Control Tower permissions (in preview)
Any user with a global role that has the Product Rights > Control Tower global permission can access the Control Tower product pages. Certain tasks, however, require specific permissions.
Global permissions
| Global permission | Description | Required license | New license |
|---|---|---|---|
|
Product Rights > Control Tower |
Allows users full access to the Control Tower product pages. |
Read only | Viewer |
|
Resources > Manage all resources |
Allows users to set the Owner of a Managed Control asset, on create or afterward. The Asset > Add resource permission is enough to create a control, but not to assign its Owner. |
Standard | Creator |
By default, only the Sysadmin global role has this global permission. There is no out-of-the-box Control Tower-related global role. We recommend that you do one of the following:
- Give this global permission to an existing global role.
- Create a new global role and give it this global permission.
For guidance on how to do this, go to Set up Control Tower.
Resource permissions
| Resource permission | Description | Required license | New license |
|---|---|---|---|
|
Asset > Control > Activate and Run |
Allows users to enable (activate) a control query. |
Standard | Creator |
| Asset > Add | Allows users to create Managed Control assets. | Standard | Creator |
| Asset > Remove | Allows users to delete Managed Control assets. | Standard | Creator |
| Asset > Update | Allows users to edit Managed Control assets, including configuring control queries. | Standard | Creator |