Role catalog
The 21 platform-shipped roles, the permissions each grants, and which carry MFA or dual-approval requirements.
The platform ships 21 roles. They cannot be renamed or have their core permissions revoked; tenants extend the model with custom roles. Order below matches the role-picker default ordering.
| Key | Role | Constraints | Permissions | Domain scope |
|---|---|---|---|---|
platform_owner | Platform Owner | MFA, bootstrap | 118 | all |
tenant_admin | Tenant Administrator | MFA | 61 | identity, settings, reporting, integration, workforce, time_tracking, status_page, maintenance, license, pseudonymization, patch |
service_desk_agent | Service Desk Agent | -- | 21 | incident, request, cmdb, knowledge, workforce, time_tracking, dashboard, license, maintenance |
service_desk_supervisor | Service Desk Supervisor | -- | 32 | incident, request, sla, reporting, knowledge, workforce, time_tracking, dashboard, maintenance |
incident_manager | Incident Manager | MFA | 37 | incident, problem, reporting, workforce, time_tracking, patch, dashboard, status_page, license, maintenance |
problem_manager | Problem Manager | -- | 25 | problem, incident, cmdb, change, knowledge, workforce, time_tracking, dashboard, maintenance |
change_manager | Change Manager | -- | 22 | change, cmdb, incident, reporting, workforce, time_tracking, dashboard, patch, license, maintenance |
change_approver | Change Approver (CAB) | MFA | 6 | change, cmdb, incident, dashboard |
cmdb_admin | CMDB Administrator | -- | 21 | cmdb, patch, dashboard, license, maintenance |
ci_owner | CI Owner | -- | 4 | cmdb, dashboard |
service_owner | Service Owner | -- | 9 | cmdb, change, dashboard, status_page, maintenance |
end_user | End User | -- | 7 | incident, request, knowledge, dashboard, maintenance |
auditor | Auditor | MFA, dual-approval | 16 | audit, reporting, patch, dashboard, license, maintenance |
external_auditor | External Auditor | MFA, dual-approval | 10 | audit, reporting, dashboard |
compliance_officer | Compliance Officer | MFA | 29 | audit, reporting, incident, identity, pseudonymization, patch, dashboard, license, time_tracking, maintenance |
procurement_officer | Procurement Officer | -- | 4 | cmdb, reporting, dashboard |
works_council_member | Works Council Member | MFA, dual-approval | 4 | reporting, pseudonymization, dashboard |
network_admin | Network Administrator | -- | 8 | cmdb, incident, dashboard |
infrastructure_admin | Infrastructure Administrator | -- | 8 | cmdb, incident, dashboard |
deployment_admin | Deployment Administrator | -- | 7 | cmdb, incident, dashboard |
api_integration | API Integration | -- | 5 | cmdb, incident, request |
Per-role detail
Platform Owner (platform_owner)
Tenant administrator with full permissions. Exactly one exists per tenant.
MFA required - tenant bootstrap role
Permissions (118): identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.schutzbedarf.accept, cmdb.ci.reconcile, incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.broadcast_external, problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, change.request.submit, change.request.approve, change.request.reject, change.request.implement, change.model.create, change.pir.author, change.sap_transport.force_import, request.servicerequest.create, request.servicerequest.fulfill, request.catalog.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, sla.definition.manage, sla.timer.override, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, reporting.custom_report.author, reporting.custom_report.run, notification.rule.manage, notification.template.manage, notification.channel.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, customization.saved_view.share_with_tenant, customization.saved_view.set_tenant_default, ticket.comment.create, ticket.comment.edit_own, ticket.comment.moderate, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, pseudonymization.request, pseudonymization.approve, pseudonymization.disclosure.read, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy
Tenant Administrator (tenant_admin)
Day-to-day tenant administration. Cannot modify Auditor role assignments.
MFA required
Permissions (61): identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, pseudonymization.request, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy
Service Desk Agent (service_desk_agent)
First-line support. Creates and resolves incidents and service requests.
Permissions (21): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.read, incident.ticket.update, incident.ticket.close, cmdb.ci.read, request.servicerequest.create, request.servicerequest.fulfill, knowledge.article.read, knowledge.article.author, knowledge.article.rate, knowledge.article.evolve_request, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.routing.suggest, time_tracking.entry.create_own, integration.config.read, dashboard.layout.edit_own, license.allocation.read, maintenance.window.read
Service Desk Supervisor (service_desk_supervisor)
Service desk team lead with timer-override and reopen authority.
Permissions (32): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.close, incident.ticket.reopen, incident.ticket.escalate, cmdb.ci.read, request.servicerequest.create, request.servicerequest.fulfill, sla.timer.override, reporting.run, reporting.custom_report.author, reporting.custom_report.run, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read
Incident Manager (incident_manager)
Major-incident coordination including DORA / NIS-2 classification.
MFA required
Permissions (37): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.broadcast_external, cmdb.ci.read, problem.problem.create, problem.problem.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, integration.config.read, dashboard.layout.edit_own, patch.status.read, status_page.component.read, status_page.component.manage, status_page.publish, license.allocation.read, maintenance.window.read, maintenance.window.manage
Problem Manager (problem_manager)
Problem-management practice owner. Promotes Problems to Known Errors. Manages the recurring-incident detection queue (PRB-05).
Permissions (25): problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, incident.ticket.read, cmdb.ci.read, change.request.submit, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read
Change Manager (change_manager)
Change Enablement practice owner. Cannot approve own submissions.
Permissions (22): change.request.submit, change.request.implement, change.model.create, change.pir.author, change.sap_transport.force_import, cmdb.ci.read, incident.ticket.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, patch.definition.read, patch.status.read, patch.deploy, license.allocation.read, maintenance.window.read, maintenance.window.manage
Change Approver (CAB) (change_approver)
Authorizes Normal Changes. Cannot approve own submissions.
MFA required
Permissions (6): change.request.approve, change.request.reject, cmdb.ci.read, incident.ticket.read, settings.featureflags.read, dashboard.layout.edit_own
CMDB Administrator (cmdb_admin)
CMDB data steward. Manages classes, attributes, relationships.
Permissions (21): cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.ci.reconcile, settings.featureflags.read, integration.config.read, dashboard.layout.edit_own, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy, license.entitlement.manage, license.allocation.read, maintenance.window.read, maintenance.window.manage
CI Owner (ci_owner)
Business owner of a specific CI or group. Owned-only scope on updates.
Permissions (4): cmdb.ci.read, cmdb.ci.update.owned_only, settings.featureflags.read, dashboard.layout.edit_own
Service Owner (service_owner)
Owner of an ITService or BusinessService. Approves changes affecting their services.
Permissions (9): cmdb.ci.read, cmdb.ci.update.owned_only, change.request.approve, change.request.reject, settings.featureflags.read, dashboard.layout.edit_own, status_page.component.read, status_page.component.manage, maintenance.window.read
End User (end_user)
Standard tenant user. Submits incidents and service requests.
Permissions (7): incident.ticket.create, request.servicerequest.create, knowledge.article.read, knowledge.article.rate, settings.featureflags.read, dashboard.layout.edit_own, maintenance.window.read
Auditor (auditor)
Internal audit / risk function. Read-only across the tenant. Cannot be revoked from the audit log.
MFA required - assignment needs dual approval
Permissions (16): cmdb.ci.read, incident.ticket.read, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, maintenance.window.read
External Auditor (external_auditor)
External or regulatory auditor. Time-bounded engagement-based access with elevated audit logging. (Engagement workflow: IDN-05.)
MFA required - assignment needs dual approval
Permissions (10): cmdb.ci.read, incident.ticket.read, audit.log.read, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, dashboard.layout.edit_own
Compliance Officer (compliance_officer)
Compliance and regulatory reporting. Runs DORA RoI and BAIT Berechtigungskonzept exports.
MFA required
Permissions (29): cmdb.ci.read, cmdb.schutzbedarf.accept, incident.ticket.read, incident.ticket.classify_major, incident.ticket.classify_significant, incident.war_room.coordinate, incident.war_room.broadcast_external, audit.log.read, audit.log.export, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, pseudonymization.request, pseudonymization.approve, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, time_tracking.report.read, maintenance.window.read
Procurement Officer (procurement_officer)
Procurement function. Reads Contract and Supplier CIs; updates commercial-term fields. (Full scope: v2.)
Permissions (4): cmdb.ci.read, reporting.run, settings.featureflags.read, dashboard.layout.edit_own
Works Council Member (works_council_member)
BetrVG co-determination representative. Reads aggregate stats with PII pseudonymized. Sees + releases de-pseudonymization disclosures after the mandatory delay (PSE-08). Usable aggregate view requires v2 masking infrastructure.
MFA required - assignment needs dual approval
Permissions (4): reporting.run, settings.featureflags.read, pseudonymization.disclosure.read, dashboard.layout.edit_own
Network Administrator (network_admin)
Owns network and DMZ infrastructure CIs.
Permissions (8): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own
Infrastructure Administrator (infrastructure_admin)
Owns server, storage, and virtualization CIs.
Permissions (8): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own
Deployment Administrator (deployment_admin)
Owns software-distribution systems (SCCM, Intune, Workspace ONE). Full delegated scope requires connectors (v2+).
Permissions (7): cmdb.ci.read, cmdb.ci.update.owned_only, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own
API Integration (api_integration)
Service-to-service automation. OAuth client credentials, not user credentials. Permission subset configured per-token.
Permissions (5): cmdb.ci.read, incident.ticket.create, incident.ticket.read, incident.ticket.update, request.servicerequest.create