Skip to main content
Version: 10.3

Manage Control Tower roles and permissions

In Control Tower, the Role Management page lists all roles available for the application users and allows managing associated permissions.

Assign permissions

The list of roles on the Role Management page is based on that of the wf-control-tower client in Keycloak. To assign permissions to the roles, follow the steps below:

  1. Go to System Settings > Role Management and click a role.

  2. In the Select Role Permissions section, select the permission checkboxes required for the role.

  3. Click Save to save the changes.

Explore default role permissions

Permissions/RolesAdministratorDeveloperOperator
View Tasks
Task Designer
Task Advanced Options
View Results
Generate snapshot
Task/Business Process Actions
View Business Processes
Import/Export
View Campaigns
Manage Campaigns
Manage BEP Resources
Schedules
Manage Templates
Manage Bot Configurations
Manage Rules
Manage Data Stores
View Data Stores
Manage Workers
Filter Management
Manage Data Sources
Manage Bot Sources
Manage Answer Types
Manage Operations
Manage Control Tower Permissions
Restricted Manage Control Tower Permissions
Activity Log
View Secrets Vault Aliases
Manage Secrets Vault Aliases
View Secrets Vault Entries
Manage E-mails
Configure Database and S3 Data Management
Run Data Management Configurations
Erase AI Agent Datastores
Delete AI Agent Variations
Advanced Package Import
Process Deep Copy
Bot Task Monitoring Access
Manage AutoML Settings
View AI Agents
Manage models
Manage solution catalog
Analytics Read-only
Edit Dashboards
Edit Charts, Datasets & Queries
Import Dashboards
Dashboard AI Insights
AI Chart Generator
Alerts and Reports

Study permission descriptions

View Tasks

The permission allows you to view all created Manual Tasks (MT). To access the task list, go to the main Control Tower menu and select Manual Tasks > View All Tasks.

Location:

  • Business Processes

Relative paths:

  • /tasks
  • /task/edit/{UUID}
  • /task/new

Task Designer

The permission allows you to view, edit, and create design Manual Tasks and Business Processes (BP).

Location:

  • Business Processes

Relative paths:

  • /task/...
  • /business-process/...
  • /question/...
  • /questions

Task Advanced Options

The permission allows you to modify the advanced options of a Manual Task.

View Results

The permission allows you to view MT or BP run results:

Location:

  • Manual Tasks
  • Business Processes

Relative paths:

  • task/edit/{uuid}?actTab=RESULTS/...
  • business-process/edit/{uuid}?actTab=RESULTS/...

Generate snapshot

The permission allows you to generate snapshots for a non-draft BP instance.

Task/Business Process Actions

The permission allows you to do the following:

  • Copy, pause, stop, resume, delete tasks and BPs using the Actions menu

  • Access and manage BEP Workforces

Location:

  • Manual Tasks
  • Business Processes
  • BEP Workforces

View Business Processes

The permission allows you to view all created Business Processes. For that, open the main Control Tower menu and select Business Processes > View All.

Location: Business Processes

Relative path: /business-processes

Import/Export

The permission allows you to import and export BP and task runs, Operations, packages, templates, and so on. Without the permission, users cannot see the import and export functionality on Control Tower pages and view the Packages tabs for Manual Tasks or BPs.

Location: All pages

Relative paths:

  • /templates
  • /questions
  • /rules
  • /rules-templates
  • /operations

View Campaigns

The permission allows you to view Campaigns.

Manage Campaigns

The permission allows you to manage Campaigns.

Manage BEP resources

The permission allows you to access the user interface for managing resources of the Bot Execution Platform (BEP) from Control Tower. In the interface, you can do the following:

  • Adjust the BEP worker resource requirements when the default values in worker*.yml do not satisfy the workload scenario.

  • Change the count of worker pool apps when the Worker Management Service (WMS) decisions on the worker pool orchestration are not optimal to maintain proper performance or satisfy the Service Level Agreement requirements.

Location: System settings

Schedules

The permission allows you to start Manual Tasks and BPs according to a schedule.

Location: Advanced

Relative path: /schedules

Manage Templates

The permission allows you to create, edit, copy, and delete Templates. Templates enable reusing objects within the Work.AI platform. Manual Tasks, BPs, and rules are based on Templates.

Location: Advanced

Relative path: /templates

Manage Bot Configurations

The permission allows you to create, edit, copy, and delete Bot Configs (Bot Tasks).

Location: Advanced

Relative path: /bot-configs

Manage Rules

The permission allows you to create, edit, delete, and copy rules and rule templates.

Location: Advanced

Relative paths:

  • /rules
  • /rules-templates

Manage Data Stores

The permission allows you to create, edit, delete, and export Data Stores, Field Schemes, and training sets.

The Data Stores module is a web interface for managing DB tables. You can use Data Stores to keep lookup tables for multi-value Answer options, to save BP results, and make queries from Bot Configs and Rules.

Location:

  • Business Processes
  • System Settings

Relative paths:

  • /data-stores
  • /field-schemes

View Data Stores

The permission allows you only to access, view, and download Data Stores. However, you cannot delete or update them via Control Tower or API.

Location:

  • Business Processes
  • System Settings

Relative paths:

  • /data-stores

Manage Workers

The permission allows you to view and manage human-in-the-loop workers.

Location: deprecated starting from 10.3.

Filter Management

The permission allows you to access the Filters page under the System Settings category, where you can create and manage filters to let specific user groups access specific Control Tower items or restrict them from access.

Location: System Settings

Manage Data Sources

Data Source is a mechanism that provides input data and configuration for your BPs and tasks. This input format is best suited for those Operations where data resides on an external source, such as SFTP Server.

Location: System Settings

Relative path: /data-sources

Manage Bot Sources

The permission allows you to manage Bot Sources.

Manage Answer Types

The Answer Types screen allows you to create and manage Answer Types within Work.AI. Answer Types are used when setting up ETL Bots or creating Field Schemes.

Location: System Settings

Relative path: /answer-types

Manage Operations

Operations serve as the basis for both tasks and BPs. They describe the workflow of a particular Business Process, which makes it possible to use them as templates to create Manual or Bot Tasks.

Location: System Settings

Relative paths:

  • /operations

Manage Control Tower Permissions

The permission allows you to manage all permissions for all user roles in Control Tower.

note

The permission does not allow you to edit user emails.

Location: System Settings

Restricted Manage Control Tower Permissions

The option allows you to manage CT permissions for all roles, except for the ones you have as a grantee of access rights.

Location: System Settings

Activity Log

The permission allows you to use the Activity Log module.

Location: System Settings

Relative path: /activity-log

View Secrets Vault Aliases

The permission allows you to view aliases in Secrets Vault and use them in Business Processes.

Location: System Settings

Relative path: /secrets-vault

Manage Secrets Vault Aliases

The permission allows you to view aliases, create, update, and delete records in Secrets Vault.

Location: System Settings

Relative path: /secrets-vault

View Secrets Vault Entries

This permission is available with the Manage Secrets Vault Aliases permission only. It lets you view all entries in Secrets Vault if no filters are assigned to a user.

Location: System Settings

Relative path: /secrets-vault

Manage E-mails

The permission allows you to edit user emails while creating or editing a user profile.

Location: System Settings

Relative path: /users

Configure Database and S3 Data Management

In addition to viewing and executing data management configurations, the permission allows creating, updating, and deleting them. By default, the permission is enabled only for the Administrator role.

Location: Advanced

Relative path: /data-management

Run Data Management Configurations

The permission allows executing data management configurations and viewing their list together with the status and execution information. By default, the permission is enabled for the Developer and Administrator roles.

Location: Advanced

Relative path: /data-management

Erase AI Agent Datastores

The permission allows you to apply the drop-data-stores operation in Maven and call the associated API endpoint to delete the entire AI Agent Data Model. The dropping of the whole Data Model is dangerous and is recommended for use only in development environments. For details, read Manage Data Model with Liquibase.

By default, the permission is disabled for all roles.

Delete AI Agent Variations

The permission lets you delete AI Agent variations via the Control Tower user interface or dedicated API endpoints. For more information, refer to Manage AI Agent Variations.

Advanced Package Import

The permission allows you to overwrite process versions with significant differences (steps added, deleted, or substituted). See Migrate Business Processes and Manual Tasks.

Location:

  • Manual Tasks
  • Business Processes

Relative paths:

  • /business-processes
  • /tasks

Process Deep Copy

The Deep Copy option creates a completely unlinked process instance where all steps are separated from the ones in the source BP. See Copy Business Process.

Location: Business Processes

Bot Task Monitoring Access

The permission allows you to access and monitor the following:

  • Bot Tasks in execution, grouped by Bot Sources
  • Records in execution and submitted but not started records
  • Thread dumps for Bot Tasks filtered by process UUID
  • Bot Source metrics, such as active record threads, record queue size, executed record total

Location: REST API

Relative paths:

  • /api/v1/monitoring/bots/sources
  • /api/v1/monitoring/bots/sources/{source-name}
  • /api/v1/monitoring/bots/thread-dumps
  • /api/v1/monitoring/bots/thread-dumps?businessProcessUuid={bp-uuid}

Manage AutoML Settings

The permission allows you to view the Configure AutoML tab and configuration settings for Manual Task automation.

Location: deprecated starting from 10.2.9.

View AI Agents

The permission allows you to view AI Agents.

Location: AI Agents

Manage models

The permission allows you to view the AutoML menu and interact with its items to manage models, pipelines, experiments, tests, and datasets.

Location: AutoML

Manage solution catalog

The permission gives you access to the Solution catalog from where you can install and configure AI Agents. When the permission is enabled, you can see the Solution catalog button in the Control Tower UI.

By default, the permission is enabled for the Admin and Developer roles.

Location: AI Agents

Analytics Read-only

The permission enables you to view Superset-based dashboards and related data, subject to any access-restricting filters. However, users with only this permission cannot create or modify dashboards and their components.

By default, the permission is enabled for all roles: Administrator, Developer, and Operator.

Location: Analytics

Edit Dashboards

The permission allows you to create and modify Superset-based dashboards, but not charts, datasets, or queries.

By default, the permission is enabled for the Developer and Administrator roles.

Location: Analytics

Edit Charts, Datasets & Queries

The permission allows you to create and modify components for Superset-based dashboards, such as charts, datasets, and queries.

By default, the permission is enabled for the Developer and Administrator roles.

Location: Analytics

Import Dashboards

The permission allows you to import Superset-based dashboards as well as their components.

By default, the permission is enabled for the Administrator role only.

Location: Analytics

Dashboard AI Insights

The permission enables you to switch on or off the AI Insights capability for WorkFusion analytics dashboards. If the permission is selected, the AI Insights button appears on dashboard pages in both Control Tower and Workspace. As you click it, Artificial Intelligence (AI) generates a report based on the precofigured chart metrics.

By default, the permission is enabled for all roles: Administrator, Developer, and Operator.

Location: Analytics

AI Chart Generator

The permission allows you to create charts using natural language prompts. You input a query or describe the data you want visualized, and Gen AI automatically generates a chart for you.

By default, the permission is enabled for the Developer and Administrator roles.

Location: Analytics

Alerts and Reports

The permission allows you to view, configure, and receive alerts and reports based on the data from Superset-based analytics.

By default, the permission is enabled for the Administrator role only.

Location: Analytics

Mind permission restrictions

When a user has a role without appropriate permissions, the following restrictions can be applied in the user interface:

  • Main menu items are not displayed

    • Restricted permissions

    • All permissions

  • Action buttons or links are not displayed

    • Restricted permissions

    • All permissions

  • Access Restricted message when trying to open a direct URL

Explore known issues

It is impossible to delete a role assigned only to a group. No messages appear after the Delete Confirmation operation.