Skip to Main Content
Status Future consideration
Product Area Right Click Tools
Categories Privileged Access
Created by Charlie Maurice
Created on Jun 3, 2026

Add scoping to RBAC in Privileged Access

At one point, it was possible to scope users/groups to specific OU's when setting up an admin in Privilege Manager. At some point, that was removed, and the AD and CM sync were set behind an enterprise license. It would be nice to see better RBAC/Scoping inside a product that controls admin access on machines.

For example, if you have someone managing Dept A, they should not be able to setup self-service rules, or pull codes for Dept B, and vice-versa. Right now, if you have access to setup self-service rules or pull codes, you have full carte blanche to the entire environment.

When this did work, when setting up an admin, I was able to select an OU as a scope for them. In self-service, it would only return machines that belonged to that OU. I unfortunately don't remember what happened in the agents tab because it was so long ago.

Anyways, please consider adding more fine grained controls of admins inside privilege manager. Thank you.

  • Attach files