Updated on 2026-07-30 GMT+08:00

Role

Scenarios

A role is an identity type to which a set of permissions can be assigned. You can assign a role to a user to grant the user the permissions of that role. The bastion host system provides multiple default roles. You can also add custom roles.

Role Types

Table 1 Role types

Role Type

Role

Role Description

Role Restriction

Default system roles

DepartmentManager

This role is the department operation manager and manages the bastion host system. It has the permissions for user, resource, and policy management.

  • Only the admin user can edit the permissions of default system roles.
  • Default system roles cannot be deleted.

PolicyManager

This role is the user permission policy administrator. It manages host operation permissions. It has the permissions for configuration of the user management, resource management, and access policy management modules.

AuditManager

This role is the operation result audit administrator. It queries and manages system audit data. This role has the configuration permissions for real-time session, historical session, and system logs modules.

User

This role specifies common users and operators who can access the system. It has the permissions for operations for resources, such as host and application resources, and service ticket authorization management.

Custom role

-

You can customize the role name and permission scope as required.

  • Only the admin user can edit the permissions of custom roles.
  • Only the admin user can delete custom roles.

Notes and Constraints

Only the admin user has the permission to manage the Role module. This means only the admin user can create, edit, view, and delete roles.

Creating a Role

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose User > Role to go to the role list page.
  3. On the displayed page, click New in the upper right corner of the page. In the displayed New Role dialog box, complete required parameters

    Table 2 Parameters for creating a role

    Parameter

    Description

    Role

    Enter a name for the role.

    • The value of Role must be unique in a bastion host and cannot be changed after it is created.
    • The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.

    Managing Permission

    Specify whether to enable management permission for the role. It is disabled by default. The management permission allows the role to view data of the current department and its lower-level departments.

    • Enable: The role has management permissions and users with this role granted can view the data of their departments and lower-level departments. Users of this role can select a superior department when they add a resource or user. Only users with management permissions can grant ticket approval permission to a role. Otherwise, the approval permission will not take effect, even if it is enabled in 4.
    • Disable: The role has no management permissions.

    Role Manager Setting

    Configure whether only the role manager can create users of this role or change other users to this role. This function is disabled by default.

    • Enabled: You need to configure Role Manager. Only the user selected as the role manager can assign the current role to a user when creating or editing a user, as long as the selected user has permission to create or edit users.

      You can select one or more roles as role managers and set yourself as the manager of your own role.

    • Disabled: All users can select the current role when creating or editing a user, as long as they have permission to create or edit users.

    Policy Delivery Target

    Configure whether a policy can be applied to the current role. This function is enabled by default.

    • Enabled: When you associate users with an access control rule, command control rule, or database control rule, users of this role are selectable.
    • Disabled: When you associate users with an access control rule, command control rule, or database control rule, users of this role are not displayed and cannot be associated with the rule.

    The rules for the policy delivery target to take effect are as follows:

    • This configuration applies only when you select an associated user during policy creation or editing. It does not affect users already associated with the policy.
    • This configuration does not apply when you associate a user group with a policy.

    Remarks

    (Optional) Provide a brief description of the role. A maximum of 128 characters can be entered.

  4. Click Next to go to the role configuration window.

    Enable or disable the permission for each system module on the left. If the permission is enabled, you can select specific functions on the right of the corresponding system module. After the configuration, the role will have the permissions of the selected functions.

    Figure 1 Configuring the permissions for a new role

  5. Click OK. You can then view the created role in the role list.

Viewing or Modifying the Basic Information and Permissions of a Role

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose User > Role to go to the role list page.
  3. Query the target role.

    Enter a keyword in the search box and search for a role by name.

  4. In the Operation column of the target role, click the role name or click Manage to go to the role details page.
  5. View or edit the basic information about the role.

    • In the Basic Info area, view the detailed information about the role.
    • In the right pane of the Basic Info area, click Edit. In the displayed dialog box, modify the basic information. For details, see Table 2.

  6. View or edit the permission scope of the role.

    • In the Permissions area, view the system operation permissions of the role.
    • In the Permissions area, click Edit on the right to modify the permissions of the role.
    • Click Remove of a module to revoke permissions for the module of the role.

Restoring the Default Settings of a Default System Role

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose User > Role to go to the role list page.
  3. In the Operation column of the target role, click Restore Default.
  4. In the displayed dialog box, click OK.

Deleting a Custom Role

Only the admin user can delete custom roles. Default system roles cannot be deleted.

If a role is deleted, all users with this role will immediately lose the permissions of the role. Exercise caution when performing this operation.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose User > Role to go to the role list page.
  3. Delete any role you no longer need.

    • Deleting a role
      1. In the Operation column of the target role, click Delete.
      2. In the displayed dialog box, click OK.
    • Batch deleting roles
      1. In the role list, select all target roles.
      2. Click Delete in the lower left corner.
      3. In the displayed dialog box, click OK.