---
title: "Security Policy - View Only Role"
slug: "security-policy-view-only-role"
updated: 2025-08-26T14:31:34Z
published: 2025-08-26T14:31:34Z
canonical: "support.controlup.com/security-policy-view-only-role"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.controlup.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Policy - View Only Role

If you would like to grant user permissions to access the Real-Time Console and view systems and real-time performance data, you will first need to create a Security Role for that user or an AD Group. In our example, we use the name "View Only".  
 
**To create the "View Only" Security Role:**	  

 1. Open the **Security Policy** pane at the bottom of the Console.
 2. In the Home ribbon, click the **Manage Roles**	  button.
 3. Click  **Add New Role...![Add New Role button](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407141942673AddNewRole.png)**
 4. Under  **Role Name,**	  enter View Only. Click the  **Add Users/Groups**	  button to assign an Active Directory group to this security role.
 5. Click the **Search**	  button and select the AD group that includes the domain users for which you want to grant view-only permissions. Click **OK**	  to add the new role.  
![AD User Group with Search button](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407136542865ADUserGroup.png)
 6. The new role "View Only" is now assigned to the AD group "AD_CUViewOnlyRole". Click **OK**	  to finish the role configuration.  
![New Role Added as AD_CUViewOnlyRole](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407137208849NewRoleAdded.png)
 7. The View Only role is now added to the list along with the other default groups ControlUp Admins, Helpdesk, and Automation Admins. Click **OK**	  and wait until the changes are applied to the Security Policy Pane.  
![View Only role](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407146354065NewRoleVisible.png)
 8. In the Security Policy Pane, the new column "View Only" is added and you can start to assign permissions for this new role.  
![View Only Role Added](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407139060241ViewOnlyRoleAdded.png)

## Actions to Set Permissions
Set the permission <b style="color:green">Allow</b>	to the following actions:


### Perform organization-wide actions
**Recommended actions:**
Launch Controllers
![Launch Controllers icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407164699537LaunchControllers.png)

View Incidents
![View Incidents icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407165205137ViewIncidents.png)

View Events
![View Events icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407173433489ViewEvents.png)

View All Hypervisors
![View All Hypervisors icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407165766417ViewAllHypervisors.png)

Use Shared Credentials
![Use Shared Credentials icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407166060305UseSharedCredentials.png)

Connect to Data Source
![Connect To Data Source icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407166694545ConnectToDataSource.png)

**Optional actions to set the Allow permission:**

### Run Machines Actions
Connect to Windows Machine
![Connect To Windows Machine icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407155337489ConnectToWindowsMachine.png)

Connect to Linux Machine
![Connect To Linux Machine icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407155298833ConnectToLinuxMachine.png)

Event Viewer on Remote Computer**
![Event Viewer On Remote Machine icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407161712657EventViewerOnRemoteMachine.png)

Monitor File System**
![Monitor File System icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407154122001MonitorFileSystem.png)

### Installed Software
Display Installed Software**
![Display Installed Software icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407158000785DisplayInstalledSoftware.png)

Display Installed Updates**
![Display Installed Updates icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407157785105DisplayInstalledUpdates.png)

### Registry
Monitor Machine Registry**
![Monitor Machine Registry icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407159057041MonitorMachineRegistry.png)

### Services
Monitor Services**
![Monitor Services icon](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4407159338641MonitorServices.png)

**	  Optional: Other "View Only" settings that may require remote admin privileges.
