Control Tower permissions (in preview)

Any user with a global role that has the Product Rights > Control Tower global permission can access the Control Tower product pages. Certain tasks, however, require specific permissions.

Global permissions

Global permission Description Required license New license

Product Rights > Control Tower

Allows users full access to the Control Tower product pages.

Read only Viewer

Resources > Manage all resources

Allows users to set the Owner of a Managed Control asset, on create or afterward. The Asset > Add resource permission is enough to create a control, but not to assign its Owner.

Standard Creator

By default, only the Sysadmin global role has this global permission. There is no out-of-the-box Control Tower-related global role. We recommend that you do one of the following:

  • Give this global permission to an existing global role.
  • Create a new global role and give it this global permission.

For guidance on how to do this, go to Set up Control Tower.

Resource permissions

Resource permission Description Required license New license

Asset > Control > Activate and Run

Allows users to enable (activate) a control query.

Standard Creator
Asset > Add Allows users to create Managed Control assets. Standard Creator
Asset > Remove Allows users to delete Managed Control assets. Standard Creator
Asset > Update Allows users to edit Managed Control assets, including configuring control queries. Standard Creator