Domain-Based and Organization-Based Roles

Domain-Based and Organization-Based Roles

Overview

This platform uses a role-based access control (RBAC) system to manage what actions users can perform. Roles are divided into two main categories: Domain-Based Roles and Organization-Based Roles. Each role provides a specific set of permissions that determine whether a user can view (read), modify (edit), or remove (delete) settings across various features such as DNS, caching, WAF, traffic analytics, subscriptions, and billing.

Domain-Based Roles

Provide access only to specific domains or services (such as DNS, CDN, or WAF).
  1. No access to organization-wide settings
  2. Cannot view or modify billing
  3. Cannot manage users

1. Domain Admin

Access AreaPermissions
Attack statisticsRead
Cloud iconRead, Edit
DDoS settingsRead, Edit, Delete
DNS analyticsRead
DNS recordsRead, Edit, Delete
Domain dashboardRead
Error analyticsRead
Firewall rulesRead, Edit, Delete
General settings (captcha, load balancer, redirect)Read, Edit
General settings menuRead, Edit, Delete
L4 firewall / proxy / monitoringRead, Edit, Delete
L4 statisticsRead
Load balancersRead, Edit, Delete
Location analyticsRead
Log forwarderRead, Edit, Delete
Manage boostRead, Edit, Delete
Manage cacheRead, Edit, Delete
Manage custom pageRead, Edit
Manage domainsPartial Read
Manage page rulesRead, Edit, Delete
Manage SSLRead, Edit, Delete
Manage subscriptionsEdit
Metric exporterRead, Edit, Delete
Purge cacheRead, Edit, Delete
Rate limit rulesRead, Edit, Delete
Response analyticsRead
Security dashboardRead, Edit
Smart checkerCheck, Read
Traffic statisticsRead
Visited IPsRead
WAF settingsRead, Edit, Delete

2. General Cache purger

Focused on cache management.
Access AreaPermissions
Domain dashboardRead
Manage cacheDelete
Manage domainsPartial Read
Purge cacheRead, Edit, Delete
Traffic statisticsRead

3. DNS Manager

Manages DNS-related settings.
Access AreaPermissions
Cloud iconRead, Edit
DNS analyticsRead
DNS recordsRead, Edit, Delete
Domain dashboardRead
Manage domainsPartial Read
Smart checkerCheck, Read
Traffic statisticsRead

4. Insights Analyst

Read-focused analytical access with some exporter privileges.
Access AreaPermissions
Attack statisticsRead
DNS analyticsRead
Domain dashboardRead
Error analyticsRead
L4 statisticsRead
Location analyticsRead
Log forwarderRead, Edit, Delete
Manage domainsPartial Read
Metric exporterRead, Edit, Delete
Response analyticsRead
Smart checkerCheck, Read
Traffic statisticsRead
Visited IPsRead

5. General Security Manager

Advanced domain-level security permissions.

Access AreaPermissions
Attack statisticsRead
DDoS settingsRead, Edit, Delete
Firewall rulesRead, Edit, Delete
Security dashboardRead, Edit
WAF settingsRead, Edit, Delete
L4 firewall / proxy / monitoringRead, Edit, Delete
Rate limit rulesRead, Edit, Delete
Custom pages, SSL, page rulesRead, Edit, Delete

6. General Traffic Manager

Focused on traffic and performance optimization.

Access AreaPermissions
Cloud iconRead, Edit
DNS recordsRead, Edit, Delete
Load balancersRead, Edit, Delete
L4 proxy & monitoringRead, Edit, Delete
Boost, cache, page rulesRead, Edit, Delete
Purge cacheTRUE
Traffic analyticsRead
Smart checkerCheck, Read

7. Read-Only Admin

Provides view-only access to almost all domain-level features. Users cannot modify or delete any configuration.

Organization-Based Roles

These roles apply to the entire account and include global settings, billing, user management, and configuration across all domains.

1. Organization Admin

Highest level of access across all domains and organization settings.

Includes all domain-level admin permissions, plus:

  1. Activity log (Read all)
  2. IP lists (Read, Edit, Delete)
  3. Manage domains (Read, Create)
  4. Billing & subscription management
  5. User management (in Read-Only Admin)
  6. API key management (in Read-Only Admin)

2. Billing Manager

Manages billing functions.
Access AreaPermissions
Manage billingRead, Edit, Delete
Subscription managementRead, Edit, Delete

3. Cache Purger

Global equivalent of the domain Cache Purger.

Access AreaPermissions
Domain dashboardRead
Manage cacheDelete
Manage domainsRead
Purge cacheRead, Edit, Delete
Traffic statisticsRead

4. DNS Manager

Similar to domain DNS manager, but account-wide.

Access AreaPermissions
Cloud iconRead
DNS analyticsRead
DNS recordsRead, Edit, Delete
Domain dashboardRead
Manage domainsRead
Smart checkerCheck, Read
Traffic statisticsRead

5. Insights Analyst (Org)

Account-wide analytics and exporter capabilities.

Access AreaPermissions
Attack, DNS, error, response analyticsRead
L4 statisticsRead
Location analyticsRead
Log forwarderRead, Edit, Delete
Metric exporterRead, Edit, Delete
Traffic statisticsRead
Visited IPsRead
Manage domainsRead

6. Read-Only Admin

Full visibility across the account without configuration access.

Access AreaPermissions
Activity logRead all
All analyticsRead
DNS, SSL, firewall, WAF, L4Read
BillingRead
UsersRead
SubscriptionsRead
API keysRead

7. Security Manager

Full global security access.

Access AreaPermissions
DDoS, WAF, Firewall rulesRead, Edit, Delete
IP listsRead, Edit, Delete
L4 firewall / proxy / monitoringRead, Edit, Delete
Rate limit rulesRead, Edit, Delete
SSL, page rules, custom pagesRead, Edit, Delete
Security dashboardRead, Edit
All analytics modulesRead

8. Traffic Manager

Account-wide traffic and performance control.

Access AreaPermissions
DNS recordsRead, Edit, Delete
Load balancersRead, Edit, Delete
Boost, cache, purgeRead, Edit, Delete
Page rulesRead, Edit, Delete
L4 proxy & monitoringRead, Edit, Delete
Traffic analyticsRead
Smart checkerCheck, Read

Best Practices

Assign the minimum necessary role
Follow the principle of least privilege. Assign only the permissions required for a user’s tasks.

Prefer domain-based roles when only domain access is needed
To avoid unnecessary exposure to billing and global security settings.

Use organization roles only for cross-account responsibilities
Billing, user management, and global security require organization-based roles.

Read-Only roles are ideal for audits and external consultants

Review user roles periodically
Regular audits help maintain security and compliance.

    • Related Articles

    • Organization

      Overview Every VergeCloud user begins with a personal organization by default. This personal organization is a private space that only the user can access and serves as an initial environment for managing their resources. While personal organizations ...
    • Invite User

      Overview Inviting users to your VergeCloud organization is a fundamental part of managing your team and ensuring that the right individuals have access to the resources they need. VergeCloud provides a robust Member Management system that allows ...
    • API Keys

      Overview The API Keys section in VergeCloud provides a centralized location to create, manage, and secure programmatic access to your organization’s services. API keys allow applications, scripts, or internal tools to interact with VergeCloud ...
    • Log Forwarder Setup Guide

      Log Forwarder Setup Guide The Log Forwarder feature in VergeCloud allows users to stream different types of logs to external systems like Kafka, S3, and Syslog. It provides visibility into HTTP requests, security events, DNS activity, and internal ...
    • Updating NS Records on Popular Registrar

      Overview This guide provides step-by-step instructions for updating your domain’s Nameserver (NS) records across several popular registrars. Since registrar interfaces may vary or change over time, use these instructions as a general reference when ...