Read-only role
Users with the `Read-Only` role can:
View any page or any setting in Security Cloud Control.
-
View all device configuration details including sensitive values in device configurations, such as certificates, PSKs, and credentials.
NoteNote: For ASA devices, we recommend enabling password encryption as a best practice. Password encryption helps prevent PSKs and credentials from being visible in clear text in the configuration.
-
Compare device configurations, view the change log, and see VPN mappings.
Search and filter the contents of any page.
View every warning regarding any setting or object on any page.
Generate, refresh, and revoke their own API tokens. Note that if a read-only user revokes their own token, they cannot recreate it.
Contact support through our interface and can export a change log.
Users with the `Read-Only` role cannot:
Create, update, configure, or delete anything on any page.
Onboard devices.
Step-through the tasks needed to create something like an object or a policy, but not be able to save it.
Create Security Cloud Control user records.
Change user role.
Attach or detach access rules to a policy.