Management Scope for Permissions
The following table maps global RBAC functionalities to their corresponding advanced scopes, outlining the permitted actions (Create, Edit, Delete, Read Only) for each. This enables fine-grained administrative control across network components and services when creating a custom role.
| Global Permissions - Category | Advanced Permissions - Functional Area and Features | User Permission |
|---|---|---|
| Wi-Fi | Venue > Wi-Fi | Permitted venue Wi-Fi operations include:
Note: The following actions are not allowed:
|
| Wi-Fi | Venue > Venue Management | Provides full access to create, modify, or remove venue information. |
| Wi-Fi | Venue > Property Management |
Provides full access to manage property-level data associated with a venue. Note: Grants
read-only access to the resident portal setting.
Note: Grants full
access to registration messaging templates.
|
| Wi-Fi | Venue > Property Management - Units | Provides full access to control creation and management of unit-level data within a venue. |
| Wi-Fi | Wi-Fi > Wi-Fi Networks | Provides full access to manage Wi-Fi networks.
|
| Wi-Fi | Wi-Fi > Access Points | Provides only Edit permission on AP configuration. Note: The user cannot
add or delete APs. Note: The user cannot
add, edit, or delete AP Groups. Note: The user cannot
change venue settings. |
| Wi-Fi | Clients > Wireless | Provides full access to manage Wi-Fi clients and guest passes. |
| Wi-Fi | Clients > Identity Management | Provides full access to manage identity and identity groups. |
| Wi-Fi | Network Control (Services) >
|
Provides full access to manage individual network control services. Note: DPSK
permissions do not imply DPSK Passphrases permissions; they are
managed independently.
Note: Each Network
Control service must be explicitly selected for access.
|
| Wi-Fi | Network Control (Profiles) >
|
Provides full access to manage individual network control policies and profiles. Note: The user cannot
activate or deactivate the Syslog Server profile on
venues.
Note: Scope mapping
is not available for SAML Identity Providers but is available
for Hotspot 2.0 Identity Providers.
Note: Each Network
Control profile or policy must be explicitly selected for
access.
|
| Wired | Venue > Switch | Manages Venue Switch settings.
|
| Wired | Wired > Switches | Based on the permission level assigned, the following operations
are permitted:
|
| Wired | Wired > Wired Network Profile | Provides full access for the profile lifecycle. Add, update, or remove Default VLAN setting. |
| Wired | Clients > Wired | Provides full access support. Note: Port edits are
not permitted under any permission level. |
| Wired | Network Control (Services) > Web Authority | Provides full access support. Enables configuration of web authentication policies and templates. |
| Wired | AI (AI Assurance, Business Insight, Reports) | Prepares wired reports. Note: Create, Edit, and
Delete permissions for AI Assurance are bundled together.
Selecting one automatically selects the other two
permissions. |
| Wired | Administration (Account Management) | Provides full access support to standard admin controls. |
| Gateways | RUCKUS Edge > Edge Management | Provides full access to manage RUCKUS Edge devices,
clusters, configurations, WAN gateway settings, service-level
configurations for gateways, and high-quality service policies. Note: Edge and RWG
device management is allowed only with venue-level permissions.
This means, users cannot manage or assign devices to venues they
do not have access to. Note: Each Network
Control service, policy, or profile must be explicitly selected
for access. |
| Gateways | Network Control (Policies) > HQoS | |
| Gateways | Network Control (Services) >
|
|
| Gateways | RUCKUS WAN Gateway > RWG | |
| AI | AI Assurance >
|
Provides access to monitor and manage the network for optimal
performance. Note: Create, Edit, and Delete permissions for AI Assurance are
bundled together. Selecting one at the global level
automatically enables the other two permissions in a
partially-enabled state. To fully enable them, configure each
individually in the Advanced Permissions
tab. Note: Users with Edit
privilege for AI Analytics can access and manage Intent Settings and
Incident Settings. Note: Changes to
Intent Settings and Incident Settings are applied at the tenant
level and impact all venues within the tenant, regardless of
whether the scope of the user’s assigned privilege group is set
to All
Venues or Specific
Venues. |
| AI | Business Insights >
|
Provides full access support to view and generate business
intelligence reports. Note: Create, Edit, and Delete permissions for
Business Insights are bundled together. Selecting one at the
global level automatically enables the other two permissions in
a partially-enabled state. To fully enable them, configure each
individually in the Advanced Permissions
tab. |
| Admin | Licensing | Provides full access to manage licenses. |
| Admin | Account Setup | Provides full access to manage account-level configurations. Note: Users with Edit
privilege can configure notification settings for each Incident
type. |
| Admin | Timeline | Provides full access to manage account activities, events, and admin logs. |
| Admin | Account Management | Provides full access to manage tenant administration, firmware, the app library, or modify specific entries in the Activities log. |
| MSP | MSP > MSP and Tech Partners Management | Provides full access to manage MSP and Tech Partners tenants and
entitlements. Note: You can add and
configure permissions for MSP roles for Tech Partners only. You
cannot add MSP roles for Customers. |
| MSP | MSP > Templates | Provides full access to manage configuration templates. |
| MSP | MSP > MSP Portal | Provides full access to manage MSP portal settings. Note: Create operation
is only supported during first-time login, and only Edit
operation thereafter. Note: Delete operation
is not supported for any of the MSP
functionalities. |