and deleting itsystems.edit
systems.attestAnswer an ownership attestationConfirming or rejecting an ownership attestation, including correcting wrong fieldssystems.view
systems.exportExport systemsExporting the register and the attestation report to CSV or Excelsystems.view

CVE vulnerabilities

KeyPermissionWhat it allowsAlso carries
vulnerabilities.viewView vulnerabilitiesThe vulnerability register and the affected servers
vulnerabilities.manageManage vulnerabilitiesAdding, editing and archiving recordsvulnerabilities.view
vulnerabilities.mark_hostMark a server handledMarking an affected server as handled in the exposure panelvulnerabilities.view
vulnerabilities.purgePurge legacy recordsDeleting old records that carry no patchvulnerabilities.view
vulnerabilities.exportExport vulnerabilitiesExporting the list to CSV or Excelvulnerabilities.view

System connections

KeyPermissionWhat it allowsAlso carries
connections.viewView system connectionsThe connection map between systems and the scheduling collisions

Databases

KeyPermissionWhat it allowsAlso carries
databases.viewView databasesThe database inventory
databases.editEdit coordination fieldsEditing a database's coordination fieldsdatabases.view
databases.exportExport databasesExporting the inventory to CSV or Exceldatabases.view

Network equipment

KeyPermissionWhat it allowsAlso carries
equipment.viewView network equipmentThe equipment list
equipment.editEdit an equipment recordEditing custom fields on an item's record — not a change to the inventory source itselfequipment.view
equipment.exportExport equipmentExporting the list to CSV or Excelequipment.view

Virtualization

KeyPermissionWhat it allowsAlso carries
virt.viewView virtualization clustersThe cluster inventory, the management planes and the cluster record
virt.editEdit a cluster recordEditing custom fields on a cluster or management-plane record — not a change to the management system itselfvirt.view
virt.exportExport clustersExporting the inventory to CSV or Excelvirt.view

Storage

KeyPermissionWhat it allowsAlso carries
storage.viewView storage systemsThe storage inventory, utilization and the system record
storage.editEdit a storage recordEditing custom fields on the record — not a change to the array itselfstorage.view
storage.exportExport storage systemsExporting the inventory to CSV or Excelstorage.view

Cloud

KeyPermissionWhat it allowsAlso carries
cloud.viewView cloud accountsThe account inventory, the attaching circuits and the account record
cloud.editEdit a cloud recordEditing custom fields on an account or circuit record — not a change at the cloud providercloud.view
cloud.exportExport cloud accountsExporting the inventory to CSV or Excelcloud.view

Container platforms

KeyPermissionWhat it allowsAlso carries
containers.viewView container clustersThe cluster inventory, the versions and the cluster record
containers.editEdit a container cluster recordEditing custom fields on the record — not a change to the cluster itselfcontainers.view
containers.exportExport container clustersExporting the inventory to CSV or Excelcontainers.view

Backup and protection

KeyPermissionWhat it allowsAlso carries
backup.viewView backup servicesThe service inventory, protection coverage and the service record
backup.editEdit a backup recordEditing custom fields on the record — not a change to the backup system itselfbackup.view
backup.exportExport backup servicesExporting the inventory to CSV or Excelbackup.view

BIA and suggestions

KeyPermissionWhat it allowsAlso carries
bia.viewView the BIAThe BIA register and the system-to-database dependency tree
bia.editEdit a BIA recordEditing custom fields on a business-process record — not a change to the register itselfbia.view
suggestions.viewView suggestionsThe update suggestions, by system
suggestions.send_mailEmail the system managerPreparing the update-status email to a system managersuggestions.view
suggestions.exportExport suggestionsExporting the suggestions and the system reports to Excelsuggestions.view

Dashboards and alerts

KeyPermissionWhat it allowsAlso carries
dashboards.viewView dashboardsViewing the boards
dashboards.editEdit dashboardsBuilding and editing boardsdashboards.view
alerts.viewView alertsThe alert bell for vulnerabilities and collisions
alerts.manageManage alert rulesCreating and editing alert rules, delivery channels and the delivery logalerts.view
reports.viewView scheduled reportsThe list of scheduled reports and their delivery log
reports.manageManage scheduled reportsCreating, editing and test-sending a reportreports.view

System memory

KeyPermissionWhat it allowsAlso carries
memory.viewView system memoryThe contacts and notes accumulated per system
memory.manageManage system memoryAdding, editing and deleting memory recordsmemory.view

Activity planning

KeyPermissionWhat it allowsAlso carries
(three keys, not printed)Activity planningViewing the weekly activity calendar, approving or rejecting an activity and syncing it with the ticketing system, and recording an incident recollection

Settings and configuration

KeyPermissionWhat it allowsAlso carries
settings.viewOpen settingsReaching the settings screen
settings.typesUpdate types and templatesManaging update types and message templatessettings.view
settings.contactsContacts and performersManaging the standing contacts and the performer listsettings.view
settings.checklistsChecklist formsBuilding the event checklist formssettings.view
settings.systemSystem settingsThe general settings and the integration statussettings.view
settings.accessAccess managementViewing the access-management screen; editing it stays with administratorssettings.view
settings.navSidebar menuAdjusting the order and names of the sidebar for everyonesettings.view
settings.mailEmail to the system managerEditing the email template and the columns of the table inside itsettings.view
settings.simulateSimulationRunning integration tests from the simulation screensettings.view
settings.freezeChange freezeManaging change-freeze periods on the calendarsettings.view
settings.integrationsIntegrations and connectionsManaging connections to external systems and their health checkssettings.view
settings.ssoSingle sign-on (SSO)Configuring a corporate identity provider and federated loginsettings.view
(one key, not printed)WorkflowsManaging the workflows synced from the ticketing systemsettings.view
settings.scenariosMemory scenariosManaging the activity memory scenariossettings.view
settings.fieldsCustom fieldsDesigning the custom fields of servers, systems and equipmentsettings.view
views.manageShared views and layoutsSaving and editing table views and column layouts shared by everyone
ingest.authorCustom collection sourcesDefining a collection source against an internal system — an SQL query or an HTTP call the product runs against one of the organisation's systems, and the mapping of the fields it fillssettings.view
recipients.manageRecipient groupsCreating and editing standing recipient groupssettings.view
tokens.createCreate API tokensCreating and managing your own account's access tokenssettings.view
tokens.serviceService tokensCreating tokens for automated systems, which do not narrow with the permissions of whoever created themtokens.create
tokens.manage_allManage all tokensViewing, disabling and revoking every user's tokenstokens.create
docs.apiAPI documentationViewing this installation's interactive API documentationsettings.view

Permissions and audit

KeyPermissionWhat it allowsAlso carries
roles.viewView rolesThe list of roles, their permissions and their members
roles.manageManage rolesCreating, editing and deleting roles and their permissionsroles.view
roles.assignAssign usersAssigning users to roles and removing themroles.view
audit.viewView the audit logThe audit log of system actions

Updated

This page is the file content/docs/en/v1/reference/permissions.mdx