UiPath Documentation
ixp
latest
false
IXP overview guide
  • Introduction
    • Introduction to UiPath® IXP
      • Capability types
      • Choosing the correct capability
  • Access control and administration
  • Licensing
  • Frequently asked questions

Managing access

Manage access in the IXP service on Automation Cloud, including available roles, permissions, and how to assign them to users and groups.

This section addresses to Automation Cloud users and contains information on how to manage access in the IXP service.

Roles and their underlying permissions

This section contains an overview of the different roles and the underlying permissions they grant in the UiPath® IXP service.

In the Manage Access tab from the Administration page, you can assign roles to specific users. Each role comes with a predefined set of permissions, so you cannot assign individual permissions. Instead, you must assign the main role, which includes all associated permissions.

Note:

All users can view other users in projects and tenants, but only administrators can modify users.

The following table contains a list of all roles and permissions, as well as a description of each role. The Applies to column indicates whether the role is functional in Communications Mining (CM) projects, Unstructured and Complex Documents (UCD) projects, or both:

RoleScopeApplies toPermissionsRole description
IXP Service AdminTenantCM and UCDAudit Log - Read
Tenant - Manage
Grants full rights to the IXP service.
IXP Project CreatorTenantCM and UCDProject - CreateCan create IXP projects in the tenant. Becomes Project Admin of projects they create.
IXP Project AdminProjectCM and UCDAlert - Write
Appliance Configuration - Write
Bucket - Append
Bucket - Write
Comment - Manage
Dataset - Export
Dataset - Manage
Integration - Write
Source - Manage
Stream - Consume
Stream - Manage
You can manage everything within a project such as users, integrations, sources, datasets, models, streams, and alerts. You cannot create or delete projects.
IXP Audit Log ViewerTenantCM and UCDAudit Log - ReadYou can view audit logs for the tenant through the Audit API.
IXP Package Admin (preview)TenantUCDPackages - Read
Packages - Write
Packages - Delete
You can create, modify, and delete packages in the tenant.
IXP Package Publisher (preview)TenantUCDPackages - Read
Packages - Write
You can view, create, and modify packages in the tenant. You cannot delete packages.
IXP Package Reader (preview)TenantUCDPackages - ReadYou can view packages in the tenant.
IXP AnalystProjectCMAlert - Write
Dashboard - Write
Dataset - Read
Integration - Read
Source - Read
Stream - Read
You can view everything within a project and can create, update, and delete dashboards and alerts. You cannot import, export, or review and label data. Also, you cannot modify or consume streams or set up integrations.
IXP Automation UserProjectCM and UCDComment - Manage
Dataset - Read
Project - Execute
Source - Read
Stream - Consume
Stream - Read
You can upload data and consume predictions from Communications Mining datasets in this project. This role also allows Agents to consume runtime predictions from Unstructured and Complex Documents projects.
IXP DeveloperProjectCM and UCDAlert - Read
Appliance Configuration - Write
Bucket - Append
Bucket - Read
Comment - Manage
Dataset - Export
Integration - Write
Model - Manage
Source - Manage
Stream - Consume
Stream - Manage
You can view everything within a project, upload or export data, configure integrations, publish model versions, manage streams, and consume predictions from them. You cannot review and label data. Also, you cannot create, update, or delete datasets or alerts.
IXP Model TrainerProjectCM and UCDAlert - Read
Dataset - Review
Dataset - Write
Integration - Read
Source - ReadSensitive
Stream - Read
You can view everything within a project, review and label data, and publish model versions. You can also create and update datasets, but you cannot delete them.
IXP ViewerProjectCM and UCDAlert - Read
Dataset - Read
Integration - Read
Source - Read
Stream - Read
You can view everything within a project. You cannot create, update, or delete anything.
Note:

Since permissions are granted at the project level, users might need different permissions for different projects.

Permission types

Define the level of access granted to users for specific actions or resources.

Permission typeDescription
Service permissionsAllows you to view audit logs and manage projects and users for a tenant.
Sources permissionsRefer to the data your company uploaded for analysis.
Datasets permissionsGrant access to datasets, that is, a named collections of labels, general fields, and training data.
Streams permissionsGrant access to streams, which allow you to take actions on newly ingested data.
Buckets permissionsGrant access to buckets, which are containers of raw data items that you can upload.
Integration permissionsGrant access to integrations, which allow you to connect other services to the platform.
Packages permissions (preview)Grant access to packages, which contain the model versions deployed to Orchestrator folders for Flow projects.
Utility permissionsInclude any permissions that do not belong to any of the other categories.
Note:

Buckets, integration, and utility permissions are typically only granted to programmatic users such as development engineers. In addition, these permissions are not required for the daily use of the platform.

Permissions

Note:

The Modify users, View users, and Upload file permissions are deprecated because they are no longer required as standalone permissions outside of the available roles.

In the Manage Access tab from the Administration page, you can assign roles to specific users. Each role comes with a predefined set of permissions, so you cannot assign individual permissions. Instead, you must assign the main role, which includes all associated permissions.

Permission typePermissionApplies toPermission description
Service (only non-project)Tenant - ManageCM and UCDCreate, modify, and delete projects and users for a tenant, and set the tenant quotas. In Unstructured and Complex Documents projects, this permission is required to create and delete projects, as well as their runtime deployments. Additionally, all admins on UiPath Automation Cloud™ also receive this permission in the IXP platform automatically.
Service (only non-project)Project - CreateCM and UCDCreate projects in the tenant. The user who creates a project becomes project admin of that project.
Service (only non-project)Project - ReadCM and UCDView the projects in the tenant.
Service (only non-project)Project - WriteCM and UCDEdit the projects in the tenant, which covers updating the project title and description from the Administration page.
Service (only non-project)Project - DeleteCM and UCDDelete the projects in the tenant.
Service (only non-project)Audit Log - ReadCM and UCDView audit logs.
SourcesSource - ReadCM and UCDView sources and the messages they contain. This is required to view individual messages on the platform. For Unstructured and Complex Documents, this permission is required alongside Dataset - Read to open a project. Without it, you can see the project, but you cannot access it.
SourcesSource - ReadSensitive
(Grants Source - Read)
CM and UCDView any user properties marked as sensitive, in addition to others. Without this permission, sensitive values are redacted in any request that returns messages or documents.
SourcesSource - Manage
(Grants Source - ReadSensitive)
CMCreate, modify, and delete sources. You must create sources via the API.
SourcesComment - ManageCM and UCDCreate, update, and delete messages in a Communications Mining source via the API or the UI, as well as upload and delete design-time documents in an Unstructured and Complex Documents project.
DatasetsDataset - Read*CM and UCDView annotated and predicted labels on the datasets of the user. This is required to view individual messages on the platform. In Unstructured and Complex Documents projects, this permission covers the documents, annotations, and predictions of a project.
DatasetsDataset - Manage
(Grants Dataset - Write, Dataset - Read, Dataset - Review)
CMCreate, update, and delete datasets.
DatasetsDataset - Write
(Grants Dataset - Read, Model - Manage, Dashboard - Write)
CM and UCDCreate datasets and update their properties, for example, their description, sources and general fields, as well as enabling Quality of Service and Tone analysis. In Unstructured and Complex Documents projects, this permission also grants updating the Model configuration settings of a project.
DatasetsDataset - Review
(Grants Dataset - Read)
CM and UCDCreate, edit, and delete taxonomy elements, including labels, field groups, and fields, and annotate them on messages or documents. In Unstructured and Complex Documents projects, this permission also grants importing and exporting taxonomies.
DatasetsDataset - ExportCM and UCDExport datasets via the user interface. In Unstructured and Complex Documents projects, this permission (together with Dataset - Read and Source - Read) is required to export projects through the command-line interface (CLI). You do not need it to download documents from the user interface.
DatasetsModel - ManageCM and UCDPublish and unpublish trained models and update their tags.
DatasetsDashboard - WriteCMCreate or modify dashboards.
StreamsStream - ReadCMView streams and their configuration.
StreamsStream - ManageCMCreate, modify, and delete streams.
StreamsStream - ConsumeCMFetch and advance the output of a stream.
BucketsBucket - ReadCMView information on raw data buckets.
BucketsBucket Item - ReadCMDownload items from raw data buckets.
BucketsBucket - WriteCMAdd or remove raw data buckets.
BucketsBucket - AppendCMUpload data to buckets.
IntegrationsIntegration - ReadCMView information on external integrations.
IntegrationsIntegration - WriteCMAdd or remove integrations with external services.
Packages (preview)Packages - ReadUCDView packages in the tenant.
Packages (preview)Packages - WriteUCDCreate and modify packages in the tenant.
Packages (preview)Packages - DeleteUCDDelete packages in the tenant.
UtilityProject - ExecuteUCDRead and upload documents, and consume runtime predictions, and list Unstructured and Complex Documents projects or models. This permission applies when runtime permission checks are enabled.
UtilityAlert - ReadCMView alerts, and issues raised by them.
UtilityAlert - WriteCMCreate, modify and delete alerts.
UtilityAppliance Configuration - ReadCMFetch appliance configs.
UtilityAppliance Configuration - WriteCMUpload new or replace existing appliance configs.
Note:

*To view any data related to a source, dataset, or message in the platform, both Source - Read and Dataset - Read, or their parent roles, are required.

Permissions in Unstructured and Complex Documents projects

For a better understanding of how to use these roles and permissions in your Unstructured and Complex Documents projects, refer to Roles and permissions in Unstructured and Complex Documents projects.

Custom roles

Apart from the default IXP roles, you can also create and manage custom roles. Adapting custom roles to the specific needs and permissions of users, helps you align more closely with the needs of your organization.

Custom roles are available at tenant level, or project level.

Tenant-level roles

The tenant-level roles can grant the following permissions:

Standard permissions
  • Authorization / Action: Read Users can read the actions or permissions when creating a custom role or when viewing a role.
  • Authorization / Role: Read, Update, Create, Delete Depending on the selected permission, users can view, update, or delete existing roles, as well as create new custom roles.
  • Authorization / Role Assignment: Read, Update, Create, Delete Depending on the selected permission, users can view, update, or delete existing role assignments. In addition, users can assign roles through the Create permission.
  • IXP:
    • Audit Log - Read: Users can view the IXP audit logs.
    • Packages - Read: Users can view the packages in the tenant.
Additional permissions
  • Authorization / Role Assignment: Export role assignment data Users can extract and download information about role assignments, including which roles are assigned to which identities, such as users, groups, or service accounts. To export role assignment data, go to Automation Cloud, select Admin, then Accounts and local groups, and then Download role assignments.
  • IXP:
    • Can perform service-level administration tasks, manage quotas, and create and delete projects.
    • Create, modify, and delete packages in the tenant.
Project-level roles

The project-level roles can grant the following permissions:

Standard permissions
  • Authorization / Action: Read Users can read the actions or permissions when creating a custom role or when viewing a role.
  • Authorization / Role: Read, Update, Create, Delete Depending on the selected permission, users can view, update, or delete existing roles, as well as create new custom roles.
  • Authorization / Role Assignment: Read, Update, Create, Delete Depending on the selected permission, users can view, update, or delete existing role assignments. In addition, users can assign roles through the Create permission.
  • IXP:
    • Alert - Read, Write
    • Appliance Configuration - Read, Write
    • Bucket - Read, Write
    • Bucket Item - Read
    • Dashboard - Write
    • Dataset - Read, Write
    • Integration - Read, Write
    • Source - Read
    • Stream - Read, Write
Additional permissions
  • Authorization / Role Assignment: Export role assignment data Users can extract and download information about role assignments, including which roles are assigned to which identities, such as users, groups, or service accounts. To export role assignment data, go to Automation Cloud, select Admin, then Accounts and local groups, and then Download role assignments.
  • IXP:
    • Upload items to raw data buckets.
    • Create, update, and delete messages in a Communications Mining source via the API or the UI, including CSV upload, as well as upload and delete design-time documents in an Unstructured and Complex Documents project.
    • Export datasets via the UI.
    • Create and delete datasets. Grants all other dataset permissions except dataset export.
    • Create, edit, and delete taxonomy elements, including labels, field groups, and fields, and annotate messages or documents with them.
    • Publish and unpublish trained models and update their tags.
    • Read and upload documents, and consume runtime predictions from Unstructured and Complex Documents projects.
    • Create, modify, and delete sources.
    • View any user properties which have been marked as sensitive, in addition to others.
    • Fetch and advance the output of a stream.
    • Create, modify, and delete streams.
Creating a custom role

To create a custom role, proceed as follows:

  1. Go to the Administration page, and select Manage Access.
  2. Select Service, and then the Roles tab.
  3. Select Create role, and fill in the following fields:
    • Role name - Give your role a descriptive name.
    • Description - Optionally, provide a description.
    • Category - Choose between:
      • Tenant - You can assign this role at tenant-level, and consists of tenant-level permissions.
      • Project - You can assign this role to existing or new projects and consists of project-level permissions.
  4. Select Next to proceed to the permissions page.
  5. In the Standard permissions and Additional permissions tabs, select the permissions to assign to the custom role.
  6. Select Create.
Viewing a custom role

To view a custom role, proceed as follows:

  1. Navigate to the Administration page, and select Manage Access.
  2. Select Service, or a project folder, and then the Roles tab.
  3. Select the ellipsis for the custom role you want to view.
  4. Select View.
Editing a custom role

To edit a custom role, proceed as follows:

  1. Go to the Administration page, and select Manage Access.
  2. Select Service, or a project folder, and then the Roles tab.
  3. Select the ellipsis for the custom role you want to edit.
  4. Select Edit to modify the description and permissions of the custom role.
  5. After making the changes, select Update.
Duplicating a custom role

To duplicate a custom role, proceed as follows:

  1. Navigate to the Administration page, and select Manage Access.
  2. Select Service, or a project folder, and then the Roles tab.
  3. Select the ellipsis for the custom role you want to duplicate.
  4. Select Duplicate & customize, to create a copy of the role and modify its description and permissions.
  5. After making the changes, select Create.
Removing a custom role

To remove a custom role, proceed as follows:

  1. Go to the Administration page, and select Manage Access.
  2. Select Service, or a project folder, and then the Roles tab.
  3. Select the ellipsis for the custom role you want to edit.
  4. Select Delete.
    Note:

    Deleting a custom role also removes all associated role assignments.

  • Roles and their underlying permissions
  • Permission types
  • Permissions
  • Permissions in Unstructured and Complex Documents projects
  • Custom roles

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated