Skip to main content

Overview - Roles Settings

Roles provide a central hub for creating, managing, and customizing administrative access profiles. By defining explicit permissions and structural boundaries, you can tailor platform access to match the specific responsibilities of different staff members.

This guide covers the three main sections of Roles management:


UNDERSTANDING THE ROLES LIST

Clicking the Admin menu and selecting Roles will display the table layout containing existing system profiles.

  • Name: Unique identifier assigned to the authorization profile (e.g., CF_ADMIN, CM_TEACHER).

  • Type: Identifies whether a role is Built-in (system default, uneditable) or Custom (user-defined admin profiles).

  • Resource Scoped: Displays Yes or No to indicate whether data visibility boundaries are active for the role.

  • Permissions: Indicates platform access levels.

  • Actions: Functional controls based on type:

    • Click the view eye icon to review default built-in profile specifications.

    • Click the edit pencil icon to adjust custom setups, or click the trash icon to delete custom roles.


CREATING AND CONFIGURING CUSTOM ROLES

Click the blue + New Role button at the top right of the screen to manually build a custom access configuration.

  • This action opens a prompt where you can define a unique name and select distinct checkbox items mapping directly to primary platform functions.

Field / Feature

Description

Name

Required text identifier for the new custom role profile.

View Summary

Access to the main platform operational health dashboard.

View Devices

Grants authorization to see managed endpoint logs.

Sub-actions: Checkboxes to allow device tracking toggles or marking devices as lost/stolen.

View Accounts

Capability for user listings within the Directory section.

View Groups

Allows permissions for structural organization units and groups.

View Policy

Authorizes policy rules access.

View Activities

Provides read visibility to historical tracking tabs and user interactions.

View Classes

Grants access to the Classroom Manager.

Sub-action: Authorizes administrative modification of classes owned by other users.

View Scenes

Unlocks customized scenes templates.

Sub-action: Authorizes management overrides on active scenes created by others.

View Console Users

Grants visibility to lists of internal backend platform operators.

Sub-action: Allows operators to grant or revoke administrative access.

View Google Classroom

Unlocks access to Google Classroom management.

View IP Ranges

Access to monitored network environments settings.

View Admin Settings

Grants access to general system global variables and environment options.

View Scheduled Reports

Authorizes access to set up automated system reports.


RESTRICTING ROLES TO SPECIFIC RESOURCES

Click the Restrict to specific resources toggle switch to activate granular limits.

  • This action is ideal for enterprise environments or school districts needing to split visibility parameters so operators can only track distinct sub-groups or campuses.

  • Domain Scopes: Click the Add Domain input field to restrict the scope of this role to a specific active domain structure (e.g., automicloud.com).

  • Organizational Unit Scopes: Click the input field to select a target organizational group or container (e.g., SchoolA, SchoolB). Operators assigned to this custom profile will only see data originating from these explicit containers.

Click the blue Save button at the bottom of the prompt to finalize and apply the role configuration.

Did this answer your question?