---
title: "Permissions Reference"
slug: "permissions-reference"
updated: 2026-07-09T05:30:48Z
published: 2026-07-09T05:30:48Z
canonical: "support.controlup.com/permissions-reference"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.controlup.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions Reference

This article lists the permissions for each ControlUp product and capability, as well as the default roles they are assigned to. The default roles are: *Admin*, *Editor*, *Viewer*, *VDI and DaaS Admins*, *Access Real-Time DX Console,* and *DaaS IQ Admin*. You can also create custom roles and assign them the specific permissions required for your organization. For more details, visit [Set ControlUp Account Permissions](https://support.controlup.com/v1/docs/dex-platform-account-permissions).

## Create a Customized Permissions Planning Sheet

You can build your own permissions planning worksheet by exporting this article and converting it into an editable format. Follow the steps below to download the Permissions Reference as a PDF, save it as an Excel file, and customize it for your organization:

1. On the top right corner of this article, click the 3 dots > **Export PDF**.
2. Save the PDF file to your computer.
3. Convert the PDF into an Excel sheet.

Now that your Permissions Reference is in Excel, you can tailor it to plan roles and access levels across your organization.

## Access Control

| Permission | Description | Default Roles |
| --- | --- | --- |
| View settings | Access settings such as the users/roles in your organization, IP restrictions, and SAML settings, but does not let you make any changes to these settings. | Admin |
| Manage users | Invite, disable/enable, or delete users, or change a user's roles. | Admin |
| View users | View users and their roles | Admin |
| Manage roles | Create/delete roles, and edit existing roles. | Admin |
| Manage SSO access | Configure SAML Single Sign On. Read [How to Configure SAML Single SSO with Your IdP](/v1/docs/saml-sso-for-dex) for details. | Admin |
| Manage Integrations | Configure integrations in the DEX Platform global settings page. Read [Integrations overview](https://support.controlup.com/docs/controlup-integrations-overview) for details. | Admin |
| Manage login methods | Configure the allowed login methods for your organization. Read [Login Methods Overview](/v1/docs/login-methods-overview) for details. | Admin |
| Manage MFA | Configure the allowed Multi-Factor Authentication methods for your organization. | Admin |
| Manage session timeout | Configure the session timeout duration for your organization. | Admin |
| View Audit Log | View the DEX Platform Audit Log. Read [Audit Logs](/v1/docs/dex-audit-log) for details. | Admin |
| Manage IP restrictions | Configure IP restrictions. Read [IP Restrictions](/v1/docs/ip-allow-list) for details. | Admin |
| Manage PII Encryption | Not currently used. |  |
| Manage Default Home Page | Configure the default home page. Read [Set the Default Home Page](/v1/docs/set-the-default-home-page) for details. | Admin |
| TV Mode | Accounts with this permission ignore the session timeout duration and are never signed out due to inactivity. This can be useful for displaying dashboards on TVs for continuous monitoring. | - - - |
| Manage Tags | Create, edit, or delete tags in the Tags Management settings page. Read [Centralized Tags Management](/v1/docs/centralized-tags-management) for details. | Admin |
| Associate Synthetic Monitoring Tags | Lets you apply tags to Synthetic Monitoring Scouts and Hives. See Centralized Tags Management for details. | Admin, Editor |

## Subscription

| Permission | Description | Default Roles |
| --- | --- | --- |
| Manage Subscription | Manage your licensed products: activate your license, view its status, renewal dates and usage data, as well as extend or expand your license. Read [Subscription Overview](https://support.controlup.com/v1/docs/what-is-the-new-subscription-feature) for details. | Admin |

## Employees

| Permission | Description | Default Roles |
| --- | --- | --- |
| Access App Group AI | Use ControlUp AI to suggest app groups. Read [App groups](https://support.controlup.com/docs/experience-scores#app-groups) for details | Admin |
| Access Employees | View the Employees dashboards and details pages. Read [Employees View Overview](/v1/docs/employees-view-overview) for details. | Admin, Editor, Viewer |
| Manage Experience Score Rules | Configure Experience Score calculation settings. Read [Experience Scores](/v1/docs/experience-scores) for details. | Admin |
| View Experience Score Rules | View the Experience Score calculation settings | Admin |

## Device Permissions

| Permission | Description | Default Roles |
| --- | --- | --- |
| Run Command | Use the Run Command action to execute a command on a device. | Admin, Editor |
| Send Message | Send messages to devices. Read [Send Messages](/v1/docs/send-a-message-to-a-device) for details | Admin, Editor |
| Power Actions | Perform power actions on a device (Logoff user, Disconnect user, Reboot) | Admin, Editor |
| Terminate Process | Terminate a process on a device. You can perform this action from the **Active Processes** tab when drilling down into the details for a specific device. | Admin, Editor |
| Run Ungrouped Scripts | Run scripts in the permission group **Ungrouped**. Read [Script permissions](https://support.controlup.com/docs/scripting-guide#script-permissions) for details. | Admin, Editor |
| Run Group (1,2,3,4,5) Scripts | Run scripts in the permission group **Group (1,2,3,4,5)**. Read [Script permissions](https://support.controlup.com/docs/scripting-guide#script-permissions) for details. | Admin, Editor |
| Set Device Group | Add or remove a device from a device group. Note that device groups can be used for RBAC. This means that changing a device's group can change who has access to that device. Read [Organize Devices with Groups and Tags](/v1/docs/organize-devices-with-groups-and-tags) for details. | Admin, Editor |
| Set Device Tags | Add or remove tags from a device. Note that device tags can be used for RBAC. This means that changing a device's tags can change who has access to that device. Read [Organize Devices with Groups and Tags](/v1/docs/organize-devices-with-groups-and-tags) for details. | Admin, Editor |
| Configure Device Agent Settings | Change the agent debugger level, toggle auto agent update, and save notes. These actions are performed when viewing the details for a specific device. | Admin, Editor |
| Delete Device | Delete a device. Read [Licensing](/v1/docs/edge-dx-licensing) for details. | Admin, Editor |
| Allow Remote Shell | Start Remote Shell sessions. Read [Remote Shell](/v1/docs/open-a-remote-shell-on-a-device) for details. | Admin, Editor |
| Do Not Audit Remote Shell Commands | If you have this permission, then the commands you run during a Remote Shell session are **not** recorded in the System Events log. Read [Remote Shell](/v1/docs/open-a-remote-shell-on-a-device) for details. | Admin, Editor |
| Allow Remote Control | Start Remote Control Sessions. Read [Remote Control and Shadow](/v1/docs/remote-control-or-shadow-a-device) for details. | Admin, Editor |
| Allow File Transfer | Use two-way file transfer during Remote Control Sessions. Read [Remote Control and Shadow](/v1/docs/remote-control-or-shadow-a-device) for details. | Admin, Editor |
| Allow Elevated Command Shell | Open an elevated cmd prompt during Remote Control Sessions. Read [Remote Control and Shadow](/v1/docs/remote-control-or-shadow-a-device) for details. | Admin, Editor |
| Allow Remote Shadow | Start Remote Shadow sessions. Read [Remote Control and Shadow](/v1/docs/remote-control-or-shadow-a-device) for details. | Admin, Editor |
| Allow Remote Control and Remote Shadow without End User Consent | Start Remote Control and Remote Shadow sessions without the end user of the device agreeing to a consent prompt. Read [Remote Control and Shadow](/v1/docs/remote-control-or-shadow-a-device) for details. | Admin, Editor |
| Allow Smart Consent Bypass | Not currently used |  |
| Allow remote control to unmanaged devices | Start a remote control session on unmanaged devices. Read [Remote Control for Unmanaged Devices](/v1/docs/remote-control-for-unmanaged-devices) for details. | Admin |
| Allow file transfer to unmanaged devices | Send and receive files during a remote control session on unmanaged devices. Read [Remote Control for Unmanaged Devices](/v1/docs/remote-control-for-unmanaged-devices) for details. | Admin |
| View Non-Security Events | View all events in the security events log except those with type = Security. Read [Audit Logs](/v1/docs/dex-audit-log) for details. | Admin |
| View Security Events | View events in the security events log with type = Security. Read [Audit Logs](/v1/docs/dex-audit-log) for details. | Admin |
| View, Create, Edit and Delete Alerts | View, create, edit, and delete alerts. Read [Create Alerts](/v1/docs/create-alerts) for details. | Admin, Editor |
| View and Configure ServiceNow Incidents | View and configure ServiceNow incidents. Read [ServiceNow Integration](https://support.controlup.com/v1/docs/servicenow-integration) for details. | Admin, Editor |
| View Scripts | View scripts that have been added to your organization. Read [Scripting Guide](/v1/docs/scripting-guide) for details. | Admin, Editor |
| View, Create, Edit and Delete Scripts | Manage scripts in your organization, including adding new scripts. We recommend that you grant this permission only to senior administrators due to the inherent risk from adding and running custom scripts on your managed devices. Read [Scripting Guide](/v1/docs/scripting-guide) for details. | Admin, Editor |
| View Index Data | Access all data indexes. | Admin, Editor |
| Read Indexes | View the total number of indexes, the total number of records, and the total GB stored. | Admin, Editor |
| Delete Indexes | Delete a data index. Deleting a data index also deletes the contents of the index. | Admin, Editor |
| Prune Data | Delete the contents of a data index. | Admin, Editor |
| View Custom Reports | View Custom Reports that other users in your organization have published. Read [Create Custom Reports](/v1/docs/create-custom-reports) for details. | Admin, Editor |
| Create, Edit and Delete Custom Reports | Create your own Custom Reports. Read [Create Custom Reports](/v1/docs/create-custom-reports) for details. | Admin, Editor |
| Publish Custom Reports | Publish your Custom Reports so that they can be viewed by other users in your organization. Read [Create Custom Reports](/v1/docs/create-custom-reports) for details. | Admin, Editor |
| Create, Edit and Delete Filter Presets | Create, edit, and delete your own private filter presets. Read [Create and Share Filter Presets](/v1/docs/create-and-share-filter-presets) for details. | Admin, Editor |
| Publish Filter Presets | Publish your filter presets so they can be used by all users in your organization. Read [Create and Share Filter Presets](/v1/docs/create-and-share-filter-presets) for details. | Admin, Editor |
| Allow Export to CSV | Export data to CSV | Admin, Editor |
| Configure Production Agent Versions | Configure which Agent versions are installed on devices. Read [Agent Version Control](/v1/docs/agent-version-control) for details. | Admin, Editor |
| Configure Agent Intervals | Configure the duration for short and long trigger intervals. Read [Time-based triggers](https://support.controlup.com/docs/scripting-guide#timebased-triggers) for details. | Admin, Editor |
| Configure Agent Feature Settings | Configure Windows Event Log Collection settings. Read [Windows Event Logs](/v1/docs/windows-event-logs-with-edge-dx) for details. | Admin, Editor |
| Configure Auto Deletion of Old Devices | Configure auto deletion of devices after they haven't connected to ControlUp for a specified duration. Read [Licensing](/v1/docs/edge-dx-licensing) for details. | Admin, Editor |
| Configure Custom Settings | Configure **Custom Settings**. Note that custom settings let you make many different types of changes to your tenant, and you should apply custom settings only if you are specifically instructed to do so. | Admin, Editor |
| Configure Device Dashboards Settings | Access the **Web Console** settings page to configure stress level thresholds and to display or hide time gaps in dashboard charts. | Admin, Editor |
| Configure End User Activity Collection | Configure End User Activity data collection. Read [End User Activity](/v1/docs/end-user-activity) for details. | Admin, Editor |
| Configure End User Activity Collection - Individual User Info | Enable or disable the setting **Collect Individual User Information** in End User Activity settings. Read [End User Activity](/v1/docs/end-user-activity) for details. | Admin, Editor |
| Configure Extended Settings | Configure **Extended Settings**. Read [Extended Settings](/v1/docs/extended-settings) for details. | Admin |
| Configure Network Latency Targets | Add custom latency targets. Read [Network Performance](https://support.controlup.com/docs/network-performance#configure-multiple-latency-targets) for details. | Admin, Editor |
| Configure ServiceNow Connector | Configure the ServiceNow connector to integrate ControlUp for Desktops Alerts with ServiceNow. Read [ServiceNow Integration](/v1/docs/servicenow-integration) for details. | Admin, Editor |
| View and Configure ServiceNow Incidents | Use the ServiceNow integration’s features in ControlUp, such as viewing ServiceNow widgets and configuring an Alert to create a ServiceNow ticket. Read [ServiceNow Integration](/v1/docs/servicenow-integration) for details. | Admin, Editor |
| Configure Google Cloud Connector | Configure the Google Cloud connector for additional ChromeOS data collection. Read [ChromeOS Deployment](/v1/docs/chromeos-edge-dx-deployment) for details. | Admin, Editor |
| License Assignment | Use the License assignment feature to claim licenses. Read [Licensing](/v1/docs/edge-dx-licensing) for details. | Admin |
| Show Agent Download Page | View the Agent downloads page to see your organization's device registration code and download the ControlUp for Desktops Agent. Read [Agent Installation Overview](/v1/docs/edge-dx-agent-installation) for details. | Admin |
| Management Remote Control Settings | Configure remote control/shadow auto-reconnect settings. Read [Automatic reconnect](https://support.controlup.com/docs/remote-control-or-shadow-a-device#automatic-reconnect) for details. | Admin |
| View Reports with user privacy information | View the following reports: - Location History - Network Interfaces - Power and Session Events - Stopped Processes - Top Users by Application - Top User Process Elevations - Top Users Starting Processes with Elevated Rights - Local Administrators - Logons and Sessions - Top User Profiles by Size - User Profiles View the Device Events tab when viewing the details for a specific device (if you also have either the 'View Non-Security Events' or 'View Security Events' permission). | Admin, Editor |
| View End User Activity | View the **End User Activity** dashboard. Read [End User Activity](/v1/docs/end-user-activity) for details. | Admin, Editor |
| View Wi-Fi SSID and MAC | View SSID and MAC address columns in reports. Note that you can still view the SSID and MAC address of a device outside of reports even if you don't have this permission. | Admin, Editor |
| Performance | Set the date picker to **Now** on the device details drilldown page to start getting 3-second metric updates from the device. Read [Viewing Your List of Devices](/v1/docs/device-dashboard-overview#drill-down-to-details-for-a-specific-device) for details. | Admin, Editor, Viewer |
| Access Processes | View the **Active Processes** tab on the device details page. Read [Real-Time Process Details](/v1/docs/live-process-details) for details. | Admin, Editor, Viewer |
| End Process | End a process on the **Active Processes** tab. Read [Real-Time Process Details](/v1/docs/live-process-details) for details. | Admin, Editor |
| Network Traffic | View the **TCP Connections** page under the **Network** tab on the device details page. Read [Real-Time Network Analysis](/v1/docs/live-network-analysis) for details. | Admin, Editor, Viewer |
| Map View | View the **Map** page under the **Network** tab on the device details page. Read [Real-Time Network Analysis](/v1/docs/live-network-analysis) for details. | Admin, Editor, Viewer |
| Storage | View the **Topology** page under the **Network** tab on the device details page. Read [Real-Time Network Analysis](/v1/docs/live-network-analysis) for details. | Admin, Editor, Viewer |
| View Files (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| View Folders (User Files) | Not currently used. See the permission below for System Files for more information. | Admin |
| Modify Files (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Modify Folders (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Create Files (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Create Folders (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Delete Files (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Delete Folders (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Download (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| Upload (User Files) | Not currently used. See the permission below for System Files for more information. | None |
| View Files (System Files) | Lets you see the contents of folders (file names, file size, created, date, modified date, etc.). This permission does **not** allow the user to open a file (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| View Folders (System Files) | Required for access to the file browser features. Allows the user to load the directory tree and see the names of folders (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | Admin |
| Modify Files (System Files) | Allows the user to move and rename files (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Modify Folders (System Files) | Allows the user to move and rename folders (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Create Files (System Files) | Allows the user to copy a file to a new location (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Create Folders (System Files) | Allows the user to create folders (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Delete Files (System Files) | Allows the user to delete files (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Delete Folders (System Files) | Allows the user to delete folders (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Download (System Files) | Allows the user to transfer files from remote machine to local machine (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| Upload (System Files) | Allows the user to transfer files from local machine to remote machine (for both system files AND user files). Read [File Browser](/v1/docs/file-browser) for details. | None |
| View (System Hives) | Allows the user to view a device’s registry. Read [Registry Editor](/v1/docs/registry-editor) for details. | Admin |
| Modify (System Hives) | Allows the user to make changes to the registry. Read [Registry Editor](/v1/docs/registry-editor) for details. | Admin |
| Import (System Hives) | Allows the user to import .reg files to update the registry. Read [Registry Editor](/v1/docs/registry-editor) for details. | Admin |
| Export (System Hives) | Allows the user to export .reg files from the registry. Read [Registry Editor](/v1/docs/registry-editor) for details. | Admin |
| View (User Hives) | Not currently used. | Admin |
| Modify (User Hives) | Not currently used. | Admin |
| Import (User Hives) | Not currently used. | Admin |
| Export (User Hives) | Not currently used. | Admin |
| View Device Location | Allows the user to view device geolocation. Read [Device Geolocation](/v1/docs/device-geolocation#manage-location-privacy) for details. |  |

## Sentiment

| Permission | Description | Default Roles |
| --- | --- | --- |
| View, Create, Edit and Delete Templates | Create, edit, and delete survey templates. Read [Survey Library](/v1/docs/survey-library) for details. | Admin |
| View, Create, Edit and Delete Surveys | Create surveys, and edit/delete surveys that you have created. Read [Publish and Distribute Surveys](/v1/docs/publish-and-distribute-surveys) for details. | Admin, Editor |
| Edit and Delete Surveys owned by other users | Edit or delete surveys that other users have created. Read [Publish and Distribute Surveys](/v1/docs/publish-and-distribute-surveys) for details. | Admin, Editor |
| View Results from other Users Surveys | View survey results from surveys that other users have published. Without this permission, you can only view results from surveys that you have created. | Admin, Editor |
| Send On Demand Surveys | Manually perform an action to send a survey to a device. Read [On Demand Surveys](https://support.controlup.com/docs/publish-and-distribute-surveys#on-demand) for details. | Admin |
| Configure Global Settings | Configure settings that affect all of your surveys. Read [Employee Sentiment Settings](/v1/docs/employee-sentiment-settings) for details. | Admin |

## Media Library

| Permission | Description | Default Roles |
| --- | --- | --- |
| Upload, Edit and Delete items | Upload, edit, or delete items to the Media library. Read [Asset Library](/v1/docs/asset-library) for details | Admin |

## Unified Communications and Collaboration

| Permission | Description | Default Roles |
| --- | --- | --- |
| UC&C Dashboards | View UC&C dashboards, call details, and reports. Read [Explore Microsoft Teams Data](/v1/docs/explore-ucc-data-teams) or [Explore Zoom Data](/v1/docs/explore-ucc-data-zoom) for details. | Admin, Editor, Viewer |
| View Zoom call topic | View the call topic of Zoom calls. | Admin, Editor, Viewer |
| API Configuration | Configure Microsoft Teams and Zoom integrations. Read [Microsoft Teams Integration](/v1/docs/ucc-getting-started-teams) or [Zoom Integration](/v1/docs/ucc-getting-started-zoom) for details. | Admin |

## VDI

| Permission | Description | Default Roles |
| --- | --- | --- |
| Access Access VDI & DaaS | View the Overview page in the VDI & DaaS web UI. Read [How to Access the VDI & DaaS Web UI](/v1/docs/vdi-daas-authentication-methods) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Access Details page | View the Details page in the VDI & DaaS web UI. Read [How to Access the VDI & DaaS Web UI](/v1/docs/vdi-daas-authentication-methods) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Access Real-Time DX Console | Sign in to the Real-Time DX console with your ControlUp account using the web-login feature. Read [Sign into the Real-Time DX Console](/v1/docs/sign-in-to-the-real-time-console) for details. | Admin, VDI and DaaS Admins |
| Manage Remediation Settings | Configure VDI monitoring and remediation settings. Read [Monitor and Remediate Your ControlUp for VDI](/v1/docs/controlup-support-monitor-and-remediate) for details. | Admin, VDI and DaaS Admins |

## DaaS IQ

| Permission | Description | Default Roles |
| --- | --- | --- |
| View All | View all pages in DaaS IQ. Read [ControlUp DaaS IQ](/v1/docs/daas-iq) for details. | Admin, Viewer, DaaS IQ Admin |
| Manage Hosts | Manage hosts in DaaS IQ. Read [ControlUp DaaS IQ](/v1/docs/daas-iq) for details. | Admin, DaaS IQ Admin |
| Manage Sessions | Manage sessions in DaaS IQ. Read [ControlUp DaaS IQ](/v1/docs/daas-iq) for details. | Admin, DaaS IQ Admin |
| Apply Scaling Policies | Apply existing scaling policies to host pools in DaaS IQ. Read [Autoscale Host Pools](/v1/docs/autoscale-host-pools) for details. | Admin, DaaS IQ Admin |
| Manage Scaling Profiles | Configure and manage scaling policies for host pools in DaaS IQ. Read [Autoscale Host Pools](/v1/docs/autoscale-host-pools) for details. | Admin, DaaS IQ Admin |
| View Settings | View all settings in DaaS IQ. | Admin, Viewer, DaaS IQ Admin |
| Manage Settings | Manage all settings in DaaS IQ. | Admin, DaaS IQ Admin |
| Manage Host Pool Settings | Manage host pool settings in DaaS IQ. | Admin, DaaS IQ Admin |

## Synthetic Monitoring

| Permission | Description | Default Roles |
| --- | --- | --- |
| Create Scout | Create EUC, Infrastructure and Application scouts. Read [Welcome to Synthetic Monitoring](https://support.controlup.com/v1/docs/getting-started-with-scoutbees) for details. | Admin, Editor |
| Read Scout | View Synthetic Monitoring scouts | Admin, Editor, Viewer |
| Update Scout | [Update](/v1/docs/manage-your-scouts#edit-scouts) scouts | Admin, Editor |
| Delete Scout | [Delete](/v1/docs/manage-your-scouts#delete-scouts) scouts | Admin, Editor |
| Create Alert | [Create](/v1/docs/alert-policies#create-an-alert-policy-for-a-scout) an alert for a scout | Admin, Editor |
| Read Alert | [View](/v1/docs/alert-policies) the alert policy of a scout | Admin, Editor, Viewer |
| Update Alert | [Update](/v1/docs/manage-your-scouts) the alert policy of a scout | Admin, Editor |
| Delete Alert | [Delete](/v1/docs/alert-policies#delete-an-alert-policy) the alert policy of a scout | Admin, Editor |
| Create Hive | [Create](/v1/docs/installing-custom-hives#installation) a Custom Hive | Admin, Editor |
| Read Hive | [View](/v1/docs/custom-hives) Cloud and Custom Hives | Admin, Editor, Viewer |
| Update Hive | [Update](https://support.controlup.com/v1/docs/upgrade-your-custom-hives) a Custom Hive | Admin, Editor |
| Delete Hive | [Delete](/v1/docs/installing-custom-hives#delete-custom-hives) a Custom Hive | Admin, Editor |
| Assign Hives to Scouts | Lets users select Hives when creating or editing Scouts. Users can select only Hives within their permission and tag scope. | Admin, Editor |
| Create Maintenance Windows | [Create](/v1/docs/maintenance-window) a Maintenance Window to prevent receiving alerts during scheduled maintenance | Admin, Editor |
| Read Maintenance Windows | [View](/v1/docs/maintenance-window) Maintenance Windows for Scouts and Custom Hives | Admin, Editor, Viewer |
| Update Maintenance Windows | [Edit](/v1/docs/maintenance-window#manage-your-maintenance-windows) your maintenance Windows for Scouts and Custom Hives | Admin, Editor |
| Delete Maintenance Windows | [Delete](/v1/docs/maintenance-window#manage-your-maintenance-windows) Maintenance Windows for Scouts and Custom Hives | Admin, Editor |
| Create Integration | Create integrations with [ServiceNow](/v1/docs/integration-with-servicenow#add-a-servicenow-integration) and [Microsoft Teams](/v1/docs/integration-with-microsoft-teams#add-a-microsoft-teams-integration) | Admin, Editor |
| Read Integration | View integrations with ServiceNow and Microsoft Teams | Admin, Editor, Viewer |
| Update Integration | Edit the integrations with [ServiceNow](/v1/docs/integration-with-servicenow#edit-or-delete-the-servicenow-integration) and [Microsoft Teams](/v1/docs/integration-with-microsoft-teams#edit-or-delete-the-microsoft-teams-integration) | Admin, Editor |
| Delete Integration | Delete the integrations with [ServiceNow](/v1/docs/integration-with-servicenow#edit-or-delete-the-servicenow-integration) and [Microsoft Teams](/v1/docs/integration-with-microsoft-teams#edit-or-delete-the-microsoft-teams-integration) | Admin, Editor |
| Create API Key | Create an API key for the Synthetic Monitoring API. Note that these dedicated Synthetic Monitoring API keys have been replaced by the unified ControlUp platform API key. [Learn more](https://api.controlup.io/changelog/february-2026). | Admin, Editor |
| Read API Key | View information about API keys for the Synthetic Monitoring API. Note that these dedicated Synthetic Monitoring API keys have been replaced by the unified ControlUp platform API key. [Learn more](https://api.controlup.io/changelog/february-2026). | Admin, Editor, Viewer |
| Update API Key | Revoke API keys for the Synthetic Monitoring API. Note that these dedicated Synthetic Monitoring API keys have been replaced by the unified ControlUp platform API key. [Learn more](https://api.controlup.io/changelog/february-2026). | Admin, Editor |
| Delete API Key | Delete API keys for the Synthetic Monitoring API. Note that these dedicated Synthetic Monitoring API keys have been replaced by the unified ControlUp platform API key. [Learn more](https://api.controlup.io/changelog/february-2026). | Admin, Editor |
| Update Organization Settings |  | Admin |

## API keys

VDI & DaaS APIs

In app.controlup.com, there is a permission category "VDI & DaaS APIs". These permissions aren't currently used and will be removed soon. For details about access to VDI & DaaS reports through the API, read the [Reports](/v1/docs/permissions-reference#reports) section.

| Permission | Description | Default Roles |
| --- | --- | --- |
| Manage API keys | Create, revoke, or delete API keys. Read [Create an API Key](/v1/docs/create-an-api-key) for details. | Admin |

Secure DX Management

Descriptions for Secure DX Management (ControlUp for Compliance) permissions are in progress.

## Reports

| Permission | Description | Default Roles |
| --- | --- | --- |
| Environment Assessment | View the Environment Assessment report. Read [Environment Assessment](/v1/docs/environment-assessment) for details. | Admin, Editor. Viewer, VDI and DaaS Admins |
| Sizing Recommendations | View the Sizing Recommendations report. Read [Sizing Recommendations Report](/v1/docs/sizing-recommendations-report) for details. Use the **Get machine statistics for virtual environments** and **Get machine statistics for Azure environments** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Session Count | View the Session Count report. Read [Session Count Report](/v1/docs/user-sessions-count-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Session Activity | View the Session Activity report. Read [Session Activity Report](/v1/docs/user-sessions-activity-report) for details. Use the **Get user activity status** and **Get session statistics** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Logon Duration | View the Logon Duration report. Read [Logon Duration Report](/v1/docs/logon-duration-report) for details | Admin, Editor, Viewer, VDI and DaaS Admins |
| Protocol Trends | View the Protocol Trends report. Read [Protocol Trends Report](/v1/docs/protocol-trends-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Machine Trends | View the Machine Trends report. [Machine Trends Report](/v1/docs/computer-trends-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Machine Statistics | View the Machine Statistics report. Read [Machine Statistics Report](/v1/docs/computer-statistics-report) for details. Use the **Get machine statistics** API endpoint. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Host Trends | View the Host Trends report. Read [Host Trends Report](/v1/docs/host-trends-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Host Statistics | View the Host Statistics report. Read [Host Statistics Report](/v1/docs/host-statistics-report) for details. Use the **Get host metrics per folder** and **Get host counts** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Top Windows Errors | View the Top Windows Errors report. Read [Top Windows Errors Report](/v1/docs/top-windows-errors-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| NetScaler | View the NetScaler report. Read [NetScaler Report](/v1/docs/citrix-netscaler-adc-report) for details. Use the **Get NetScaler metrics** and **Get NetScaler metrics with time series** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Load Balancing | View the Load Balancing report. Read [NetScaler Load Balancing Report](/v1/docs/citrix-netscaler-load-balancing-report) for details. Use the **Get Load Balancer metrics** and **Get Load Balancer metrics with time series** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Gateway | View the Gateway report. Read [NetScaler Gateway Report](/v1/docs/citrix-netscaler-gateway-report) for details. Use the **Get Gateway metrics** and **Get Gateway metrics with time series** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Citrix License Usage | View the Citrix License Usage report. Read [Citrix License Usage Report](/v1/docs/citrix-license-usage-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| App Statistics | View the App Statistics report. Read [App Statistics Report](/v1/docs/application-statistics-report) for details. Use the **Get application statistics** API endpoint. | Admin, Editor, Viewer, VDI and DaaS Admins |
| App Usage Details | View the App Usage Details report. Read [App Usage Details Report](/v1/docs/application-usage-details-report) for details. Use the **Get usage details for an application** and **Get usage details for all applications** API endpoints. | Admin, Editor, Viewer, VDI and DaaS Admins |
| App Trends | View the App Trends report. Read [App Trends Report](/v1/docs/application-trends-report) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |
| Published Apps | View the Published App Usage Details report. Read [Published App Usage Details Report](/v1/docs/published-application-usage-details-report) | Admin, VDI and Daas Admins |
| Manage Personal Automated Reports | Create and manage personal automated reports (only viewable by the user that created it). | Admin, Editor, VDI and Daas Admins |
| Manage All Automated Reports | Create and edit all automated reports. | Admin, VDI and Daas Admins |
| Cost Savings Dashboard | View the Cost Savings dashboard. Read [Cost Saving Dashboard](/v1/docs/cost-saving-dashboard) for details. | Admin, Editor, Viewer, VDI and DaaS Admins |

## Enrich

| Permission | Description | Default Roles |
| --- | --- | --- |
| Manage Sites | Configure the Enrich plugin. Read [Configure Enrich Settings](https://support.controlup.com/docs/enrich-browser-extension#configure-enrich-settings) for details. | Admin |

## ControlUp for Apps

| Permission | Description | Default Roles |
| --- | --- | --- |
| Access ControlUp for Apps | View data from ControlUp for Apps. Read [ControlUp for Apps Overview](/v1/docs/controlup-for-apps-overview) for details. | Admin, Editor, Viewer |
| Configure ControlUp for Apps | Configure ControlUp for Apps settings. Read [Deploy ControlUp for Apps](/v1/docs/deploy-controlup-for-apps) for details. | Admin |

## Workflows

| Permission | Description | Default Roles |
| --- | --- | --- |
| View flows | View flow widgets, details, templates and integrations. Read [Workflows Overview and Features](https://support.controlup.com/v1/docs/workflows-overview-and-features) for details. | Admin, Editor, Viewer |
| Create new flows | Create new flows. Read [Create a Flow](https://support.controlup.com/v1/docs/create-workflows#create-flow) for details. | Admin |
| Edit existing flows | Edit existing flows. Read [Create a Flow](https://support.controlup.com/v1/docs/create-workflows#edit-your-flow) for details. | Admin, Editor |
| Delete flows | Delete flows. Read [Create a Flow](https://support.controlup.com/v1/docs/create-workflows#flows-tab) for details. | Admin |
| Enable/disable flows | Enable or disable flows. Read [Create a flow](https://support.controlup.com/v1/docs/create-workflows#flows-tab) for details. | Admin |
| Run workflow | Run existing flows. Read [Create a flow](https://support.controlup.com/v1/docs/create-workflows#flows-tab) for details. | Admin, Editor |
| View integrations | View the available integrations for workflows. Read [Workflow Integrations](https://support.controlup.com/v1/docs/create-flows-and-integrations) for details. | Admin, Editor, Viewer |
| Configure new integration connections | Configure new integrations. Read [Workflow Integrations](https://support.controlup.com/v1/docs/create-flows-and-integrations) for details. | Admin |
| Edit integration settings | Edit the settings of each integration. Read [Workflow Integrations](https://support.controlup.com/v1/docs/create-flows-and-integrations) for details. | Admin, Editor |
| Delete integration connections | Delete integrations. Read [Workflow Integrations](https://support.controlup.com/v1/docs/create-flows-and-integrations) for details. | Admin |
| Create API keys | Create API keys for flows. | Admin |
| Delete API keys | Delete API keys for flows. | Admin |
| View forms | View existing forms. | Admin, Editor, Viewer |
| Create new forms | Create new forms. See [Forms](/v1/docs/forms) for details. | Admin |
| Edit existing forms | Edit existing forms. | Admin, Editor |
| Delete forms | Delete existing forms. | Admin |
| View agents | Not currently used. |  |
| Create new agents | Not currently used. |  |
| Edit existing agents | Not currently used. |  |
| Delete agents | Not currently used. |  |
| View organization templates | View existing templates. | Admin, Editor, Viewer |
| Create new organization templates | Create new forms. See [Templates](/v1/docs/use-templates) for details. | Admin, Editor |
| Edit existing organization templates | Edit existing templates. | Admin, Editor |
| Delete organization templates | Delete existing templates. | Admin |

## Customer Success Hub

| Permission | Description | Default Roles |
| --- | --- | --- |
| ControlUp Usage and Analytics | Access the ControlUp Usage and Analytics section of the Customer Success Hub. This section contains analytics and statistics about you ControlUp organization including license consumption and user access. | Admin |
| My Success Hub | Access the My Success Hub section of the Customer Success Hub. This section contains onboarding plans, important notifications, and information about your Customer Support tickets and Customer Success meetings. | Admin |

## Events & Alert Management

| Permission | Description | Default Roles |
| --- | --- | --- |
| View Desktop Events | View Desktops event data on the ControlUp Events Dashboard. Read [ControlUp Events Dashboard](https://support.controlup.com/v1/docs/incidents-and-events) for details. | Admin, Editor, Viewer |
| View VDI Events | View VDI event data on the ControlUp Events Dashboard. Read [ControlUp Events Dashboard](https://support.controlup.com/v1/docs/incidents-and-events) for details. | Admin, Editor, Viewer |
| View Synthetic Monitoring Events | View Synthetic Monitoring event data on the ControlUp Events Dashboard. Read [ControlUp Events Dashboard](https://support.controlup.com/v1/docs/incidents-and-events) for details. | Admin, Editor, Viewer |
| Edit Desktop Events | Reorder, delete or reset event columns for Desktops events on the ControlUp Events Dashboard. Read [Edit event columns](https://support.controlup.com/v1/docs/incidents-and-events#edit-the-events-columns) for details. | Admin, Editor |
| Edit VDI Events | Reorder, delete or reset event columns for VDI events on the ControlUp Events Dashboard. Read [Edit event columns](https://support.controlup.com/v1/docs/incidents-and-events#edit-the-events-columns) for details. | Admin, Editor |
| Edit Synthetic Events | Reorder, delete or reset event columns for Synthetic Monitoring events on the ControlUp Events Dashboard. Read [Edit event columns](https://support.controlup.com/v1/docs/incidents-and-events#edit-the-events-columns) for details. | Admin, Editor |
| View Desktop Alerts Configuration | View configured Alert Rules for Desktops. Read [Devices: Static Threshold Alerts](/v1/docs/devices-static-threshold-alerts) and [Devices: Anomaly Detection Alerts](/v1/docs/anomaly-detection) for details. | Admin, Editor |
| Create, Edit & Delete Desktop Alerts Configuration | Create, edit, and delete Alert Rules for Desktops. Read [Devices: Static Threshold Alerts](/v1/docs/devices-static-threshold-alerts) and [Devices: Anomaly Detection Alerts](/v1/docs/anomaly-detection) for details. | Admin, Editor |

## Virtual Expert

| Permission | Description | Default Roles |
| --- | --- | --- |
| Manage Virtual Expert Mappings | Create, edit, and delete mappings for suggested actions in Virtual Expert. Read [Configure Virtual Expert](/v1/docs/virtual-expert) for details. | Admin, Editor |
| View Virtual Expert Mappings | View mappings for suggested actions in Virtual Expert. Read [Employee Experience Drilldown](/v1/docs/employee-experience-drilldown) for details. | Admin, Editor, Viewer |

## AI Assistant

| Permission | Description | Default Roles |
| --- | --- | --- |
| Enable AI Assistant | When selected, the [AI Assistant for IT Operations](/v1/docs/ai-assistant) chatbot is added to the top bar next to your personal settings. | Admin |

## Dashboards

| Permission | Description | Default Roles |
| --- | --- | --- |
| View Custom Dashboards | View your personal dashboards and shared dashboards (organizational and ControlUp dashboards) | Admin |
| Edit Custom Dashboards | Create and edit your personal dashboards | Admin |
| Edit Organizational Dashboards | Create and edit personal dashboards, edit organizational dashboards, share dashboards with your org, unshare dashboards, view and duplicate ControlUp dashboards | Admin, Editor |
