Skip to main content
Version: 7.0

Edit role

Passwork administrators and users with sufficient rights can edit roles, their associated settings and manage the assigned users.

To edit a role, open it by clicking on the role's name in the Roles tab:

Role selection

Add users

You can create an unlimited number of roles and apply them to any number of users. A user can be associated with multiple roles.

Click the Add users button in the right panel to add users to the role:

Add users button

Select one or multiple users in the pop-up window and save the changes:

Select users dialog

Remove users

To remove users from role, open it and click on the list of users in the right panel:

Users list

Select one or multiple users in the pop-up window and save the changes:

Remove users dialog

Configure settings

You can configure what permissions and settings the role has access to by toggling the necessary options on the role's page.

General

Here you can grant users access rights to create vaults, view the history of actions related to settings and users, access license info, view and modify the SSO settings and background tasks.

General settings

System settings

Here you can grant users the right to view and modify specific groups of System settings.

System settings

Vaults

Here you can configure user access to specific tabs of the vault settings.

Vault settings access

LDAP settings

Here you can grant users the right to view and modify LDAP parameters which include adding and deleting servers, registering new users, managing group lists, viewing and configuring synchronization settings.

LDAP settings

User management

Here you can grant users access rights to view and modify user management parameters. These include any necessary actions with users and roles, such as creating, deleting, and editing users, changing their authorization type and sending invites.

User management settings

Role-based user management

This section includes settings that are critical to user management, such as user deletion, ability to reset 2FA or viewing the sessions of any user. You can give access to the enabled settings to any role you need, or enable them for all members of your organization.

Role-based user management

Roles

This section lets role member view or manage roles and their settings.

Roles settings

Account

Here you can grant role members the ability to manage their account, change the interface, use the API, mobile apps, and extension.

Account settings

Authorization and 2FA settings

Here you can select security policies applied to a role.

Authorization and 2FA settings

Rename role

You can rename a role by opening it and then clicking Rename role:

Rename role button

In the pop-up window, enter a new name for the role and confirm the changes:

Rename role dialog