Scope an automation or threshold profile to specific customers, so that only technicians whose role covers them can work with it. A technician whose role covers none of the customers in a profile's scope does not see that profile at all.
Scope an automation or threshold profile to specific sites, so that only technicians whose role covers them can work with it. A technician whose role covers none of the sites in a profile's scope does not see that profile at all.
How it works
Whether a technician can see and edit a profile depends on two settings:
- The profile's customer scope - The customers included in the profile's scope. You set this on the profile.
- The technician's role scope - The customers the technician can manage. This is determined by their role.
The technician's level of access depends on how much of the profile's scope their role covers:
- If their role covers every customer in the profile's scope, they can edit the profile.
- If their role covers some, but not all, of the customers, they can open the profile in read-only mode. A callout explains why editing is disabled.
- If their role does not cover any of the customers, the profile does not appear in their list.
A profile scoped to all customers can be edited by any technician with the required permissions, regardless of their role scope: admins can edit threshold profiles, while technicians with patch management permissions can edit automation profiles.
- The profile's site scope - The sites included in the profile's scope. You set this on the profile.
- The technician's role scope - The sites the technician can manage. This is determined by their role.
The technician's level of access depends on how much of the profile's scope their role covers:
- If their role covers every site in the profile's scope, they can edit the profile.
- If their role covers some, but not all, of the sites, they can open the profile in read-only mode. A callout explains why editing is disabled.
- If their role does not cover any of the sites, the profile does not appear in their list.
A profile scoped to all sites can be edited by any technician with the required permissions, regardless of their role scope: admins can edit threshold profiles, while technicians with patch management permissions can edit automation profiles.
Scope is not assignment. Customer scope controls who can view and access the profile. Assignment controls where its thresholds apply, and opens from Manage assignment. To change which devices a profile applies to, update its assignment rather than its scope.
Before you begin
Important: Before a profile's scope has any effect, the technician's role must already be limited to specific customers under Admin > Users and security > Access roles. Scoping a profile does nothing on its own.
Important: Before a profile's scope has any effect, the technician's role must already be limited to specific sites under Admin > Users and security > Access roles. Scoping a profile does nothing on its own.
Check the role before you scope the profile: open the technician's role under Admin > Users and security > Access roles and note which customers the Customers access tab covers. A technician can only edit a profile whose scope sits entirely inside their role scope.
Check the role before you scope the profile: open the technician's role under Admin > Users and security > Access roles and note which sites the Customers access tab covers. A technician can only edit a profile whose scope sits entirely inside their role scope.
Scope is available in the new experience, and applies to automation profiles and threshold profiles.
Set a profile's scope
For automation profiles
- Go to Admin > Monitoring and automation > Patch management and IT automation and select the automation profile you want to scope.
- Open the Configuration tab. In the Profile settings menu on the left, you'll see the Customer scope setting, showing a counter and a Full, Partial or None label - for example, Customer scope (17/23) Partial. Click Manage to open the Customer scope dialog.
- A new profile starts scoped to every customer, shown as Full. To narrow it, tick the ones you want to exclude in the Scoped customers list and click Remove selected. To widen it again, pick them in Select scoped customers and click Add.
- Click Save in the dialog, then Save on the profile.
For threshold profiles
- Go to Admin > Monitoring and automation > Thresholds and select the threshold profile you want to scope.
- In the Settings panel on the left, you'll see the Customer scope setting, showing a counter and a Full, Partial or None label - for example, Customer scope (17/23) Partial. Click Manage to open the Customer scope dialog.
- A new profile starts scoped to every customer, shown as Full. To narrow it, tick the ones you want to exclude in the Scoped customers list and click Remove selected. To widen it again, pick them in Select scoped customers and click Add.
- Click Save in the dialog, then Save on the profile.
Once saved, technicians whose role scope covers every customer in the profile's scope can edit it. Technicians whose role covers only some of them see the profile in read-only mode, and technicians whose role covers none of them do not see it at all.
Once saved, technicians whose role scope covers every site in the profile's scope can edit it. Technicians whose role covers only some of them see the profile in read-only mode, and technicians whose role covers none of them do not see it at all.
Default profile
Scoped to everything is the default. A new profile covers all customers, so any technician whose permissions allow it can edit it, whatever their role scope. Narrowing the scope is the exception, not the starting point.
Scoped to everything is the default. A new profile covers all sites, so any technician whose permissions allow it can edit it, whatever their role scope. Narrowing the scope is the exception, not the starting point.
Automation and threshold profiles are scoped separately. Every profile carries its own scope. Scoping a threshold profile does not scope your automation profiles, even for the same customers - set the scope on each profile you want to narrow.
Automation and threshold profiles are scoped separately. Every profile carries its own scope. Scoping a threshold profile does not scope your automation profiles, even for the same sites - set the scope on each profile you want to narrow.
Related articles
- Roles and permissions
- Automate patch management via IT automation profiles
- Manage alert threshold profiles