Cisco Cloud Control Role-Based Access Control

 
Updated July 30, 2026
PDF
Is this helpful? Feedback

Role-based access control

Cisco Cloud Control uses role-based access control (RBAC) to manage what users can view and do across Cisco Cloud Control and supported integrated products. RBAC helps ensure that users see only the features, data, and actions allowed by their assigned permissions.

If you do not have permission to access a feature, Cisco Cloud Control either hides the option or displays an access denied message.

How RBAC controls access

These stages describe how Cisco Cloud Control controls access at the Cisco Cloud Control level and integrated product level.

  1. Cisco Cloud Control retrieves user roles from the Cisco User Identity service.

  2. Cisco Cloud Control includes those roles in the user access token.

  3. Cisco Cloud Control uses the roles to control access to pages, menu items, data, and actions.

  4. For integrated products, Cisco Cloud Control respects the permissions that a user has in the source product.

    This source-product permission check provides more granular control over which assets and services are visible in Cisco Cloud Control.

Supported roles

Cisco Cloud Control supports these roles:

  • Tenant Full Admin: Can configure and manage all tenant-level settings.

  • Tenant Read-Only: Can view all tenant-level settings, but cannot change them.

  • Integration Admin: Can manage cross-product and third-party integrations in Cisco Cloud Control, but does not have platform administration rights.

These roles determine which features, views, and actions are available to each user.

RBAC-controlled areas

RBAC controls access to these areas in Cisco Cloud Control:

  • Pages and menu items

  • Administrative actions

  • Topology features

  • Product-specific assets and services

These sections describe how RBAC controls access in each area.

Pages and menu items

Your role determines which pages and menu items you can access. Examples include Admin Console and Topology.

Administrative actions

Only users with the required administrative privileges can perform sensitive operations, such as exporting inventory data and deleting configurations.

Read-only users can view information but cannot perform editing or administrative actions.

Topology access

Topology access is role-based. Depending on your role, you can have one of these topology access levels:

  • Full access to topology features, including adding, editing, and deleting scopes or sites.

  • View-only access to Topology, device details, and site information.

  • Filtered view-only access, showing only the sites, devices, and connections that your product and asset permissions allow. Objects you cannot access are hidden.

  • No topology access; Topology is hidden, and direct URL access is denied.

Product-specific access

Cisco Cloud Control integrates with product-specific RBAC for these products:

  • Cisco Intersight

  • Firewall

  • Nexus Dashboard

You can access only the assets and services that your source-product permissions allow. For example, if you are an administrator in Cisco Intersight but do not have administrative access in Meraki, you can access Cisco Intersight assets through Cisco Cloud Control, but not Meraki assets. This behavior helps maintain consistent access enforcement between Cisco Cloud Control and the integrated products it manages.

User role management for integrated products

Cisco Cloud Control unifies user management and role assignment for supported integrations. Administrators can manage user roles for integrated products, such as Nexus Dashboard, from Users in Cisco Cloud Control instead of switching to separate management consoles. This includes assigning and revoking Nexus Dashboard roles for Cisco Cloud Control users.