Skip to main content

Getting Started with the Illumio Console

Roles with Global Scopes

These Global Roles use the scope All Applications, All Environments, and All Locations. You cannot change the scope for these roles. The roles have the following capabilities in Illumio Console.

Role

Granted Access

Owner

Perform all actions: add, edit, or delete any resource, security settings, or user account.

Viewer

View any resource or organization setting. Viewers can perform only view operations.

Provisioner

Provision policy objects, such as IP lists, services, and label groups. They cannot provision policies, virtual services, or virtual servers. Neither can they add, modify, or delete existing policy items. View all other resources.