Permission catalog
Every permission that can be granted, grouped by product area. Use this page to find which key corresponds to the action you want to allow.
The labels are the same ones shown on the IAM screen.
How to read this
Level is how much damage the permission can do, and it is what the screen highlights:
| Level | Means |
|---|---|
| Low | Read-only, no side effects |
| Normal | Everyday changes |
| High | Destructive or expensive to undo |
| Critical | Data loss, or loss of access control |
Scopes lists where the key may be granted: Platform, Tenant, Customer, VDC. Granting outside the allowed scopes is rejected.
A key ending in :* grants everything under that prefix, at any depth — including permissions added in future releases.
IAM
| Permission | What it does | Level | Scopes |
|---|---|---|---|
* | Super administrator | Critical | P |
iam:* | All iam:* permissions | High | PTCV |
iam:audit:view | View audit log | Low | PTCV |
iam:grant:* | All iam:grant:* permissions | High | PTCV |
iam:grant:create | Create direct grant | Critical | PTCV |
iam:grant:renew | Renew direct grant | Normal | PTCV |
iam:grant:revoke | Revoke direct grant | High | PTCV |
iam:group:* | All iam:group:* permissions | High | PTCV |
iam:group:assign | Assign/unassign group | Critical | PTCV |
iam:group:delete | Delete group | High | PTCV |
iam:group:manage | Manage group | High | PTCV |
iam:group:set-permissions | Set group permissions | Critical | PTCV |
iam:users:* | All iam:users:* permissions | High | PTCV |
iam:users:effective-permissions:view | View effective permissions | Low | PTCV |
iam:users:invite | Invite user | Normal | PTCV |
iam:users:remove | Remove user | High | PTCV |
iam:users:update | Update user | Normal | PTCV |
iam:view | View IAM | Low | PTCV |
Tenant
| Permission | What it does | Level | Scopes |
|---|---|---|---|
tenant:* | All tenant:* permissions | High | PTCV |
tenant:manage | Manage organization | High | PT |
tenant:view | View organization | Low | PT |
Customer
| Permission | What it does | Level | Scopes |
|---|---|---|---|
customer:* | All customer:* permissions | High | PTC |
customer:archive | Archive customer | High | PT |
customer:create | Create customer | High | PT |
customer:reactivate | Reactivate customer | High | PT |
customer:update | Update customer | Normal | PTC |
customer:view | View customer | Low | PTC |
Contract
| Permission | What it does | Level | Scopes |
|---|---|---|---|
contract:* | All contract:* permissions | High | PTC |
contract:create | Create contract | High | PTC |
contract:link-vdc | Link VDC | High | PTC |
contract:update | Update contract | Normal | PTC |
contract:view | View contract | Low | PTC |
Billing
| Permission | What it does | Level | Scopes |
|---|---|---|---|
billing:* | All billing:* permissions | High | PTC |
billing:manage | Manage billing | High | PT |
billing:view | View billing | Normal | PTC |
VDC
| Permission | What it does | Level | Scopes |
|---|---|---|---|
vdc:* | All vdc:* permissions | High | PTCV |
vdc:create | Create VDC | Normal | PTCV |
vdc:delete | Delete VDC | High | PTCV |
vdc:update | Update VDC | Normal | PTCV |
vdc:view | View VDC | Low | PTCV |
Virtual machines
| Permission | What it does | Level | Scopes |
|---|---|---|---|
vm:* | All vm:* permissions | High | PTCV |
vm:clone | Clone VM | Normal | PTCV |
vm:console:* | All vm:console:* permissions | High | PTCV |
vm:console:file-transfer | Transfer files to/from VM console | Critical | PTCV |
vm:console:view | View VM console | Critical | PTCV |
vm:create | Create VM | Normal | PTCV |
vm:delete | Delete VM | High | PTCV |
vm:disk:* | All vm:disk:* permissions | High | PTCV |
vm:disk:destroy | Destroy VM disk | High | PTCV |
vm:disk:manage | Manage VM disks | Normal | PTCV |
vm:nic:* | All vm:nic:* permissions | High | PTCV |
vm:nic:manage | Manage VM NICs | Normal | PTCV |
vm:nic:manage-public-ip | Attach/detach public IP | High | PTCV |
vm:power | Power VM | Normal | PTCV |
vm:rename | Rename VM | Normal | PTCV |
vm:resize | Resize VM (memory & vCPU) | Normal | PTCV |
vm:snapshot:* | All vm:snapshot:* permissions | High | PTCV |
vm:snapshot:manage | Manage VM snapshots | Normal | PTCV |
vm:snapshot:rollback | Rollback VM snapshot | High | PTCV |
vm:view | View VM | Low | PTCV |
Storage
| Permission | What it does | Level | Scopes |
|---|---|---|---|
storage:* | All storage:* permissions | High | PTCV |
storage:attach | Attach orphan disk | Normal | PTCV |
storage:boot_disks:view | View boot disks | Low | PTCV |
storage:delete | Delete orphan disk | High | PTCV |
storage:disk_migration:* | All storage:disk_migration:* permissions | High | PTCV |
storage:disk_migration:delete | Delete disk migration | High | PTCV |
storage:disk_migration:manage | Manage disk migration | High | PTCV |
storage:disk_migration:view | View disk migration | Low | PTCV |
storage:object_storage:* | All storage:object_storage:* permissions | High | PTCV |
storage:object_storage:bucket:create | Create bucket | Normal | PTCV |
storage:object_storage:bucket:delete | Delete bucket | High | PTCV |
storage:object_storage:buckets:view | View buckets | Low | PTCV |
storage:object_storage:credential:delete | Delete storage credential | High | PTCV |
storage:object_storage:credential:manage | Manage storage credentials | High | PTCV |
storage:object_storage:credentials:view | View object storage credentials | Low | PTCV |
storage:object_storage:lock | Lock object/directory | Normal | PTCV |
storage:object_storage:object:delete | Delete object | High | PTCV |
storage:object_storage:object:upload | Upload object | Normal | PTCV |
storage:object_storage:path:create | Create path | Normal | PTCV |
storage:object_storage:path:delete | Delete path | High | PTCV |
storage:object_storage:view | View storage | Low | PTCV |
storage:rename | Rename orphan disk | Normal | PTCV |
storage:view | View orphan disks | Low | PTCV |
storage:volume_disks:view | View volume disks | Low | PTCV |
Object storage
| Permission | What it does | Level | Scopes |
|---|---|---|---|
object-storage:* | All object-storage:* permissions | High | PT |
object-storage:create | Create object storage provider | Normal | PT |
object-storage:delete | Delete object storage provider | High | PT |
object-storage:update | Update object storage provider | Normal | PT |
object-storage:view | View object storage providers | Low | PT |
Network
| Permission | What it does | Level | Scopes |
|---|---|---|---|
network:* | All network:* permissions | High | PTCV |
network:customer_gateway:* | All network:customer_gateway:* permissions | High | PTCV |
network:customer_gateway:manage | Manage customer gateway | High | PTCV |
network:customer_gateway:view | View customer gateway | Low | PTCV |
network:dns:manage | Manage DNS records | Normal | PTCV |
network:public-ip:* | All network:public-ip:* permissions | High | PTCV |
network:public-ip:allocate | Attach public IP | Normal | PTCV |
network:public-ip:release | Detach public IP | Normal | PTCV |
network:public_ips:view | View public IPs | Low | PTCV |
network:subnet:* | All network:subnet:* permissions | High | PTCV |
network:subnet:delete | Delete subnet | High | PTCV |
network:subnet:manage | Manage subnet | Normal | PTCV |
network:view | View network | Low | PTCV |
network:vnet:* | All network:vnet:* permissions | High | PTCV |
network:vnet:create | Create VNet | Normal | PTCV |
network:vnet:delete | Delete VNet | High | PTCV |
network:vnet:update | Update VNet | Normal | PTCV |
network:vnet:view | View VNet | Low | PTCV |
Security
| Permission | What it does | Level | Scopes |
|---|---|---|---|
security:* | All security:* permissions | High | PTCV |
security:firewall:* | All security:firewall:* permissions | High | PTCV |
security:firewall:delete | Delete firewall rule | High | PTCV |
security:firewall:manage | Manage firewall rules | High | PTCV |
security:firewall:view | View firewall | Low | PTCV |
security:perimeter:* | All security:perimeter:* permissions | High | PTCV |
security:perimeter:delete | Delete perimeter policy | High | PTCV |
security:perimeter:manage | Manage perimeter policies | High | PTCV |
security:perimeter:view | View perimeter policy | Low | PTCV |
security:view | View security section | Low | PTCV |
Customer Connect
| Permission | What it does | Level | Scopes |
|---|---|---|---|
customer-connect:* | All customer-connect:* permissions | High | PTCV |
customer-connect:direct_connect:* | All customer-connect:direct_connect:* permissions | High | PTCV |
customer-connect:direct_connect:delete | Delete Direct Connect | High | PTCV |
customer-connect:direct_connect:manage | Manage Direct Connect | High | PTCV |
customer-connect:direct_connect:view | View Direct Connect | Low | PTCV |
customer-connect:ipsec:* | All customer-connect:ipsec:* permissions | High | PTCV |
customer-connect:ipsec:connect | Connect/disconnect IPSec VPN | Normal | PTCV |
customer-connect:ipsec:create | Create IPSec VPN | High | PTCV |
customer-connect:ipsec:delete | Delete IPSec VPN | High | PTCV |
customer-connect:ipsec:view | View IPsec | Low | PTCV |
customer-connect:openvpn:view | View OpenVPN server | Low | PTCV |
customer-connect:view | View customer connect section | Low | PTCV |
customer-connect:vpn:* | All customer-connect:vpn:* permissions | High | PTCV |
customer-connect:vpn:create | Create OpenVPN server | High | PTCV |
customer-connect:vpn:delete | Delete OpenVPN server | High | PTCV |
customer-connect:vpn:power | Power OpenVPN server | Normal | PTCV |
customer-connect:vpn:route:add | Add VPN route | Normal | PTCV |
customer-connect:vpn:route:remove | Remove VPN route | Normal | PTCV |
customer-connect:vpn:update | Update OpenVPN server | High | PTCV |
customer-connect:vpn:user:create | Create VPN user | Normal | PTCV |
customer-connect:vpn:user:delete | Delete VPN user | Normal | PTCV |
customer-connect:vpn:user:disconnect | Disconnect VPN user | Normal | PTCV |
customer-connect:vpn:user:update | Update VPN user | Normal | PTCV |
Backup
| Permission | What it does | Level | Scopes |
|---|---|---|---|
backup:* | All backup:* permissions | High | PTCV |
backup:backup_jobs:view | View backup jobs | Low | PTCV |
backup:backups:view | View backups | Low | PTCV |
backup:create | Create backup | Normal | PTCV |
backup:delete | Delete backup | Critical | PTCV |
backup:job:* | All backup:job:* permissions | High | PTCV |
backup:job:delete | Delete backup job | High | PTCV |
backup:job:manage | Manage backup job | Normal | PTCV |
backup:restore | Restore backup | High | PTCV |
backup:view | View backup | Low | PTCV |
Virtual router
| Permission | What it does | Level | Scopes |
|---|---|---|---|
vrouter:* | All vrouter:* permissions | High | PT |
vrouter:resolve | Resolve VRouter executions | High | PT |
vrouter:update | Update VRouters | Normal | PT |
vrouter:view | View VRouter releases | Low | PT |
Support
| Permission | What it does | Level | Scopes |
|---|---|---|---|
support:* | All support:* permissions | High | P |
support:act-as-user | Impersonate user | Critical | P |
support:view-all-vdcs | View all VDCs as NOC | High | P |