Permissions reference
The full catalogue of VMease RBAC permissions, grouped by category. Use these keys when building roles.
About permissions
VMease uses action-based RBAC. A permission is a dot-separated key in the form category.module.action (some modules are nested, e.g. dataprotection.backups.jobs.read). Roles are built from these keys and assigned to users or user groups.
- read — view/list access; create — add/modify (and implicitly grants read for that module); update — modify; delete — remove.
- * is an admin/all wildcard: module.* grants every action in a module; *.* is full platform super-admin; *.*.read grants read across every module.
- Granting a broader key satisfies the finer checks beneath it (a section-level or wildcard grant covers its module and action keys).
- Note: resourcemanagement.tags.* and accesscontrol.sso.* exist in the catalogue but are not yet surfaced in the role editor UI.
Global
Platform-wide wildcards. Grant these only to trusted administrator roles.
| Permission | Grants |
|---|---|
*.* | System - Super Admin |
Compute
Permissions in the Compute category.
| Permission | Grants |
|---|---|
compute.* | Compute - Full Access |
compute.appliances.* | Appliances - Admin |
compute.appliances.create | Appliances - Create |
compute.appliances.delete | Appliances - Delete |
compute.appliances.read | Appliances - View |
compute.appliances.update | Appliances - Update |
compute.create | Compute - Write All |
compute.delete | Compute - Delete All |
compute.disks.* | Disks - Admin |
compute.disks.create | Disks - Create |
compute.disks.delete | Disks - Delete |
compute.disks.read | Disks - View |
compute.disks.update | Disks - Update |
compute.isos.* | ISO Library - Admin |
compute.isos.create | ISO Library - Add |
compute.isos.delete | ISO Library - Delete |
compute.isos.read | ISO Library - View |
compute.isos.update | ISO Library - Update |
compute.media.* | Image Library - Full Access |
compute.media.create | Image Library - Write All |
compute.media.delete | Image Library - Delete All |
compute.media.read | Image Library - Read All |
compute.media.update | Image Library - Update All |
compute.monitoring.* | Compute Monitoring - Admin |
compute.monitoring.read | Compute Monitoring - View |
compute.read | Compute - Read All |
compute.storagepools.* | Storage Pools - Admin |
compute.storagepools.create | Storage Pools - Create |
compute.storagepools.delete | Storage Pools - Delete |
compute.storagepools.read | Storage Pools - View |
compute.storagepools.update | Storage Pools - Update |
compute.templates.* | Templates - Admin |
compute.templates.create | Templates - Create |
compute.templates.delete | Templates - Delete |
compute.templates.read | Templates - View |
compute.templates.update | Templates - Update |
compute.update | Compute - Update All |
compute.vms.* | VMs - Admin |
compute.vms.create | VMs - Create |
compute.vms.delete | VMs - Delete |
compute.vms.read | VMs - View |
compute.vms.update | VMs - Update |
Networking
Permissions in the Networking category.
| Permission | Grants |
|---|---|
networking.* | Network - Full Access |
networking.create | Networking - Write All |
networking.delete | Networking - Delete All |
networking.firewalls.* | Firewalls - Admin |
networking.firewalls.create | Firewalls - Create |
networking.firewalls.delete | Firewalls - Delete |
networking.firewalls.read | Firewalls - View |
networking.firewalls.update | Firewalls - Update |
networking.read | Networking - Read All |
networking.subnets.* | Subnets - Admin |
networking.subnets.create | Subnets - Create |
networking.subnets.delete | Subnets - Delete |
networking.subnets.read | Subnets - View |
networking.subnets.update | Subnets - Update |
networking.update | Networking - Update All |
networking.vlans.* | VLANs - Admin |
networking.vlans.create | VLANs - Create |
networking.vlans.delete | VLANs - Delete |
networking.vlans.read | VLANs - View |
networking.vlans.update | VLANs - Update |
networking.vnets.* | Virtual Networks - Admin |
networking.vnets.create | Virtual Networks - Create |
networking.vnets.delete | Virtual Networks - Delete |
networking.vnets.read | Virtual Networks - View |
networking.vnets.update | Virtual Networks - Update |
networking.vpn.* | VPN - Admin |
networking.vpn.create | VPN - Create |
networking.vpn.delete | VPN - Delete |
networking.vpn.read | VPN - View |
networking.vpn.update | VPN - Update |
Data Protection
Permissions in the Data Protection category.
| Permission | Grants |
|---|---|
dataprotection.* | Data Protection - Full Access |
dataprotection.backups.* | Backups - Full Access |
dataprotection.backups.create | Backups - Write All |
dataprotection.backups.delete | Backups - Delete All |
dataprotection.backups.jobs.* | Backup Jobs - Admin |
dataprotection.backups.jobs.create | Backup Jobs - Create |
dataprotection.backups.jobs.delete | Backup Jobs - Delete |
dataprotection.backups.jobs.read | Backup Jobs - View |
dataprotection.backups.jobs.update | Backup Jobs - Update |
dataprotection.backups.policies.* | Backup Policies - Admin |
dataprotection.backups.policies.create | Backup Policies - Create |
dataprotection.backups.policies.delete | Backup Policies - Delete |
dataprotection.backups.policies.read | Backup Policies - View |
dataprotection.backups.policies.update | Backup Policies - Update |
dataprotection.backups.read | Backups - Read All |
dataprotection.backups.restore.* | Restores - Admin |
dataprotection.backups.restore.create | Restores - Create |
dataprotection.backups.restore.delete | Restores - Delete |
dataprotection.backups.restore.read | Restores - View |
dataprotection.backups.restore.update | Restores - Update |
dataprotection.backups.update | Backups - Update All |
dataprotection.create | Data Protection - Write All |
dataprotection.delete | Data Protection - Delete All |
dataprotection.read | Data Protection - Read All |
dataprotection.update | Data Protection - Update All |
Resource Management
Permissions in the Resource Management category.
| Permission | Grants |
|---|---|
resourcemanagement.* | Resource Management - Full Access |
resourcemanagement.create | Resource Management - Write All |
resourcemanagement.delete | Resource Management - Delete All |
resourcemanagement.groups.* | Groups - Admin |
resourcemanagement.groups.create | Groups - Create |
resourcemanagement.groups.delete | Groups - Delete |
resourcemanagement.groups.read | Groups - View |
resourcemanagement.groups.update | Groups - Update |
resourcemanagement.read | Resource Management - Read All |
resourcemanagement.tags.* | Tags - Admin |
resourcemanagement.tags.create | Tags - Create |
resourcemanagement.tags.delete | Tags - Delete |
resourcemanagement.tags.read | Tags - View |
resourcemanagement.tags.update | Tags - Update |
resourcemanagement.update | Resource Management - Update All |
Organisation
Permissions in the Organisation category.
| Permission | Grants |
|---|---|
organisation.* | Organisation - Full Access |
organisation.billing.* | Billing - Admin |
organisation.billing.read | Billing - View |
organisation.create | Organisation - Write All |
organisation.delete | Organisation - Delete All |
organisation.logging.* | Logging - Admin |
organisation.logging.create | Logging - Create |
organisation.logging.delete | Logging - Delete |
organisation.logging.read | Logging - View |
organisation.logging.update | Logging - Update |
organisation.quotas.* | Quotas - Admin |
organisation.quotas.create | Quotas - Create |
organisation.quotas.delete | Quotas - Delete |
organisation.quotas.read | Quotas - View |
organisation.quotas.update | Quotas - Update |
organisation.read | Organisation - Read All |
organisation.update | Organisation - Update All |
Multi-tenancy
Permissions in the Multi-tenancy category.
| Permission | Grants |
|---|---|
multitenancy.* | Multi-tenancy - Full Access |
multitenancy.accounts.* | Tenants - Admin |
multitenancy.accounts.create | Tenants - Create |
multitenancy.accounts.delete | Tenants - Delete |
multitenancy.accounts.read | Tenants - View |
multitenancy.accounts.update | Tenants - Update |
multitenancy.applianceassignments.* | Appliance Assignments - Admin |
multitenancy.applianceassignments.create | Appliance Assignments - Create |
multitenancy.applianceassignments.delete | Appliance Assignments - Delete |
multitenancy.applianceassignments.read | Appliance Assignments - View |
multitenancy.applianceassignments.update | Appliance Assignments - Update |
multitenancy.billing.* | Billing - Admin |
multitenancy.billing.read | Billing - View |
multitenancy.childaccounts.* | Tenant Access |
multitenancy.create | Multi-tenancy - Write All |
multitenancy.delete | Multi-tenancy - Delete All |
multitenancy.isoassignments.* | ISO Assignments - Admin |
multitenancy.isoassignments.create | ISO Assignments - Create |
multitenancy.isoassignments.delete | ISO Assignments - Delete |
multitenancy.isoassignments.read | ISO Assignments - View |
multitenancy.isoassignments.update | ISO Assignments - Update |
multitenancy.networkassignments.* | Network Assignments - Admin |
multitenancy.networkassignments.create | Network Assignments - Create |
multitenancy.networkassignments.delete | Network Assignments - Delete |
multitenancy.networkassignments.read | Network Assignments - View |
multitenancy.networkassignments.update | Network Assignments - Update |
multitenancy.read | Multi-tenancy - Read All |
multitenancy.sharedresources.* | Shared Resources - Full Access |
multitenancy.sharedresources.create | Shared Resources - Write All |
multitenancy.sharedresources.delete | Shared Resources - Delete All |
multitenancy.sharedresources.read | Shared Resources - Read All |
multitenancy.sharedresources.update | Shared Resources - Update All |
multitenancy.templateassignments.* | Template Assignments - Admin |
multitenancy.templateassignments.create | Template Assignments - Create |
multitenancy.templateassignments.delete | Template Assignments - Delete |
multitenancy.templateassignments.read | Template Assignments - View |
multitenancy.templateassignments.update | Template Assignments - Update |
multitenancy.update | Multi-tenancy - Update All |
Access Control
Permissions in the Access Control category.
| Permission | Grants |
|---|---|
accesscontrol.* | Access Control - Full Access |
accesscontrol.create | Access Control - Write All |
accesscontrol.delete | Access Control - Delete All |
accesscontrol.read | Access Control - Read All |
accesscontrol.roles.* | Roles - Admin |
accesscontrol.roles.create | Roles - Create |
accesscontrol.roles.delete | Roles - Delete |
accesscontrol.roles.read | Roles - View |
accesscontrol.roles.update | Roles - Update |
accesscontrol.sso.* | SSO - Admin |
accesscontrol.sso.create | SSO - Create |
accesscontrol.sso.delete | SSO - Delete |
accesscontrol.sso.read | SSO - View |
accesscontrol.sso.update | SSO - Update |
accesscontrol.update | Access Control - Update All |
accesscontrol.usergroups.* | User Groups - Admin |
accesscontrol.usergroups.create | User Groups - Create |
accesscontrol.usergroups.delete | User Groups - Delete |
accesscontrol.usergroups.read | User Groups - View |
accesscontrol.usergroups.update | User Groups - Update |
accesscontrol.users.* | Users - Admin |
accesscontrol.users.create | Users - Create |
accesscontrol.users.delete | Users - Delete |
accesscontrol.users.read | Users - View |
accesscontrol.users.update | Users - Update |
Platform
Permissions in the Platform category.
| Permission | Grants |
|---|---|
platform.* | Platform - Full Access |
platform.alerts.* | Alerts - Admin |
platform.alerts.create | Alerts - Create |
platform.alerts.read | Alerts - View |
platform.alerts.update | Alerts - Update |
platform.auditlog.* | Audit Log - Admin |
platform.auditlog.read | Audit Log - View |
platform.clusters.managed.* | Cluster - Admin |
platform.clusters.managed.create | Cluster - Create |
platform.clusters.managed.delete | Cluster - Delete |
platform.clusters.managed.read | Cluster - View |
platform.clusters.managed.update | Cluster - Update |
platform.create | Platform - Write All |
platform.delete | Platform - Delete All |
platform.globalvms.read | Global VMs - View |
platform.globalvms.update | Global VMs - Migrate |
platform.importvms.* | Import VMs - Admin |
platform.importvms.create | Import VMs - Create |
platform.importvms.delete | Import VMs - Delete |
platform.importvms.read | Import VMs - View |
platform.importvms.update | Import VMs - Update |
platform.read | Platform - Read All |
platform.syslogs.* | Syslog - Admin |
platform.syslogs.create | Syslog - Create |
platform.syslogs.delete | Syslog - Delete |
platform.syslogs.read | Syslog - View |
platform.syslogs.update | Syslog - Update |
platform.update | Platform - Update All |
Task Manager
Permissions in the Task Manager category.
| Permission | Grants |
|---|---|
taskmanager.* | Task Manager - Full Access |
Ready to rethink private cloud?
Lower costs. Simplify operations. Deliver more.