Manage Access Profile Creation Permissions

How to delegate Access Profile creation to specific Operators and Groups.

Overview

By default, only Administrators can create Access Profiles in Lifecycle Management. With Access Controls enabled, Administrators can grant Creator permissions to specific Operators and Groups, allowing them to create new profiles. Users who create a profile automatically become its Owner and can edit that profile, but cannot modify profiles created by others. Administrators always retain full access to all profiles.

Users must have the Operator role to use Creator permissions — non-Operator roles (Access Reviewer, Watcher, etc.) cannot create Access Profiles even with explicit permission grants.

circle-info

Early Access Feature: This feature requires enablement by Veza support. Contact your Veza support team to enable Access Controls for your tenant.

Before you start

  • You have the Administrator role on the root team

  • Access Controls are enabled on your tenant (contact Veza support)

  • The users receiving permissions have the Operator role assigned

Grant Access Profile creation permissions

To assign Access Profile creation permissions to users or groups:

  1. Navigate to Lifecycle Management in the navigation sidebar.

  2. Click Settings in the Lifecycle Management sidebar.

  3. On the Settings page, locate the Access Profile Types section.

  4. Click Manage Access Profile Creation Permissions.

    The Manage Permissions modal opens, showing currently assigned users and groups.

  5. Select the Type of principal to add:

    • User: Assign permissions to individual Veza users

    • Group: Assign permissions to a Veza Group (all members receive permissions)

  6. Select the user or group from the dropdown menu.

    The dropdown shows only users or groups that don't already have permissions assigned. The permission is assigned automatically when you make a selection.

  7. Repeat steps 5-6 to assign permissions to additional users or groups.

  8. When finished, click outside the modal or press ESC to close.

Result: Users and groups with Creator permissions can now create new Access Profiles from the Lifecycle Management > Access Profiles page.

Verify permissions

To confirm that permissions were assigned correctly:

  1. In the Manage Permissions modal, review the list of assigned users and groups.

    Each row shows:

    • Principal name (user or group)

    • Principal type (User or Group)

    • Permission set name ("creator")

  2. Assigned users should now see the Create Access Profile button on the Access Profiles page.

  3. Users without permissions will not see the Create Access Profile button.

Remove Access Profile creation permissions

To revoke Access Profile creation permissions:

  1. Navigate to Lifecycle Management > Settings.

  2. Click Manage Access Profile Creation Permissions.

  3. In the permissions table, locate the user or group to remove.

  4. Click the delete (trash can) icon next to the user or group.

  5. Confirm the deletion when prompted.

Result: The user or group can no longer create new Access Profiles. They retain read-only access to view existing profiles.

circle-exclamation

See also

Last updated

Was this helpful?