Roles with Global Scopes
These Global Roles use the scope All Applications, All Environments, and All Locations. You cannot change the scope for these roles. The roles have the following capabilities in Illumio Console.
Role | Granted Access |
---|---|
Owner | Perform all actions: add, edit, or delete any resource, security settings, or user account. |
Viewer | View any resource or organization setting. Viewers can perform only view operations. |
Provisioner | Provision policy objects, such as IP lists, services, and label groups. They cannot provision policies, virtual services, or virtual servers. Neither can they add, modify, or delete existing policy items. View all other resources. |