Default user roles and their permissions

Absolute includes the following default user roles:

  • System Administrators are the only users in Absolute that have all permissions, including the ability to configure authentication settings, and create custom roles and assign their permissions. As a result, the user assigned to this role has a high degree of power.

    By default, the first user of your Absolute account is assigned the System Administrator role.

    This role has access to all devices in an account.

  • Security Administrators exist in those organizations that choose to designate certain Administrators as Security Administrators to manage the device and data security of assets. This user role has more access rights than Administrators.

    Security Administrators are authorized to submit Freeze, File Delete, and Wipe actions. Security Administrators use the Secure Endpoint Console to track and manage devices, both within the organization's local area network and outside of it.

    This role has access to all devices in an account.

  • Administrator + Unenroll Device users have the same permissions as an Administrator, but with the added permission to unenroll devices from your Absolute account.

    This role has access to all devices in an account.

  • Administrators manage their organization's devices and IT assets, and report device loss or theft. Administrators also create and manage various system communications, such as end user messaging, system notifications, and alerts and suspicious alert events.

    This role has access to all devices in an account.

  • Security Power Users exist in those organizations that choose to designate certain Powers Users as Security Power Users to manage the device and data security of assets. This user role has more access rights than Power Users.

    Security Power Users are authorized to submit Freeze, File Delete, and Wipe actions for devices in their assigned Device Group. Security Power Users use the Secure Endpoint Console to track and manage devices within the organization's local area network.

    This role is typically granted access to the devices in one or more device groups, but they can also be granted access to all devices.

  • Power User + Unenroll Device users have the same permissions as a Power User, but with the added permission to unenroll devices from your Absolute account.

    This role is typically granted access to the devices in one or more device groups, but they can also be granted access to all devices.

  • Power Users have access rights to most features excluding security features. Administrators can restrict Power Users permissions to specific devices or device groups.

    This role is typically granted access to the devices in one or more device groups, but they can also be granted access to all devices.

  • Guest Users have limited access to information and reports. These users can't submit device actions, but they can report devices missing or stolen. Guest Users can only browse the Investigation Reports that they've created.

    This role is typically granted access to the devices in one or more device groups, but they can also be granted access to all devices.

Permissions by feature and default user role

Depending on the Absolute product licenses associated with your account, some features may not be available.

Permissions for the various features in the Secure Endpoint Console depend on your user role:

Legend
P The role is granted the permissions that are required to perform the action
O The role is not granted the permissions that are required to perform the action
Features and permissions Security Administrator Administrator Security Power User Power User Guest User

System Administrators are granted all permissions.

Permissions for Security Power Users, Power Users, and Guest Users apply to devices in the user's assigned device groups only. If a user is assigned to all devices in your account, permissions apply to all devices.

Dashboard
View available inventory-related dashboard widgets P P P P P
View available security-related dashboard widgets P P P O O
Use AI Assistant P P O O O
Devices
View and manage active devices on the Devices page P P P P P
View and manage missing devices on the Missing Devices page P P P P P
View the location of devices in map view P P P P O
View device usage P P P P P
Create and manage device groups and folders P P P P O
Create and manage permission groups P P O O O
Applications
View installed applications on the Applications page P P P P P
Reports
View and export all predefined reports P P P1 P1 P2
Create, export, and share own reports P P P P P
View reports shared by other users P P P1 P1 P2
View Device Freeze Status report P O P O O
Create Device Analytics reports P P P P P
Configure weekly time ranges in Web Usage reports P P O O O
Manage websites included in Web Usage chart P P P P View only
Policies
View, create, and manage policy groups P P O O O
Assign licenses to policy groups P P O O O
Configure and activate policies P P O O O
Resilience: view policy configuration of third party applications P P O O O
Rules: create and manage rules and geofences P P View only View only View only
Rules: create and manage Offline Freeze rules P O P O O
Create, manage, and publish EDD Rules P P O O O
Custom Data: create and manage the Custom Data policy P P View only View only View only
Remediation
Reach Script: run and cancel scripts P P P O O
Reach Script: edit temporary script location P View only View only O O
Reach Script: manage scripts (upload and save to library) P O O O O
Device Actions
Unenroll P

P

[Administrator + Unenroll Device role only]

P

P

[Power User + Unenroll Device role only]

O
Perform EDD scan P P O O O
Freeze and Remove freeze P O P O O
Delete file P O P O O
Send message P P P P O
Manage supervisor password3 O O O O O
Report missing or stolen P P P P P
Report found P P P P P
Wipe P O P O O
Run playbooks P P O O O
Investigations
View theft reports P P P P P
View contacts P P P P P
History
Events: view and export recent events P P O O O
Action Requests: view recent Unenroll actions P

P

[Administrator + Unenroll Device role only]

P

P

[Power User + Unenroll Device role only]

O
Action Requests: view and cancel recent Script actions P P P O O
Action Requests: view and cancel recent Delete File actions P P P O O
Action Requests: view and cancel recent Send Message actions P P P P O
Action Requests: view and cancel recent Wipe actions P O P O O
Actions: view recent Unenroll actions by device P

P

[Administrator + Unenroll Device role only]

P

P

[Power User + Unenroll Device role only]

O
Actions: view recent Script actions by device P P P O O
Actions: view recent Delete File actions by device P P P O O
Actions: view recent Send Message actions by device P P P P O
Actions: view recent Wipe actions by device P O P O O
Settings
Account settings P View only View only O O
Accept Service Agreement P P View only View only View only
Agent management > Assign agent versions P P O O O
Agent management > Install agent (Windows and Mac) P P O O O
API management P P P P P

Authentication settings (SSO, SCIM integration, and 2FA)3

View status only View status only View status only View status only View status only
Custom fields > View and Edit Device Fields P P P P View only
Custom fields > Manage Device Fields P P O O O
Contact list P View only View only View only View only
License management P P O O O
Messages: manage Freeze message templates P View only P View only O
Messages: manage End User Messaging message templates P P P P View only
SIEM integration: configure events3 O O O O O
SIEM integration: view configured events P P P P P
Script library P O O O O
User management: view users and roles P P P P O
User management: create and manage user profiles for other users

P

[All roles]

P

[All roles except Security Administrator]

P

[All roles except Administrator and Security Administrator]

P

[Guest Users only]

O
User management: assign users to roles

P

[All roles]

P

[All roles except Security Administrator]

P

[All roles except Administrator and Security Administrator]

P

[Guest Users only]

O
User management: create and manage custom roles3 O O O O O
User management: configure Dual Approval Settings P O O O O
Utilities: download tools P P P P P
Vulnerabilities: view and manage vulnerabilities P P O O O
Workflows: view and manage workflows P View only View only O O
Workflows: run workflows P O P O O

1 Does not apply to reports in the Data Visibility report category or the Web Subscriptions report

2 Does not apply to reports in the Data Visibility report category, or any of the following reports: Upcoming Offline Device Freeze, Device Freeze Status, Event History, and Web Subscriptions

3 Only System Administrators are granted this permission.