Skip to main content
Reference

Role catalog

The 21 platform-shipped roles, the permissions each grants, and which carry MFA or dual-approval requirements.

The platform ships 21 roles. They cannot be renamed or have their core permissions revoked; tenants extend the model with custom roles. Order below matches the role-picker default ordering.

KeyRoleConstraintsPermissionsDomain scope
platform_ownerPlatform OwnerMFA, bootstrap188all
tenant_adminTenant AdministratorMFA96identity, settings, change, reporting, integration, workforce, time_tracking, status_page, maintenance, license, pseudonymization, patch, announcements
service_desk_agentService Desk Agent--27incident, request, cmdb, knowledge, workforce, time_tracking, dashboard, license, maintenance
service_desk_supervisorService Desk Supervisor--55incident, request, sla, reporting, knowledge, workforce, time_tracking, dashboard, maintenance, announcements
incident_managerIncident ManagerMFA47incident, problem, reporting, workforce, time_tracking, patch, dashboard, status_page, license, maintenance
problem_managerProblem Manager--27problem, incident, cmdb, change, knowledge, workforce, time_tracking, dashboard, maintenance
change_managerChange Manager--28change, cmdb, incident, reporting, workforce, time_tracking, dashboard, patch, license, maintenance, sap
change_approverChange Approver (CAB)MFA7change, cmdb, incident, dashboard
cmdb_adminCMDB Administrator--33cmdb, patch, dashboard, license, maintenance, ai_governance
ci_ownerCI Owner--4cmdb, dashboard
service_ownerService Owner--11cmdb, change, dashboard, status_page, maintenance, sla, request
end_userEnd User--12incident, request, knowledge, dashboard, maintenance, announcements, directory
auditorAuditorMFA, dual-approval19audit, reporting, patch, dashboard, license, maintenance, ai_governance
external_auditorExternal AuditorMFA, dual-approval13audit, reporting, dashboard, ai_governance
compliance_officerCompliance OfficerMFA41audit, reporting, incident, identity, pseudonymization, patch, dashboard, license, time_tracking, maintenance, ai_governance
procurement_officerProcurement Officer--6cmdb, reporting, dashboard, license
works_council_memberWorks Council MemberMFA, dual-approval4reporting, pseudonymization, dashboard
network_adminNetwork Administrator--8cmdb, incident, dashboard
infrastructure_adminInfrastructure Administrator--10cmdb, incident, dashboard, sap
deployment_adminDeployment Administrator--7cmdb, incident, dashboard
api_integrationAPI Integration--5cmdb, incident, request

Per-role detail

Platform Owner (platform_owner)

Tenant administrator with full permissions. Exactly one exists per tenant.

MFA required - tenant bootstrap role

Permissions (188): snippets.share, identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.schutzbedarf.accept, cmdb.ci.reconcile, cmdb.ci.transition_state, cmdb.state_conflict.resolve, cmdb.checklist.read, cmdb.checklist.manage, cmdb.checklist.run, incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.ticket.delete, incident.ticket.restore, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.pir.edit, incident.war_room.pir.publish, incident.war_room.broadcast_external, problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.problem.delete, problem.problem.restore, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, change.request.submit, change.request.approve, change.request.reject, change.request.implement, change.request.delete, change.request.restore, change.model.create, change.pir.author, change.sap_transport.force_import, change.freeze_window.declare, sap.transport.import, sap.transport.schedule, sap.transport.confirm_import, request.servicerequest.create, request.servicerequest.fulfill, request.servicerequest.delete, request.servicerequest.restore, request.catalog.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, sla.definition.manage, sla.calendar.manage, sla.timer.override, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, reporting.custom_report.author, reporting.custom_report.run, notification.rule.manage, notification.template.manage, notification.channel.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, directory.read, directory.admin, directory.sync.admin, settings.workflow.read, settings.workflow.edit, customization.saved_view.share_with_tenant, customization.saved_view.set_tenant_default, ticket.comment.create, ticket.comment.edit_own, ticket.comment.moderate, portal.links.admin, settings.provider_ticket.read, settings.provider_ticket.submit, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, account.work_defaults.update_own, account.personal_landing.update_own, identity.session.revoke_own, identity.security.read_own, privacy.personal_data.export_own, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, sap.archive.read, sap.archive.export, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, settings.mobile.read, settings.mobile.manage, workforce.location.share_own, workforce.location.view, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, license.trueup.export, pseudonymization.request, pseudonymization.approve, pseudonymization.disclosure.read, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy, privacy.personal_data.export_own, ai_governance.ai_system.read, ai_governance.ai_system.create, ai_governance.ai_system.update, identity.session.revoke_own, identity.security.read_own, privacy.personal_data.export_own, ai_governance.ai_assessment.create, ai_governance.ai_assessment.accept, ai_review.submit, ai_review.review, ai_review.approve, publication.read, publication.acknowledge, publication.author, publication.publish, portal.publications.admin, portal.poll.respond, portal.poll.author, portal.poll.publish, portal.banner.view, portal.banner.author, portal.banner.publish, portal.event.author, portal.event.publish, portal.layout.author, portal.project.read, portal.project.author, portal.project.publish

Tenant Administrator (tenant_admin)

Day-to-day tenant administration. Cannot modify Auditor role assignments.

MFA required

Permissions (96): snippets.share, identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, request.catalog.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, directory.read, directory.admin, directory.sync.admin, settings.workflow.read, settings.workflow.edit, portal.links.admin, settings.provider_ticket.read, settings.provider_ticket.submit, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, sap.archive.read, sap.archive.export, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, settings.mobile.read, settings.mobile.manage, workforce.location.share_own, workforce.location.view, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, license.trueup.export, pseudonymization.request, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy, publication.read, publication.acknowledge, publication.author, publication.publish, portal.publications.admin, portal.poll.respond, portal.poll.author, portal.poll.publish, portal.banner.view, portal.banner.author, portal.banner.publish, portal.event.author, portal.event.publish, portal.layout.author, portal.project.read, portal.project.author, portal.project.publish, change.freeze_window.declare

Service Desk Agent (service_desk_agent)

First-line support. Creates and resolves incidents and service requests.

Permissions (27): snippets.share, incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.read, incident.ticket.update, incident.ticket.close, cmdb.ci.read, cmdb.ci.transition_state, cmdb.checklist.read, cmdb.checklist.run, request.servicerequest.create, request.servicerequest.fulfill, knowledge.article.read, knowledge.article.author, knowledge.article.rate, knowledge.article.evolve_request, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.routing.suggest, settings.mobile.read, workforce.location.share_own, time_tracking.entry.create_own, integration.config.read, dashboard.layout.edit_own, license.allocation.read, maintenance.window.read

Service Desk Supervisor (service_desk_supervisor)

Service desk team lead with timer-override and reopen authority.

Permissions (55): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.close, incident.ticket.reopen, incident.ticket.escalate, cmdb.ci.read, cmdb.state_conflict.resolve, request.servicerequest.create, request.servicerequest.fulfill, request.servicerequest.delete, request.servicerequest.restore, sla.timer.override, reporting.run, reporting.custom_report.author, reporting.custom_report.run, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, settings.provider_ticket.read, settings.provider_ticket.submit, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, settings.mobile.read, workforce.location.share_own, workforce.location.view, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read, publication.read, publication.acknowledge, publication.author, publication.publish, portal.poll.respond, portal.poll.author, portal.poll.publish, portal.banner.view, portal.banner.author, portal.banner.publish, portal.event.author, portal.event.publish, portal.layout.author, portal.project.read, portal.project.author

Incident Manager (incident_manager)

Major-incident coordination including DORA / NIS-2 classification.

MFA required

Permissions (47): snippets.share, incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.ticket.delete, incident.ticket.restore, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.pir.edit, incident.war_room.pir.publish, incident.war_room.broadcast_external, settings.provider_ticket.read, settings.provider_ticket.submit, cmdb.ci.read, problem.problem.create, problem.problem.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.suggest, settings.mobile.read, workforce.location.share_own, workforce.location.view, time_tracking.entry.create_own, time_tracking.report.read, integration.config.read, dashboard.layout.edit_own, patch.status.read, status_page.component.read, status_page.component.manage, status_page.publish, license.allocation.read, maintenance.window.read, maintenance.window.manage

Problem Manager (problem_manager)

Problem-management practice owner. Promotes Problems to Known Errors. Manages the recurring-incident detection queue (PRB-05).

Permissions (27): problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.problem.delete, problem.problem.restore, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, incident.ticket.read, cmdb.ci.read, change.request.submit, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read

Change Manager (change_manager)

Change Enablement practice owner. Cannot approve own submissions.

Permissions (28): snippets.share, change.request.submit, change.request.implement, change.request.delete, change.request.restore, change.model.create, change.pir.author, change.freeze_window.declare, change.sap_transport.force_import, sap.transport.import, sap.transport.schedule, cmdb.ci.read, incident.ticket.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, patch.definition.read, patch.status.read, patch.deploy, license.allocation.read, maintenance.window.read, maintenance.window.manage

Change Approver (CAB) (change_approver)

Authorizes Normal Changes. Cannot approve own submissions.

MFA required

Permissions (7): snippets.share, change.request.approve, change.request.reject, cmdb.ci.read, incident.ticket.read, settings.featureflags.read, dashboard.layout.edit_own

CMDB Administrator (cmdb_admin)

CMDB data steward. Manages classes, attributes, relationships.

Permissions (33): snippets.share, cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.ci.reconcile, cmdb.ci.transition_state, cmdb.state_conflict.resolve, cmdb.checklist.read, cmdb.checklist.manage, cmdb.checklist.run, settings.featureflags.read, integration.config.read, dashboard.layout.edit_own, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy, license.entitlement.manage, license.allocation.read, maintenance.window.read, maintenance.window.manage, ai_governance.ai_system.read, ai_governance.ai_system.create, ai_governance.ai_system.update, ai_governance.ai_assessment.create, ai_review.submit, ai_review.review

CI Owner (ci_owner)

Business owner of a specific CI or group. Owned-only scope on updates.

Permissions (4): cmdb.ci.read, cmdb.ci.update.owned_only, settings.featureflags.read, dashboard.layout.edit_own

Service Owner (service_owner)

Owner of an ITService or BusinessService. Approves changes affecting their services.

Permissions (11): cmdb.ci.read, cmdb.ci.update.owned_only, change.request.approve, change.request.reject, settings.featureflags.read, dashboard.layout.edit_own, status_page.component.read, status_page.component.manage, maintenance.window.read, sla.calendar.manage, request.catalog.manage

End User (end_user)

Standard tenant user. Submits incidents and service requests.

Permissions (12): incident.ticket.create, request.servicerequest.create, knowledge.article.read, knowledge.article.rate, settings.featureflags.read, dashboard.layout.edit_own, maintenance.window.read, publication.read, publication.acknowledge, portal.poll.respond, portal.banner.view, directory.read

Auditor (auditor)

Internal audit / risk function. Read-only across the tenant. Cannot be revoked from the audit log.

MFA required - assignment needs dual approval

Permissions (19): cmdb.ci.read, incident.ticket.read, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, sap.archive.read, sap.archive.export, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, maintenance.window.read, ai_governance.ai_system.read

External Auditor (external_auditor)

External or regulatory auditor. Time-bounded engagement-based access with elevated audit logging. (Engagement workflow: IDN-05.)

MFA required - assignment needs dual approval

Permissions (13): cmdb.ci.read, incident.ticket.read, audit.log.read, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, sap.archive.read, sap.archive.export, dashboard.layout.edit_own, ai_governance.ai_system.read

Compliance Officer (compliance_officer)

Compliance and regulatory reporting. Runs DORA RoI and BAIT Berechtigungskonzept exports.

MFA required

Permissions (41): cmdb.ci.read, cmdb.schutzbedarf.accept, incident.ticket.read, incident.ticket.classify_major, incident.ticket.classify_significant, incident.war_room.coordinate, incident.war_room.pir.edit, incident.war_room.pir.publish, incident.war_room.broadcast_external, audit.log.read, audit.log.export, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, sap.archive.read, sap.archive.export, pseudonymization.request, pseudonymization.approve, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, license.trueup.export, time_tracking.report.read, maintenance.window.read, ai_governance.ai_system.read, ai_governance.ai_system.create, ai_governance.ai_system.update, ai_governance.ai_assessment.create, ai_governance.ai_assessment.accept, ai_review.review, ai_review.approve

Procurement Officer (procurement_officer)

Procurement function. Reads Contract and Supplier CIs; updates commercial-term fields. Generates licence true-up exports the compliance officer signs off (SLM-05). (Full scope: v2.)

Permissions (6): cmdb.ci.read, reporting.run, settings.featureflags.read, dashboard.layout.edit_own, license.allocation.read, license.trueup.export

Works Council Member (works_council_member)

BetrVG co-determination representative. Reads aggregate stats with PII pseudonymized. Sees + releases de-pseudonymization disclosures after the mandatory delay (PSE-08). Usable aggregate view requires v2 masking infrastructure.

MFA required - assignment needs dual approval

Permissions (4): reporting.run, settings.featureflags.read, pseudonymization.disclosure.read, dashboard.layout.edit_own

Network Administrator (network_admin)

Owns network and DMZ infrastructure CIs.

Permissions (8): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own

Infrastructure Administrator (infrastructure_admin)

Owns server, storage, and virtualization CIs.

Permissions (10): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own, sap.transport.import, sap.transport.confirm_import

Deployment Administrator (deployment_admin)

Owns software-distribution systems (SCCM, Intune, Workspace ONE). Full delegated scope requires connectors (v2+).

Permissions (7): cmdb.ci.read, cmdb.ci.update.owned_only, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own

API Integration (api_integration)

Service-to-service automation. OAuth client credentials, not user credentials. Permission subset configured per-token.

Permissions (5): cmdb.ci.read, incident.ticket.create, incident.ticket.read, incident.ticket.update, request.servicerequest.create