Comment on page
Overview of role-based Administrative Permissions
A Keeper role can be granted Administrative permissions over the node (or sub-nodes) for which a role exists. This delegated administration allows different roles to have different permissions inside of the Admin Console.
An example of a role that can be created would be a Delegated Admin role. In this role the administrator can set up one or more Administrative Permissions that allow that user in the role to login to the Keeper Admin Console and perform administrative functions. For example, the delegated admin can be given permission to create teams, add users, create or edit roles, run reports, approve devices and perform account transfers. These permissions can be limited to a single node or they can cascade or traverse down the tree structure to all the sub-nodes.
To create a privileged role with admin permissions, click on the + button in the Administrative Permissions sections.
Adding Administrative Permission to a Role
Each node a role manages has its own set of permissions and those permissions can cascade down from that node for example, if the role was created in the top root level node and there were three other nodes created under the top, root level node. The Administrative Permission can be added as the top node, the privileges added, and Cascade Node Permissions selected. This would then give those permissions to all four nodes and members of that role.
- 1.To give Administrative Permissions to a Role, select the + button on the Role screen.
- 2.Select a Node and click OK.
- 3.Set permissions by clicking on the gear icon next to the node you added.
Add Managed Node
Setting Administrative Permissions
When Cascade Node Permissions is selected, the permissions will be applied to all sub-nodes of the parent node. It is important to note that Administrative Permissions cannot be added to a Role if one or more of its users are still have an "invited" status.
A description of each permission is below.
Only administrators who are a currently a member of this role are able to select "Transfer Account". If needed, you can add yourself to the role or another administrator within the role can set this permission.
Both Administrative permissions and enforcements are configurable from within a role. Enforcements are rules or policies that apply to the end user's vault experience and security. Administrative Permissions grant rights to perform certain actions within the admin console (also known as delegated administration).
We recommend that only specific roles are given Administrative Permission, and the permission level should be based on the least amount of privilege required by that role.
For example, the default Keeper Administrator may have created a role called "All Users" specifically to handle the policies that are desired for all the users that have been onboarded to the Keeper platform. If you intend for one of those users to be able to perform some of the administrative permissions, create a new role called "Delegated Admin", grant the administrative permissions, and make the user a member of that role.