Skip to main content

Users and Roles

Connect users are managed under Settings > Users. Each user has roles, each granted on a project, and those assignments decide what the user can see and do. Managing users needs the Administrators role.

Inviting a user

Click New User and enter a first and last name, a username, and an email address, then add any Initial Roles: a role and the project it applies to. Send Invite creates the user and emails them an invitation to set their password.

If your organization also uses FireMon Cloud Defense, its users already appear in the list; give them Connect roles.

Editing and removing a user

Click the edit button on a user's row to expand it. The panel lists the user's current role assignments, each with a remove button, and lets you add new ones. A user whose account has been disabled shows a red icon beside their name. The delete button beside the edit button removes the user from your organization.

Roles

Six roles apply to Connect:

RoleIntended forWhat it allows in Connect
AdministratorsThe people who run ConnectEverything: accounts, users, API keys, projects, Group Credentials, Boundaries, change requests, Decommission, and the organization-wide settings.
Project ManagersOwners of a projectEverything a Readonly User can see, plus creating and editing projects, creating Decommission actions and approving or rejecting candidates, and viewing change requests.
Readonly UsersAnyone who needs to look but not touchView inventory, Groups, the Boundaries list, Decommission, accounts, projects, users, and settings.
Connect Boundary AuthorThe security team writing policyCreate and edit Boundaries. View inventory, Groups, change requests, accounts, projects, and users.
Firewall Change RequestorsPeople who ask for firewall changesCreate change requests, and edit the ones they created or last updated. View inventory and Groups through the request form's pickers, plus accounts and projects. In the app they see only Change.
Firewall Change ApproversPeople who review requestsView change requests and the Boundaries list, plus inventory, Groups, accounts, projects, and users.

Groups are created, edited, and deleted by Administrators only, as is approving a Manual Group's pending changes. Every other role can view them.

The Users page shows these six roles.

Role scope and projects

A role is granted on one project and applies to that project and every project beneath it. Granting a role on the root project (your organization) covers everything. Granting it on a sub-project limits the user to the accounts, Groups, Boundaries, change requests, and Decommission actions in that project and its children; objects elsewhere don't appear for them. A user can hold different roles on different projects, for example Connect Boundary Author on a lab project and Readonly Users everywhere else. See Projects.

Troubleshooting access

  • They need to see change requests. Change requests are visible to Firewall Change Requestors, Firewall Change Approvers, Connect Boundary Author, Project Managers, and Administrators.
  • They see only the Change page. Their only role is Firewall Change Requestors. Add another role for anything more.
  • A Group, Boundary, or account is missing for them. It's in a project outside their role assignments. Check the object's Project column against them.
  • A page says "Not authorized". Same cause: the role needed is granted on a different project, or on none.