---
title: User permissions
source: https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-permissions
---

In a New Relic user management context, a permission is a specific task that you can do with New Relic. Various permissions are included in our pre-built roles (for example, refer to our [standard roles](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts#roles)). Here are some examples of permissions:

-   The ability to view APM app settings
-   Modify alert conditions
-   Manage data retention settings
-   Create organization-level authentication domains
-   Deploy individual fleets to specific resources

You can create custom roles at three different scopes and add any number of permissions to them:

-   **Organization-scoped permissions**: For organization-wide administrative functions (Identity and Access Management, New Relic One, API Keys, Security, etc.)
-   **Account-scoped permissions**: For platform features within specific accounts (APM, Browser, Infrastructure, Alerts, etc.)
-   **Entity-scoped permissions**: For fine-grained access to specific resources

To learn what permissions a role has, go to the user management UI and view a specific role. To find this UI: From **[one.newrelic.com](https://one.newrelic.com/all-capabilities)**, click the [user menu](https://docs.newrelic.com/docs/accounts/accounts-billing/general-account-settings/intro-account-settings) in the lower right, and then go to: **Administration > Access management > Roles**.

## Important points about permissions [#important-points]

A New Relic full platform user with no limitations (for example, a user in the **Admin** group) is able to use all features of the platform. Many, but not all, of the tasks you can perform in New Relic are available as permissions. You can add or remove these from a custom role, and we also use these permissions to differentiate between our [standard roles](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts#roles). The permissions that we've made visible and available for selection are those we think you're most likely to find useful for common user management tasks.

There are a lot of New Relic functionalities that we don't make visible and available as permissions you could select. For example, there are various UI pages that you can access as any user and that aren't gated by the permissions we expose.

> #### 💡 TIP
>
> Permissions may also sometimes be referred to as **capabilities**.

Here are some other important points about permissions:

-   **A user's user type must also allow access.** A user's access to New Relic features is governed by both user type and assigned roles. For more about that, see [User access](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts).
-   **Some permissions overlap in functionality.** This is why selecting some permissions checkboxes in the UI will automatically check or uncheck other boxes.
-   **Permissions don't affect querying of data.** Most permissions apply to New Relic UI and API experiences and not to querying data. For example, if your permissions restrict you from accessing the APM UI, you can still query APM data if you have access to that account. If you require more firm data boundaries for some projects or users, you can segment your data into [different accounts](https://docs.newrelic.com/docs/accounts/accounts-billing/account-structure/add-accounts).

To learn more about the main ways user permissions are controlled, see [User management concepts](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts).

## Our pre-built roles [#pre-built-roles]

Our pre-built roles have various groupings of permissions. See [learn about roles](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts).

## Permission definitions [#permission-definitions]

You can go to the UI to view the permissions for each of our pre-built roles. In the lower-left corner of the [UI](https://one.newrelic.com), click on your name to open the user menu, and then go to **Administration > Access management > Roles**.

The UI provides detailed information about permissions for all roles, including:

-   All product admin
-   Standard user
-   Read only
-   All custom roles in your organization

The Access Management UI shows the most current permission details for each role.

**Identity and Access Management**

These organization-scoped permissions pertain to managing users, groups, roles, and authentication domains within your organization:

-   **Accounts**: Create and manage accounts within your organization.
-   **Authentication Domains**: Configure how users are provisioned and authenticated.
-   **Data Access Policies**: Create and manage policies that control access to log data partitions.
-   **Grants**: Create and manage access grants that link groups to roles over specific targets.
-   **Groups**: Create and manage user groups within authentication domains.
-   **Roles**: Create and manage custom roles with specific permissions.
-   **Users**: Add, remove, and manage users within your organization.

**Alerts**

These permissions pertain to our [legacy alerting feature](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/learn-alerts/introduction-alerts), not to our [applied intelligence permissions](#applied-intelligence) and [incident intelligence permissions](#incident-intelligence).

Permissions:

-   **Channels**: relates to [alert notification channels](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/alert-notifications/notification-channels-control-where-send-alerts).
-   **Conditions**: relates to [alert conditions](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/alert-conditions/create-alert-conditions).
-   **Incidents**: relates to [alert events](https://docs.newrelic.com/docs/alerts/organize-alerts/specify-when-alerts-create-events) and [view alert events from our products](https://docs.newrelic.com/docs/alerts/alert-event-management/view-alert-event-details).
-   **Lifecycle overrides**: relates to [muting rules](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/alert-notifications/muting-rules-suppress-notifications).
-   **Policies**: relates to [alert policies](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/alert-policies/create-edit-or-find-alert-policy).
-   **Cross-account alerts**: relates to [cross-account alerts](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/alert-policies/create-edit-or-find-alert-policy).

**API keys**

These permissions pertain to creating and managing our [API keys](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys):

-   **Browser keys**: relates to the [browser key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#overview-keys).
-   **License keys**: relates to the [license key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#overview-keys).
-   **User API keys**: relates to the [user key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#overview-keys).

**APM**

These permissions pertain to our [APM agents](https://docs.newrelic.com/docs/apm/new-relic-apm/getting-started/introduction-apm) and associated features:

-   **Application settings**: relates to the APM **Application settings** UI page.
-   **Deployments**: relates to the [APM deployments UI page](https://docs.newrelic.com/docs/apm/new-relic-apm/maintenance/record-monitor-deployments).
-   **Embedded charts**: relates to the [**Get chart link** feature](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/ui-data/basic-ui-features/#share).
-   **Errors (all)**: relates to [error trace details](https://docs.newrelic.com/docs/apm/apm-ui-pages/error-analytics/manage-error-data).
-   **Errors (individual)**: relates to [error trace details](https://docs.newrelic.com/docs/apm/apm-ui-pages/error-analytics/manage-error-data).
-   **Instrumentation**: relates to adding [custom instrumentation](https://docs.newrelic.com/docs/apm/agents/manage-apm-agents/agent-data/custom-instrumentation).
-   **Key transactions**: relates to [key transactions](https://docs.newrelic.com/docs/apm/transactions/key-transactions/introduction-key-transactions).
-   **Labels**: relates to [tags for APM data](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/core-concepts/use-tags-help-organize-find-your-data).
-   **Log settings**: relates to [APM logs](https://docs.newrelic.com/docs/logs/logs-context/disable-automatic-logging/#solution).
-   **Slow SQL**: relates to [slow query data](https://docs.newrelic.com/docs/apm/apm-ui-pages/monitoring/view-slow-query-details).
-   **Thread profiles**: relates to the [thread profiler](https://docs.newrelic.com/docs/apm/apm-ui-pages/events/thread-profiler-tool).
-   **Transaction traces (all)**: relates to [transaction traces](https://docs.newrelic.com/docs/apm/transactions/transaction-traces/configure-transaction-traces).
-   **Transaction traces (individual)**: relates to [transaction traces](https://docs.newrelic.com/docs/apm/transactions/transaction-traces/configure-transaction-traces).

**Applied intelligence**

These permissions pertain to [applied intelligence](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/get-started-incident-intelligence) features:

-   **Channels**: relates to [notification channels](https://docs.newrelic.com/docs/alerts-applied-intelligence/notifications/intro-notifications).
-   **Comments**: relates to [postmortem comments](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/postmortems-applied-intelligence/#comment-event).
-   **Destinations**: relates to [destinations](https://docs.newrelic.com/docs/alerts-applied-intelligence/notifications/destinations).
-   **Incident analysis**: relates to the part of the [**Issues & activity** page](https://docs.newrelic.com/docs/alerts/alert-event-management/Issues-and-alert-event-management-and-response) where golden signals and component are shown.
-   **Issue RCA**: relates to [root cause analysis](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/use-incident-intelligence/#root-cause-analysis).
-   **Issues**: relates to [incident intelligence issues](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/use-incident-intelligence).
-   **Issues configuration**: relates to [issue configuration](https://docs.newrelic.com/docs/alerts/organize-alerts/specify-when-alerts-create-events).
-   **Issues feed**: relates to [the issues feed](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/get-started/alerts-ai-overview-page/#issues).
-   **Workflows**: relates to [workflows](https://docs.newrelic.com/docs/alerts/get-notified/alert-event-workflows).

**Browser**

These permissions pertain to [browser monitoring](https://docs.newrelic.com/docs/browser/browser-monitoring/getting-started/introduction-browser-monitoring):

-   **Application settings**: relates to browser application settings.
-   **Domain conditions**: relates to [browser domain conditions](https://docs.newrelic.com/docs/browser/new-relic-browser/configuration/monitor-or-block-specific-domains-subdomains).
-   **Segment allow lists**: relates to segmenting [allow lists](https://docs.newrelic.com/docs/browser/new-relic-browser/configuration/group-browser-metrics-urls).
-   **View session replays**: relates to [viewing replays.](https://docs.newrelic.com/docs/browser/browser-monitoring/browser-pro-features/session-replay/get-started).

**Dashboards**

-   **Live chart URL**: relates to the [share chart features](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/ui-data/basic-ui-features/#share) for charts generated from NRQL queries.

**Data platform**

-   **Streaming export**: relates to [streaming data export](https://docs.newrelic.com/docs/apis/nerdgraph/examples/nerdgraph-streaming-export).

**Data retention**

-   **Insights event retention**: This governs the ability to manage [data retention](https://docs.newrelic.com/docs/data-apis/manage-data/manage-data-retention) values within the bounds of a contract for specific data namepsaces.

**Errors inbox**

-   **Attribute analysis**: relates to the [attributes tab](https://docs.newrelic.com/docs/errors-inbox/errors-inbox/#attributes).

**Incident intelligence**

These permissions pertain to [incident intelligence](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/get-started-incident-intelligence):

-   **Automatic inactivity closing policy**: refers to time-to-live settings for inactive/idle issues.
-   **Cartographer**: relates to [topology settings](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/change-applied-intelligence-correlation-logic-decisions/#topology).
-   **Decisions**: relates to [applied intelligence decisions](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/change-applied-intelligence-correlation-logic-decisions).
-   **Destinations**: relates to a deprecated incident intelligence destination system.
-   **Environments**: relates to [environments](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/get-started-incident-intelligence/#1-configure-environment).
-   **Grace period policy**: relates to [grace period policy settings](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/user-settings).
-   **Incidents**: relates to [alert events](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/use-incident-intelligence).
-   **Input source configuration**: relates to [incident sources](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/get-started-incident-intelligence#1-configure-sources).
-   **Issues**: relates to [incident intelligence issues](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/use-incident-intelligence).
-   **Pathways**: relates to the mostly deprecated incident intelligence pathways feature.
-   **Platforms**: relates to the mostly deprecated incident intelligence platforms feature.
-   **Suggested decisions**: relates to [decisions suggested by applied intelligence](https://docs.newrelic.com/docs/alerts-applied-intelligence/applied-intelligence/incident-intelligence/change-applied-intelligence-correlation-logic-decisions/#suggested-decisions).

**Incident workflows**

-   **Workflows**: relates to a preview workflows feature that will likely be deprecated in 2022.

**Infinite Tracing**

-   **Trace observers**: relates to the [trace observer](https://docs.newrelic.com/docs/distributed-tracing/infinite-tracing/set-trace-observer).

**Infrastructure**

-   **Cloud integrations**: relates to [cloud integrations](https://docs.newrelic.com/docs/infrastructure/infrastructure-integrations/get-started/introduction-infrastructure-integrations).
-   **Filter sets**: relates to [filter sets](https://docs.newrelic.com/docs/infrastructure/infrastructure-ui-pages/infrastructure-inventory-page-search-your-entire-infrastructure/#filter-sets). This feature is in process of being deprecated and is only available on the infrastructure **Events** and **Inventory** UI pages.

**Insights**

**Insights** is the original name for a product that had features related to custom data ingest, custom queries, custom charts, and custom dashboards. Permissions include:

-   **Any dashboard**: relates to the ability to delete any dashboard in an account.
-   **Data sources**: relates to a now deprecated UI that allowed for controlling what data was reported to New Relic.
-   **Events to metrics**: this governs:
    -   [Events-to-metrics rules and data](https://docs.newrelic.com/docs/data-apis/convert-to-metrics/analyze-monitor-data-trends-metrics)
    -   [Service level indicators and objectives](https://docs.newrelic.com/docs/service-level-management/create-slm)
-   **Insert keys**: relates to our mostly deprecated [Insights insert key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#insights-insert-key) (a [license key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#overview-keys) is preferred).
-   **NRQL drop rules**: relates to [dropping data with drop rules](https://docs.newrelic.com/docs/data-apis/manage-data/drop-data-using-nerdgraph).
-   **Query keys**: relates to our mostly deprecated [Insights query key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#insights-query-key) (the user key is preferred).

**Logs**

-   **Data partition rules**: relates to [data partitions](https://docs.newrelic.com/docs/logs/ui-data/data-partitions).
-   **Live archives configuration**: relates to configuring [live archives](https://docs.newrelic.com/docs/logs/get-started/live-archives) retention for logs.
-   **Live archives query**: relates to querying logs stored in [live archives](https://docs.newrelic.com/docs/logs/get-started/live-archives).
-   **Obfuscation rules**: relates to [log obfuscation](https://docs.newrelic.com/docs/logs/ui-data/obfuscation-ui).
-   **Parsing rules**: relates to [log parsing](https://docs.newrelic.com/docs/logs/ui-data/parsing).
-   **Pipeline configuration**: relates to configuring the log data pipeline. Currently this governs [log patterns](https://docs.newrelic.com/docs/logs/ui-data/find-unusual-logs-log-patterns).
-   **Public saved views**: relates to [saved views](https://docs.newrelic.com/docs/logs/ui-data/use-logs-ui/#saved-views) that are public.

**Maps**

-   **Service maps**: relates to [service maps](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/ui-data/service-maps/introduction-service-maps).

**Mobile**

-   **Applications**: relates to [mobile monitoring features](https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/get-started/introduction-mobile-monitoring) for your monitored apps.
-   **Crashes**: relates to [crash analysis features](https://docs.newrelic.com/docs/mobile-monitoring/mobile-monitoring-ui/crashes/crash-analysis-group-filter-your-crashes).

**New Relic One**

These are assorted permissions related to basic features of the [New Relic platform](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/introduction-new-relic-one) (sometimes referred to as New Relic):

-   **Entities**: relates to creating and deleting New Relic-monitored [entities](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/core-concepts/what-entity-new-relic).
-   **Entity relationships**: relates to [entity relationships](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/core-concepts/what-entity-new-relic/#related-entities).
-   **Golden metrics**: relates to [golden metrics](https://docs.newrelic.com/docs/apis/nerdgraph/examples/golden-metrics-entities-nerdgraph-api-tutorial) (key metrics) in curated user experiences.
-   **Nerdpacks**: relates to [New Relic apps](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/build-custom-new-relic-one-application).
-   **NRQL lookups**: relates to the ability to use [lookup tables](https://docs.newrelic.com/docs/logs/ui-data/lookup-tables-ui).
-   **Pixie account link**: this capability allows the creation of an associated Pixie account when adding Pixie to a cluster from our [guided install](https://docs.newrelic.com/docs/kubernetes-pixie/auto-telemetry-pixie/install-auto-telemetry-pixie).
-   **Pixie credentials**: relates to access of linked Pixie accounts.
-   **Pixie live data**: enables access to live debugging data in the [Kubernetes cluster explorer](https://docs.newrelic.com/docs/kubernetes-pixie/kubernetes-integration/understand-use-data/kubernetes-cluster-explorer).
-   **Repositories**: relates to creating and deleting New Relic-monitored repositories (used by features like [New Relic CodeStream](https://docs.newrelic.com/docs/codestream/start-here/what-is-codestream)).
-   **Tags**: relates to platform [tagging](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/core-concepts/use-tags-help-organize-find-your-data).
-   **Workloads**: relates to [workloads](https://docs.newrelic.com/docs/new-relic-solutions/new-relic-one/workloads/workloads-isolate-resolve-alert-events-faster).

**Plugins**

-   **Configurations**: refers to our [deprecated plugins feature](https://support.newrelic.com/s/hubtopic/aAX8W0000008asP/new-relic-plugin-eol-wednesday-june-16th-2021).

**Synthetics**

These permissions pertain to [synthetics monitoring](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/getting-started/get-started-synthetic-monitoring):

-   **Configure private locations**: relates to [private locations](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/private-locations/private-locations-overview-monitor-internal-sites-add-new-locations).
-   **Monitor downtimes**: relates to [monitor downtimes](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/monitor-downtimes-disable-monitoring-during-scheduled-maintenance-times).
-   **Monitor scripts**: relates to [scripted monitors](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/getting-started/types-synthetic-monitors) (scripted browser monitors and scripted API test monitors).
-   **Monitors**: relates to ability to configure [synthetic monitors](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/getting-started/types-synthetic-monitors) (for example, name, period, and locations). The bulk runtime upgrade permission allows you to make runtime changes using the [runtime upgrades UI](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/runtime-upgrade-ui/).
-   **Secure credentials**: relates to [secure credentials](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/store-secure-credentials-scripted-browsers-api-tests).

**Security**

-   **Vulnerabilities**: refers to the ability to view and manage vulnerabilities detected in entities.
