Role-based access control

A role-based access control (RBAC) system manages authorizations in Control Center.

Almost every action in Control Center requires a corresponding permission. Permissions aren’t assigned directly to administrators. Instead, they’re assigned to one or more roles, and those roles are assigned to administrators.

Permissions can be separated by function. For example, a role can grant permission to read users, create users, delete users, or edit users and their data.

A role can be scoped to a provider, a product, or an operator, to which the administrator must be assigned by a Provider Admin. Some predefined roles are global and aren’t tied to a specific resource.

Custom roles exist at two levels:

  • At provider level, if the provider feature Role-based access control is active. Administrators with the administrate_access_control_management permission can create, edit, and delete custom provider-specific roles, and control whether provider roles require two-factor authentication.
  • At product level, if the product feature Role-based access control is active. Administrators with the manage_rbac permission can create, edit, and delete custom product-specific roles, and control whether product roles require two-factor authentication.