Skip to content

Admins

Oblique organizations include three default roles:

  • Organization owner: Owns the Oblique organization, can perform all actions in Oblique, and receives all communications. Each Oblique organization has one owner.
  • Admin: Manages the organization, including managing integrations, users, attributes, accounts, groups, resources, and entitlements, and creating Oblique API keys.
  • Member: Member of the organization. Members can become members of groups and have entitlements granting them access.

Objects can also have owners. Object owners are users or groups who can make or approve changes to an object, such as an attribute-based group, team group, or reporting group. By default, Oblique admins are owners of all groups in Oblique.

Although admins can create Oblique API keys, the organization owns these keys, not the individual admin. When you remove an admin, the API keys remain valid.

By default, the organization owner receives all communications about Oblique, including billing and security notifications.

You must be an admin to add an admin.

Navigate to the admins page.

  1. Under Admins, select Add admin.
  2. Search for and select the user you wish to add as an Oblique admin.
  3. Select Add admins.
You must be an admin to remove an admin.

Navigate to the Admins page.

  1. Under Admins, locate the user to be removed. If you have a lot of admins, use the search bar to more easily find them.
  2. For the selected user, in the More menu, select Remove admin….
  3. Confirm you want to remove the admin, and select Remove admin.
You must be an admin to change the organization owner.

Navigate to the Admins page.

  1. Under Organization owner, select Change owner.
  2. Search for and select the user you wish to make the new owner.
  3. Select Update owner.

Verify ownership of an Oblique organization

Section titled “Verify ownership of an Oblique organization”

Oblique requires you to show control of your organization’s domain when requesting help from our support team for certain issues, such as claiming ownership of your organization’s Oblique tenant. Our support team will ask you to do one of the following:

  • Respond to a confirmation email sent to an address at your organization, such as to the existing owner
  • Set a DNS TXT record for your domain

By default, all members of an organization can make change requests but cannot make changes unilaterally. Members who are the owners of affected objects can approve requests for those objects, including their own requests. Admins can make or approve any change.

Users and resources cannot be directly added to Oblique. Instead, they are automatically imported when they are discovered in and synced from an integration.

TargetActionDescriptionIs a requestAdminObject ownerUser
UserCREATEImport a user.NONOn/aNO
TeamCREATECreate a team group.YESYESn/aREQUEST
TeamUPDATEUpdate a team group’s description.Coming soonYESYESNO
TeamDELETEDelete a team group.YESYESYESREQUEST
TeamMemberCREATEAdd a user to a team group.YESYESYESREQUEST
TeamMemberDELETERemove a user from a team group.YESYESYESREQUEST
TeamOwnerCREATEAdd an owner to a team group.YESYESYESREQUEST
TeamOwnerDELETERemove an owner from a team group.YESYESYESREQUEST
GroupCREATECreate an attribute-based group.NOYESn/aNO
Create a reporting group.NOYESn/aYES
GroupDELETEDelete an attribute-based group or reporting group.NOYESYESNO
GroupOwnerCREATEAdd an owner to an attribute-based group or reporting group.YESYESYESREQUEST
GroupOwnerDELETERemove an owner from an attribute-based group or reporting group.YESYESYESREQUEST
ResourceCREATEImport a resource.NONOn/aNO
EntitlementCREATECreate an entitlement for a resource.YESYESn/aComing soon
EntitlementUPDATEEdit an entitlement for a resource.YESYESn/aComing soon
EntitlementDELETERevoke an entitlement for a resource.YESYESn/aComing soon
AccessReviewCREATEStart an access review.NOYESn/aNO
AccessReviewUPDATEConfirm a review’s scope, complete a review, or re-open a review.NOYESn/aNO
AccessReviewDELETEDelete a review.NOYESn/aNO
AccessReviewAppCREATEAdd an app to a review’s scope.NOYESn/aNO
AccessReviewAppDELETERemove an app from a review’s scope.NOYESn/aNO
AccessReviewAccountCREATEAdd an account to an app in a review.NOYESn/aNO
AccessReviewAccountDELETERemove an account from an app in a review.NOYESn/aNO
AccessReviewDecisionUPDATERecord, change, or clear a decision on an account.NOYESn/aNO
AccessReviewScreenshotCREATEAttach a screenshot to capture accounts in an app for a review.NOYESn/aNO
AccessReviewScreenshotDELETERemove a screenshot capturing accounts for an app in a review.NOYESn/aNO
AccessReviewRemediationEvidenceCREATEAdd remediation evidence for an app in a review.NOYESn/aNO
AccessReviewRemediationEvidenceDELETERemove remediation evidence from an app in a review.NOYESn/aNO
IntegrationCREATEAdd an integration.NOYESn/aNO
IntegrationUPDATEUpdate an integration’s settings, including approvals from Slack.NOYESn/aNO
ServiceAccountCREATECreate an API key.NOYESn/aNO
ServiceAccountDELETERevoke an API key.NOYESn/aNO
AdminCREATEAdd an admin.NOYESn/aNO
AdminDELETERemove an admin.NOYESn/aNO
OwnerUPDATEChange the organization owner.NOYESn/aNO

Only admins can view recommendations and open requests from them.

Only admins can run access reviews.