In a New Relic user management context, a permission is a specific task that you can do with New Relic. Various permissions are included in our pre-built roles (for example, refer to our standard roles). Here are some examples of permissions:
The ability to view APM app settings
Modify alert conditions
Manage data retention settings
Create organization-level authentication domains
Deploy individual fleets to specific resources
You can create custom roles at three different scopes and add any number of permissions to them:
Organization-scoped permissions: For organization-wide administrative functions (Identity and Access Management, New Relic One, API Keys, Security, etc.)
Account-scoped permissions: For platform features within specific accounts (APM, Browser, Infrastructure, Alerts, etc.)
Entity-scoped permissions: For fine-grained access to specific resources
To learn what permissions a role has, go to the user management UI and view a specific role. To find this UI: From one.newrelic.com, click the user menu in the lower right, and then go to: Administration > Access management > Roles.
Important points about permissions
A New Relic full platform user with no limitations (for example, a user in the Admin group) is able to use all features of the platform. Many, but not all, of the tasks you can perform in New Relic are available as permissions. You can add or remove these from a custom role, and we also use these permissions to differentiate between our standard roles. The permissions that we've made visible and available for selection are those we think you're most likely to find useful for common user management tasks.
There are a lot of New Relic functionalities that we don't make visible and available as permissions you could select. For example, there are various UI pages that you can access as any user and that aren't gated by the permissions we expose.
Tip
Permissions may also sometimes be referred to as capabilities.
Here are some other important points about permissions:
A user's user type must also allow access. A user's access to New Relic features is governed by both user type and assigned roles. For more about that, see User access.
Some permissions overlap in functionality. This is why selecting some permissions checkboxes in the UI will automatically check or uncheck other boxes.
Permissions don't affect querying of data. Most permissions apply to New Relic UI and API experiences and not to querying data. For example, if your permissions restrict you from accessing the UI, you can still query APM data if you have access to that account. If you require more firm data boundaries for some projects or users, you can segment your data into different accounts.
To learn more about the main ways user permissions are controlled, see User management concepts.
Our pre-built roles
Our pre-built roles have various groupings of permissions. See learn about roles.
Permission definitions
You can go to the UI to view the permissions for each of our pre-built roles. In the lower-left corner of the UI, click on your name to open the user menu, and then go to Administration > Access management > Roles.
The UI provides detailed information about permissions for all roles, including:
All product admin
Standard user
Read only
All custom roles in your organization
The Access Management UI shows the most current permission details for each role.
These organization-scoped permissions pertain to managing users, groups, roles, and authentication domains within your organization:
Accounts: Create and manage accounts within your organization.
Authentication Domains: Configure how users are provisioned and authenticated.
Data Access Policies: Create and manage policies that control access to log data partitions.
Grants: Create and manage access grants that link groups to roles over specific targets.
Groups: Create and manage user groups within authentication domains.
Roles: Create and manage custom roles with specific permissions.
Users: Add, remove, and manage users within your organization.
Filter sets: relates to filter sets. This feature is in process of being deprecated and is only available on the infrastructure Events and Inventory UI pages.
Insights is the original name for a product that had features related to custom data ingest, custom queries, custom charts, and custom dashboards. Permissions include:
Any dashboard: relates to the ability to delete any dashboard in an account.
Data sources: relates to a now deprecated UI that allowed for controlling what data was reported to New Relic.
Monitor scripts: relates to scripted monitors (scripted browser monitors and scripted API test monitors).
Monitors: relates to ability to configure synthetic monitors (for example, name, period, and locations). The bulk runtime upgrade permission allows you to make runtime changes using the runtime upgrades UI.