Add or edit a custom user role to grant custom app permissions and scope to TrendAI Vision One™ user accounts.
Permissions determine which TrendAI Vision One™ apps a user assigned the role can open, and which actions the user can perform in
each app.
If a predefined role already grants close to the access you need, duplicate the role and adjust its permissions
instead of building a role from scratch.
Procedure
- Go to .
- To add a new custom user role, click + Add role.The Create custom role window appears.
- On the General information tab, specify the role name, description, and control flag settings to determine whether
the role can be assigned to API keys, user accounts, or both.Granting Master Administrator in combination with other permissions can be risky. Be cautious granting Master Administrator to a custom user role with:
-
permission to configure user roles and the control flag allowing it to be assigned to user accounts
-
permission to configure accounts
As of October 27, 2025, the Master Administrator level permission cannot be assigned to API keys. API keys granted Master Administrator before that date retain their permission, but it is recommended that they be assigned a different role since Master Admin level API keys could be used to make user accounts changes. -
- On the Permissions tab, select permissions to grant to the role.Permissions are listed by app, so one role can grant a different level of access to each app.AccessDescriptionFull accessGrants every permission available for the app.Read-onlyGrants permission to view the app and its data, but not to change settings or perform actions.Partial accessApplied automatically when you select some, but not all, of the permissions available for the app.Some apps require selecting the Read-only or Full access permission before selecting other permissions.
- On the Management scope tab, configure the following:
-
Company scope: select a company scope that defines which managed customers this role can access, such as Full scope to grant access to all managed customers. To create or edit a company scope, go to .
-
Managed console scope: select a managed console scope that defines the platform capabilities and security functions this role can access, and the access level for each. To create or edit a managed console scope, go to .
-
- Click Save.
