You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/docs/cloudflare-one/roles-permissions.mdx
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,12 +44,12 @@ The Cloudflare Zero Trust PII role does not apply to Access audit logs. PII is a
44
44
45
45
For more information on Email Security roles, refer to [Account-scoped roles](/fundamentals/manage-members/roles/#account-scoped-roles).
46
46
47
-
-**Cloudflare Zero Trust**: Super Admin access for all Zero Trust products, Email Security included.
47
+
-**Cloudflare Zero Trust**: Can edit Cloudflare [Zero Trust](/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email Security.
48
48
-**Cloudflare Zero Trust PII**: Can read PII in Zero Trust. This includes Email Security.
49
-
-**Email Security Analyst** and **Email Security Config Admin**: Has full access to all admin features in Email Security.
49
+
-**Email Security Analyst** and **Email Security Configuration Admin**: Has full access to all admin features in Email Security.
50
50
-**Email Security Integration Admin**: Can read and set up integrations only.
51
-
-**Email Security Config Admin**: Has administrator access. Cannot take actions on emails, or read emails.
51
+
-**Email Security Configuration Admin**: Has administrator access. Cannot take actions on emails, or read emails.
52
52
-**Email Security Analyst**: Has analyst access. Can take action on emails and read emails.
53
53
-**Email Security Reporting**: Can read metrics.
54
54
-**Email Security Read Only**: Can read all information, but cannot take action on anything.
55
-
-**Email Security Policy Admin**: Can read all settings, but only write allow policies, trusted domains, and blocked senders.
55
+
-**Email Security Policy Admin**: Can read all settings, but only write [allow policies](/cloudflare-one/email-security/detection-settings/allow-policies/), [trusted domains](/cloudflare-one/email-security/detection-settings/trusted-domains/), and [blocked senders](/cloudflare-one/email-security/detection-settings/blocked-senders/).
| Super Admin | Email Security Analyst + Email Security Config Admin = Super Admin | Has full access to all products on Zero Trust Email Security |
29
-
| Configuration Admin | Email Security Configuration Admin | Admin, cannot take actions on emails or see emails |
30
-
| SOC Analyst | Email Security Analyst | Admin, can take actions on emails and see emails |
31
-
| Viewer | Email Security Reporting | Can see metrics |
28
+
| N/A | Cloudflare Zero Trust | Can edit Cloudflare [Zero Trust](/cloudflare-one/). Has administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email Security. |
29
+
| Super Admin | Email Security Analyst + Email Security Configuration Admin = Super Admin | Has full access to all admin features in Email Security |
30
+
| Configuration Admin | Email Security Configuration Admin | Has administrator access. Cannot take actions on emails, or read emails |
31
+
| SOC Analyst | Email Security Analyst | Has analyst access. Can take action on emails and read emails. |
Copy file name to clipboardExpand all lines: src/content/docs/fundamentals/manage-members/roles.mdx
+6-5Lines changed: 6 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,11 +39,12 @@ Account-scoped roles apply across an entire Cloudflare account, and through all
39
39
| Cloudflare Zero Trust Read Only | Can access [Cloudflare Zero Trust](/cloudflare-one/) read only mode. |
40
40
| Cloudflare Zero Trust Reporting | Can access [Cloudflare Zero Trust](/cloudflare-one/) reporting data. |
41
41
| DNS | Can edit [DNS records](/dns/manage-dns-records/). |
42
-
| Email Configuration Admin | Grants write access to all of Email Security, [CASB](/cloudflare-one/applications/casb/), [DLP](/cloudflare-one/policies/data-loss-prevention/), [Gateway](/cloudflare-one/policies/gateway/), and [Tunnels](/cloudflare-one/connections/connect-networks/), except Mail Preview, Raw Email, on-demand reports, actions on emails, and Submissions, Submission Transparency (Requires Cloudflare Zero Trust PII). |
43
-
| Email Integration Admin | Grants write access to Email Security account integration only, [CASB](/cloudflare-one/applications/casb/), [DLP](/cloudflare-one/policies/data-loss-prevention/), [Gateway](/cloudflare-one/policies/gateway/), and [Tunnels](/cloudflare-one/connections/connect-networks/). |
44
-
| Email Security Analyst | Grants write access to all of Email Security, except Settings which is read only (Requires Cloudflare Zero Trust PII). |
45
-
| Email Security Read Only | Grants read access to all of Email Security, but cannot see Raw Email, take action on emails, or make Submissions (Requires Cloudflare Zero Trust PII). |
46
-
| Email Security Reporting | Grants read access to Email Security Home, PhishGuard, and Submission Transparency. |
42
+
| Email Configuration Admin | Grants administrator access to Email Security. Cannot take actions on emails, or read emails. |
43
+
| Email Integration Admin | Grants read and write access to integrations only. |
44
+
| Email Security Analyst | Grants analyst access. Can take action on emails and read emails. |
45
+
| Email Security Read Only | Grants read only access to all of Email Security. |
| Email Security Policy Admin | Grants read access to all settings, and write access to [allow policies](/cloudflare-one/email-security/detection-settings/allow-policies/), [trusted domains](/cloudflare-one/email-security/detection-settings/trusted-domains/), and [blocked senders](/cloudflare-one/email-security/detection-settings/blocked-senders/)|
47
48
| Firewall | Can edit [WAF](/waf/), [IP Access rules](/waf/tools/ip-access-rules/), [Zone Lockdown](/waf/tools/zone-lockdown/) settings, and [Cache Rules](/cache/how-to/cache-rules/). |
48
49
| Load Balancer | Can edit [Load Balancers](/load-balancing/), Pools, Origins, and Health Checks. |
49
50
| Log Share | Can edit [Log Share](/logs/) configuration. |
0 commit comments