A role can be given Administrative permissions over the node (or sub-nodes) for which a role exists. This delegated administration allows different roles to have different permissions inside of the Admin Console.
An example of a role that can be created would be a Delegated Admin role. In this role the administrator can set up one or more Administrative Permissions that allow that user in the role to login to the Keeper Admin Console and perform administrative functions. For example, the delegated admin can be given permission to create teams, add users, create or edit roles, run reports and perform account transfers. These permissions can be limited to a single node or they can cascade or traverse down the tree structure to all the sub-nodes. In order to have the role applied to multiple nodes, simply select the + button after Administrative Permissions and add the node the role will manage.
Each node a role manages has its own set of permissions and those permissions can cascade down from that node for example, if the role was created in the top root level node and there were three other nodes created under the top, root level node. The Administrative Permission can be added as the top node, the privileges added, and Cascade Node Permissions selected. This would then give those permissions to all four nodes and members of that role.
To give Administrative Permissions to a Role, select the + button on the Role screen.
Select a Node and click OK.
Select the gear icon next to the node you added.
When Cascade Node Permissions is selected, the permissions will be applied to all sub-nodes of the parent node. It is important to note that Administrative Permissions cannot be added to a Role if one or more of its users are still have an "invited" status.
The ability to add, remove, or edit nodes.
The ability to add, remove, or edit users.
The ability to add, remove, or edit roles.
MSP-specific ability to manage licensing
The ability to add, remove, or add members to teams.
The ability to add, remove, or configure the Enterprise Bridge or SSO.
The ability to run and configure reports (Advanced Reporting & Alerts Module)
Perform Device Approvals
For SSO cloud users, the ability to approve devices
The ability to transfer a user's vault (if the user's Role is configured to allow this. See Account Transfer policy.
Cascade Node Permissions
If selected, the permissions apply to this node and all sub-nodes.
Both Administrative permissions and enforcements are configurable from within a role. Enforcements are rules or policies that apply to the end user's vault experience and security. Administrative Permissions grant rights to perform certain actions within the admin console (also known as delegated administration).
We recommend that only specific roles are given Administrative Permission, and the permission level should be based on the least amount of privilege required by that role.
For example, the default Keeper Administrator may have created a role called Users specifically to handle the policies that are desired for all the users that have been onboarded to the Keeper platform. If you intend for one of those users to be able to perform some of the administrative permissions it wouldn't make sense to configure the Users role with the additional entitlements for that one user as it would be applied to all the users and not congruent with a least privilege security model. So instead of editing the Users role to add additional administrative permissions, it would make the most sense to create a new role called Delegated Admin, grant the administrative permissions, and make the user a member of that role.