Role-based access control
Cisco Cloud Control uses role-based access control (RBAC) to manage what users can view and do across Cisco Cloud Control and supported integrated products. RBAC helps ensure that users see only the features, data, and actions allowed by their assigned permissions.
If you do not have permission to access a feature, Cisco Cloud Control either hides the option or displays an access denied message.
How RBAC controls access
These stages describe how Cisco Cloud Control controls access at the Cisco Cloud Control level and integrated product level.
-
Cisco Cloud Control retrieves user roles from the Cisco User Identity service.
-
Cisco Cloud Control includes those roles in the user access token.
-
Cisco Cloud Control uses the roles to control access to pages, menu items, data, and actions.
-
For integrated products, Cisco Cloud Control respects the permissions that a user has in the source product.
This source-product permission check provides more granular control over which assets and services are visible in Cisco Cloud Control.
Supported roles
Cisco Cloud Control supports these roles:
-
Tenant Full Admin: Can configure and manage all tenant-level settings.
-
Tenant Read-Only: Can view all tenant-level settings, but cannot change them.
-
Integration Admin: Can manage cross-product and third-party integrations in Cisco Cloud Control, but does not have platform administration rights.
These roles determine which features, views, and actions are available to each user.
-
By default, the Member role is configured for all Cisco Cloud Control users. This role allows users to view data across all products they have permissions for, but they cannot execute configurations.
-
Tenant Full Admin users can see all data within the Cisco Cloud Control workspace. However, they cannot access individual product dashboards (such as Meraki or Intersight) for which they do not have explicit product permissions.
-
The same user can be configured with both the Tenant Read-only Admin and Integration Admin roles.
RBAC-controlled areas
RBAC controls access to these areas in Cisco Cloud Control:
-
Pages and menu items
-
Administrative actions
-
Alert and inventory data
-
Topology
-
Actions tab
-
Product-specific access
These sections describe how RBAC controls access in each area.
Pages and menu items
Your role determines which pages and menu items you can access. Examples include Admin Console and Topology.
Administrative actions
Only users with the required administrative privileges can perform sensitive operations, such as exporting inventory data and deleting configurations.
Read-only users can view information but cannot perform editing or administrative actions.
Inventory and alert data
Visibility is strictly scoped to the specific product tenants a user can access within the active tenant group.
Topology access
Topology access is role-based. Depending on your role, you can have one of these topology access levels:
-
Full access to topology features, including adding, editing, and deleting scopes or sites.
-
View-only access to Topology, device details, and site information.
-
Filtered view-only access, showing only the sites, devices, and connections that your product and asset permissions allow. Objects you cannot access are hidden.
-
No topology access; Topology is hidden, and direct URL access is denied.
Actions tab access
Your role determines whether you can view and execute these tasks in the Actions page.
| Task | Tenant Full Admin | Member | Tenant Read-Only | Integration Admin |
|---|---|---|---|---|
|
View the Actions tab |
Yes: all actions across all integrated products |
Yes: only the products you can access through underlying RBAC |
Yes: all actions across all integrated products |
No |
|
Acknowledge, dismiss, or resolve an action |
Yes: gated by your permissions in the underlying controller This option is unavailable if you don’t have controller access. |
Yes: gated by your permissions in the underlying controller |
No |
No |
|
Run workflows |
Yes |
Yes: gated by your permissions in the underlying controller |
No |
No |
|
Assign an action |
Yes |
Yes: gated by your permissions in the underlying controller |
No |
No |
|
Act on correlated alerts |
Yes: blocked if you are missing permissions on any alert in the group |
Yes: blocked if you are missing permissions on any alert in the group |
No |
No |
|
Audit logging |
Yes: all actions are logged with user identity and timestamp |
Yes: all actions are logged with user identity and timestamp |
Yes: all actions are logged with user identity and timestamp |
No |
-
Actions on correlated alerts follow the weakest-link rule. If you lack permission on any single alert in a correlated group, the action is blocked for the entire group.
-
If you are a Tenant Read-Only user, you cannot run actions, even if you have member or administrator rights in an underlying product. To act on that product, go to the underlying product directly.
-
If you have both the Integration Admin role and Member role, you keep access to the Actions page. Your permissions come from the Member role and the underlying product permissions attached to it.
Product-specific access
You can access only the assets and services that your source-product permissions allow. Here are a couple example that illustrate this:
-
If you are an administrator in Intersight but do not have administrative access in Meraki, you can access Intersight assets through Cisco Cloud Control, but not Meraki assets.
-
The current selected tenant group contains three Meraki tenants, and you have access to two of these tenants. You will be only be able to view data for these two tenants.
This behavior helps maintain consistent access enforcement between Cisco Cloud Control and the integrated products it manages.
User role management for integrated products
Cisco Cloud Control unifies user management and role assignment for supported integrations. Administrators can manage user roles for integrated products, such as Nexus Dashboard, from Users in Cisco Cloud Control instead of switching to separate management consoles. This includes assigning and revoking Nexus Dashboard roles for Cisco Cloud Control users.