Skip to content

Admins

Oblique organizations include three default roles:

  • Owner: Owns the Oblique organization, can perform all actions in Oblique, and receives all communications. Each Oblique organization has one owner.
  • Admin: Manages the organization, including managing integrations, users, groups, resources, listings, and entitlements, and creating Oblique API keys.
  • Member: Member of the organization. Members can become members of groups and have entitlements granting them access.

Objects can also have owners. Object owners are users or groups who can make or approve changes to an object, such as an attribute-based group, team group, reporting group, or listing. By default, Oblique admins are owners of all groups and listings in Oblique.

Although admins can create Oblique API keys, the organization owns these keys, not the individual admin. When you remove an admin, the API keys remain valid.

By default, the organization owner receives all communications about Oblique, including billing and security notifications.

You must be an admin to add an admin.

Navigate to the admins page.

  1. Under Admins, select Add admin.
  2. Search for and select the user you wish to add as an Oblique admin.
  3. Select Add admins.
You must be an admin to remove an admin.

Navigate to the Admins page.

  1. Under Admins, locate the user to be removed. If you have a lot of admins, use the search bar to more easily find them.
  2. For the selected user, in the More menu, select Remove admin….
  3. Confirm you want to remove the admin, and select Remove admin.
You must be an admin to change the organization owner.

Navigate to the Admins page.

  1. Under Organization owner, select Change owner.
  2. Search for and select the user you wish to make the new owner.
  3. Select Update owner.

By default, all members of an Oblique instance can make 📥 change requests, but cannot make changes directly. Depending on the type of request, some members who are the owners of affected objects can approve requests.

Users and resources cannot be directly added to Oblique. Instead, they are automatically imported when they are discovered in and synced from an integration.

The following actions can be taken by each role:

TargetActionDescriptionOwnerAdminObject ownerMember
UserCREATEImport a user.
TeamCREATECreate a team group.n/a📥
TeamDELETEDelete a team group.📥
TeamProfileUPDATEUpdate a team group’s description.
TeamMemberCREATEAdd a user to a team group.📥
TeamMemberDELETERemove a user from a team group.📥
TeamOwnerCREATEAdd an owner to a team group.📥
TeamOwnerDELETERemove an owner from a team group.📥
GroupCREATECreate an attribute-based group or reporting group.n/a
GroupDELETEDelete an attribute-based group or reporting group.
GroupOwnerCREATEAdd an owner to an attribute-based group or reporting group.📥
GroupOwnerDELETERemove an owner from an attribute-based group or reporting group.📥
ResourceCREATEImport or create a resource.
ResourceUPDATEChange a resource’s management mode.
EntitlementCREATECreate an entitlement or assign a role.📥 for a listing
EntitlementUPDATEEdit an entitlement or edit a role assignment.📥 for a listing
EntitlementDELETERevoke an entitlement or revoke a role.📥 for a listing
ListingCREATECreate a listing.n/a
ListingUPDATEEdit a listing’s name, description, or visibility.
ListingDELETEDelete a listing.
ListingRoleCREATEAdd a role to a listing.
ListingRoleUPDATEEdit a listing role name, description.
ListingRoleUPDATEEdit a listing role mapping.
ListingRoleDELETERemove a role from a listing.
ListingOwnerCREATEAdd an owner to a listing.📥
ListingOwnerDELETERemove an owner from a listing.📥
ListingRolePolicyCREATEAdd an auto-approval policy.
ListingRolePolicyDELETEDelete an auto-approval policy.
IntegrationCREATEAdd an integration.n/a
IntegrationUPDATEUpdate an integration to allow resource creation.n/a
ServiceAccountCREATECreate an API key.
ServiceAccountDELETERevoke an API key.
AdminCREATEAdd an admin.
AdminDELETERemove an admin.
OwnerUPDATEChange the organization owner.