Vault-level read-only permission for viewing configured group permissions

Vault-level read-only permission for viewing configured group permissions

1 vote

avatar

Currently, the "Configured permissions" tab on an entry or folder is only visible to users who have the "Edit permissions" right. Users without this right can only see their own effective rights under "My permissions." We would like to request a separate permission e.g. "View permissions" that would let a user or user group view the Configured permissions list.

Use case: We want to give certain groups (vault admin groups) visibility into how access is currently configured (for auditing and documentation purposes) without giving them the ability to change any permission settings, which should remain restricted to administrators. Aim here is to give creater visibility to the current permission sets to vault admins directly.

This would follow the same pattern already used elsewhere in RDM, where View and Edit are separate, independently assignable rights (e.g. View vs. Edit on entries).

All Comments (3)

avatar

Hello,

In 2026.3 we've reworked how admin permissions are handled so they can be more granular in Devolutions Server. I'll check with the team whether it's possible there.

Could you let me know what workspace you're currently using? Is it SQL Server, Devolutions Server, or Devolutions Cloud?

Regards,

Hubert Mireault

avatar
Hello,

In 2026.3 we've reworked how admin permissions are handled so they can be more granular in Devolutions Server. I'll check with the team whether it's possible there.

Could you let me know what workspace you're currently using? Is it SQL Server, Devolutions Server, or Devolutions Cloud?

Regards,


@Hubert Mireault

Hello,

this would be great feature to have. We are using Devolutions Server

BR,

Jussi Saranpää

avatar

Hello,

Good news then, in 2026.3, permissions are changed to work by roles. There's a role called "auditor" that you can configure on users that will give them read-only access to users, licenses, groups, reports, etc. This means your user doesn't need to have access to a specific vault to be able to see reports on permissions.
Here's an example where I set my non-admin user to only the auditor role:
When I log into my user, since they have no other role assigned, they will not have any vaults available to them, but they will be able to check out multiple reports, including ones on role assignments for example:

I would be interested to know if you could check out the existing reports in RDM and DVLS and let me know whether the specific type of report / view you'd like already exists or doesn't. If we don't have the proper report for the information you'd like to easily visualize, I think this is where we could focus this feature request.

Regards,

Hubert Mireault

efa364de-3727-43da-bfeb-854add3fe29b.png

fdf03b35-9eb3-4a62-9230-903aa5ff43da.png