Skip to main content
TENSOR docs
Reference

Role catalog

The 21 platform-shipped roles, the permissions each grants, and which carry MFA or dual-approval requirements.

The platform ships 21 roles. They cannot be renamed or have their core permissions revoked; tenants extend the model with custom roles. Order below matches the role-picker default ordering.

KeyRoleConstraintsPermissionsDomain scope
platform_ownerPlatform OwnerMFA, bootstrap118all
tenant_adminTenant AdministratorMFA61identity, settings, reporting, integration, workforce, time_tracking, status_page, maintenance, license, pseudonymization, patch
service_desk_agentService Desk Agent--21incident, request, cmdb, knowledge, workforce, time_tracking, dashboard, license, maintenance
service_desk_supervisorService Desk Supervisor--32incident, request, sla, reporting, knowledge, workforce, time_tracking, dashboard, maintenance
incident_managerIncident ManagerMFA37incident, problem, reporting, workforce, time_tracking, patch, dashboard, status_page, license, maintenance
problem_managerProblem Manager--25problem, incident, cmdb, change, knowledge, workforce, time_tracking, dashboard, maintenance
change_managerChange Manager--22change, cmdb, incident, reporting, workforce, time_tracking, dashboard, patch, license, maintenance
change_approverChange Approver (CAB)MFA6change, cmdb, incident, dashboard
cmdb_adminCMDB Administrator--21cmdb, patch, dashboard, license, maintenance
ci_ownerCI Owner--4cmdb, dashboard
service_ownerService Owner--9cmdb, change, dashboard, status_page, maintenance
end_userEnd User--7incident, request, knowledge, dashboard, maintenance
auditorAuditorMFA, dual-approval16audit, reporting, patch, dashboard, license, maintenance
external_auditorExternal AuditorMFA, dual-approval10audit, reporting, dashboard
compliance_officerCompliance OfficerMFA29audit, reporting, incident, identity, pseudonymization, patch, dashboard, license, time_tracking, maintenance
procurement_officerProcurement Officer--4cmdb, reporting, dashboard
works_council_memberWorks Council MemberMFA, dual-approval4reporting, pseudonymization, dashboard
network_adminNetwork Administrator--8cmdb, incident, dashboard
infrastructure_adminInfrastructure Administrator--8cmdb, incident, dashboard
deployment_adminDeployment Administrator--7cmdb, incident, dashboard
api_integrationAPI Integration--5cmdb, incident, request

Per-role detail

Platform Owner (platform_owner)

Tenant administrator with full permissions. Exactly one exists per tenant.

MFA required - tenant bootstrap role

Permissions (118): identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.schutzbedarf.accept, cmdb.ci.reconcile, incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.broadcast_external, problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, change.request.submit, change.request.approve, change.request.reject, change.request.implement, change.model.create, change.pir.author, change.sap_transport.force_import, request.servicerequest.create, request.servicerequest.fulfill, request.catalog.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, sla.definition.manage, sla.timer.override, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, reporting.custom_report.author, reporting.custom_report.run, notification.rule.manage, notification.template.manage, notification.channel.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, customization.saved_view.share_with_tenant, customization.saved_view.set_tenant_default, ticket.comment.create, ticket.comment.edit_own, ticket.comment.moderate, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, pseudonymization.request, pseudonymization.approve, pseudonymization.disclosure.read, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy

Tenant Administrator (tenant_admin)

Day-to-day tenant administration. Cannot modify Auditor role assignments.

MFA required

Permissions (61): identity.tenant.update, identity.user.create, identity.user.read, identity.user.update, identity.user.deactivate, identity.role.assign, identity.role.revoke, identity.role.read, identity.role.create_custom, identity.group.manage, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.analytics.read, knowledge.public_surface.toggle, knowledge.section.manage, settings.tenant.update, settings.featureflags.read, settings.featureflags.toggle, settings.customization.manage, dashboard.layout.edit_own, dashboard.layout.set_tenant_default, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, integration.apitoken.manage, integration.webhook.manage, integration.config.manage, integration.config.read, workforce.skill.manage, workforce.skill.declare_own, workforce.skill.verify, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, time_tracking.rate.manage, status_page.component.read, status_page.component.manage, status_page.publish, maintenance.window.read, maintenance.window.manage, license.entitlement.manage, license.allocation.read, pseudonymization.request, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy

Service Desk Agent (service_desk_agent)

First-line support. Creates and resolves incidents and service requests.

Permissions (21): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.read, incident.ticket.update, incident.ticket.close, cmdb.ci.read, request.servicerequest.create, request.servicerequest.fulfill, knowledge.article.read, knowledge.article.author, knowledge.article.rate, knowledge.article.evolve_request, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.routing.suggest, time_tracking.entry.create_own, integration.config.read, dashboard.layout.edit_own, license.allocation.read, maintenance.window.read

Service Desk Supervisor (service_desk_supervisor)

Service desk team lead with timer-override and reopen authority.

Permissions (32): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.close, incident.ticket.reopen, incident.ticket.escalate, cmdb.ci.read, request.servicerequest.create, request.servicerequest.fulfill, sla.timer.override, reporting.run, reporting.custom_report.author, reporting.custom_report.run, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.article.rate, knowledge.article.evolve_request, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.configure, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read

Incident Manager (incident_manager)

Major-incident coordination including DORA / NIS-2 classification.

MFA required

Permissions (37): incident.ticket.create, incident.ticket.raise_on_behalf, incident.ticket.assign_group, incident.ticket.read, incident.ticket.update, incident.ticket.classify_major, incident.ticket.classify_significant, incident.ticket.close, incident.ticket.reopen, incident.escalation_ladder.write, incident.ticket.escalate, incident.category.manage, incident.routing.manage, incident.war_room.coordinate, incident.war_room.broadcast_external, cmdb.ci.read, problem.problem.create, problem.problem.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, workforce.out_of_office.declare_on_behalf, workforce.routing.suggest, time_tracking.entry.create_own, time_tracking.report.read, integration.config.read, dashboard.layout.edit_own, patch.status.read, status_page.component.read, status_page.component.manage, status_page.publish, license.allocation.read, maintenance.window.read, maintenance.window.manage

Problem Manager (problem_manager)

Problem-management practice owner. Promotes Problems to Known Errors. Manages the recurring-incident detection queue (PRB-05).

Permissions (25): problem.problem.create, problem.problem.read, problem.problem.update, problem.problem.close, problem.knownerror.promote, problem.candidate.read, problem.candidate.promote, problem.candidate.dismiss, problem.candidate.configure, incident.ticket.read, cmdb.ci.read, change.request.submit, knowledge.article.read, knowledge.article.author, knowledge.article.publish, knowledge.decision_tree.author, knowledge.analytics.read, knowledge.section.manage, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, maintenance.window.read

Change Manager (change_manager)

Change Enablement practice owner. Cannot approve own submissions.

Permissions (22): change.request.submit, change.request.implement, change.model.create, change.pir.author, change.sap_transport.force_import, cmdb.ci.read, incident.ticket.read, reporting.run, reporting.custom_report.author, reporting.custom_report.run, settings.featureflags.read, workforce.skill.declare_own, workforce.out_of_office.declare_own, time_tracking.entry.create_own, time_tracking.report.read, dashboard.layout.edit_own, patch.definition.read, patch.status.read, patch.deploy, license.allocation.read, maintenance.window.read, maintenance.window.manage

Change Approver (CAB) (change_approver)

Authorizes Normal Changes. Cannot approve own submissions.

MFA required

Permissions (6): change.request.approve, change.request.reject, cmdb.ci.read, incident.ticket.read, settings.featureflags.read, dashboard.layout.edit_own

CMDB Administrator (cmdb_admin)

CMDB data steward. Manages classes, attributes, relationships.

Permissions (21): cmdb.ci.create, cmdb.ci.read, cmdb.ci.update, cmdb.ci.delete, cmdb.class.modify, cmdb.relationship.manage, cmdb.cve.record, cmdb.schutzbedarf.assess, cmdb.ci.reconcile, settings.featureflags.read, integration.config.read, dashboard.layout.edit_own, patch.definition.read, patch.definition.manage, patch.status.read, patch.status.write, patch.deploy, license.entitlement.manage, license.allocation.read, maintenance.window.read, maintenance.window.manage

CI Owner (ci_owner)

Business owner of a specific CI or group. Owned-only scope on updates.

Permissions (4): cmdb.ci.read, cmdb.ci.update.owned_only, settings.featureflags.read, dashboard.layout.edit_own

Service Owner (service_owner)

Owner of an ITService or BusinessService. Approves changes affecting their services.

Permissions (9): cmdb.ci.read, cmdb.ci.update.owned_only, change.request.approve, change.request.reject, settings.featureflags.read, dashboard.layout.edit_own, status_page.component.read, status_page.component.manage, maintenance.window.read

End User (end_user)

Standard tenant user. Submits incidents and service requests.

Permissions (7): incident.ticket.create, request.servicerequest.create, knowledge.article.read, knowledge.article.rate, settings.featureflags.read, dashboard.layout.edit_own, maintenance.window.read

Auditor (auditor)

Internal audit / risk function. Read-only across the tenant. Cannot be revoked from the audit log.

MFA required - assignment needs dual approval

Permissions (16): cmdb.ci.read, incident.ticket.read, audit.log.read, audit.log.export, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, maintenance.window.read

External Auditor (external_auditor)

External or regulatory auditor. Time-bounded engagement-based access with elevated audit logging. (Engagement workflow: IDN-05.)

MFA required - assignment needs dual approval

Permissions (10): cmdb.ci.read, incident.ticket.read, audit.log.read, reporting.run, reporting.dora_roi.export, reporting.berechtigungskonzept.export, identity.user.read, identity.role.read, settings.featureflags.read, dashboard.layout.edit_own

Compliance Officer (compliance_officer)

Compliance and regulatory reporting. Runs DORA RoI and BAIT Berechtigungskonzept exports.

MFA required

Permissions (29): cmdb.ci.read, cmdb.schutzbedarf.accept, incident.ticket.read, incident.ticket.classify_major, incident.ticket.classify_significant, incident.war_room.coordinate, incident.war_room.broadcast_external, audit.log.read, audit.log.export, reporting.run, reporting.custom_report.author, reporting.custom_report.run, reporting.dora_roi.export, reporting.dora_major_incident.export, reporting.nis2.export, reporting.berechtigungskonzept.export, reporting.gdpr_export.run, identity.user.read, identity.role.read, settings.featureflags.read, integration.config.read, pseudonymization.request, pseudonymization.approve, dashboard.layout.edit_own, patch.definition.read, patch.status.read, license.allocation.read, time_tracking.report.read, maintenance.window.read

Procurement Officer (procurement_officer)

Procurement function. Reads Contract and Supplier CIs; updates commercial-term fields. (Full scope: v2.)

Permissions (4): cmdb.ci.read, reporting.run, settings.featureflags.read, dashboard.layout.edit_own

Works Council Member (works_council_member)

BetrVG co-determination representative. Reads aggregate stats with PII pseudonymized. Sees + releases de-pseudonymization disclosures after the mandatory delay (PSE-08). Usable aggregate view requires v2 masking infrastructure.

MFA required - assignment needs dual approval

Permissions (4): reporting.run, settings.featureflags.read, pseudonymization.disclosure.read, dashboard.layout.edit_own

Network Administrator (network_admin)

Owns network and DMZ infrastructure CIs.

Permissions (8): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own

Infrastructure Administrator (infrastructure_admin)

Owns server, storage, and virtualization CIs.

Permissions (8): cmdb.ci.read, cmdb.ci.update.owned_only, cmdb.relationship.manage, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own

Deployment Administrator (deployment_admin)

Owns software-distribution systems (SCCM, Intune, Workspace ONE). Full delegated scope requires connectors (v2+).

Permissions (7): cmdb.ci.read, cmdb.ci.update.owned_only, incident.ticket.create, incident.ticket.read, incident.ticket.update, settings.featureflags.read, dashboard.layout.edit_own

API Integration (api_integration)

Service-to-service automation. OAuth client credentials, not user credentials. Permission subset configured per-token.

Permissions (5): cmdb.ci.read, incident.ticket.create, incident.ticket.read, incident.ticket.update, request.servicerequest.create