PAM360 serves as a repository for sensitive accounts and passwords, ensuring preliminary access control through user roles. Access to the PAM360 application is contingent upon possessing a specific role, which dictates the scope of privileged operations a user can perform. This fine-grained access control mechanism safeguards data from unauthorized access directly through the PAM360 interface, facilitated by role-based access control.
User roles within PAM360 delineate the operations permissible for each user. Regardless of the role assigned, managing personal passwords in PAM360 remains exclusive to individual users, subject to administrator-enabled settings, with other users having no authority over them.
At the end of this help document, you will learn about the following topics relevant PAM360 user roles.
The various user roles in PAM360 dictate the extent of operations a user can undertake:
PAM360 User Roles | User Operations in PAM360 | ||||||||
Manage Users | Manage Resources and Accounts | Access Account Passwords and Manage Personal Passwords | Access Audit and Reports | Privacy and Security Controls | Remote Access | Secure File Transfer, HTTPS Gateway Server, and RemoteApp Access | Cloud Entitlements Management | ||
Privileged Administrator | |||||||||
Cloud Administrator | |||||||||
Administrator | |||||||||
Password Administrator | |||||||||
Password Auditor | |||||||||
Password User | |||||||||
Connection User | |||||||||
The allocation of these roles to the users ensures that access to sensitive data within PAM360 is tightly controlled, minimizing the risk of unauthorized access or misuse.
Additional Details
An Administrator/Password Administrator/Privileged Administrator can be made as a Super Administrator. A super administrator will have the privilege to manage all the resources stored in PAM360, irrespective of the resource owner. For security reasons, a user with the administrator privilege can be made a super administrator only by other PAM360 administrators. For steps on how to create a super administrator role, click here.
Apart from the above-predefined roles in PAM360, administrators have the flexibility to create custom roles tailored to their organization's specific requirements. This customization feature empowers administrators to design roles from scratch, selecting from over 100+ available operations within PAM360. To ensure an added layer of security, the creation of custom roles follows a dual-control mechanism, mandating approval from another administrator. Follow these steps to add a new custom role:

Caution
While creating a custom user role, ensure that you select the operations for the role as required. The operations with the magic wand icon beside is of administrator privilege. Selecting those operations for a custom role consider it in the administrator category and creating the user accounts with this user role might affect your PAM360 license counts.
For example,
1. If you like to create a role for the sole purpose of user administration, such as new user addition in PAM360, edit/delete user profiles, change roles, and transfer resources between users, here are the basic operations that should be selected from the User module:
Users | User Authentication Protocols | User Groups |
|
|
|
2. If you like to create a role for a junior technicians who maintains a handful of resources in your organization, a role with the following operations is required:
Resource | Accounts | Password Reset | |
Users |
|
|
|
Remote Access |
| ||
Custom Settings |
| ||
Follow these steps to edit a custom role:
To edit a custom role, click the Edit icon next to the respective role, make necessary modifications, and click Preview and Save. Verify the modifications once and click Save. The edits undergo an approval process by another administrator before implementation. Edits pending for approval will be shown with the status [Waiting for approval] beside the specific role. In the below image, red denotes operations that have been removed in the edit, and blue denotes operations that have been added to the role.
Follow these steps to delete a custom role:
Click the Delete icon beside the respective role and Delete the custom role. If you have users mapped with the custom role, the dialogue-box which opens prompts to transfer associated users to another role before deletion. Once users are mapped to a new role, click Transfer users and delete role to proceed with the role deletion.
This meticulous approach to role management in PAM360 ensures tailored access control aligned with organizational needs, maintaining security and operational efficiency.
The role filter feature enables administrators to streamline role assignment by specifying which roles should be visible under the Role field in the Add User window. To enable role filtering:


Administrators can efficiently update roles for individual users or multiple users in bulk. To do so,

1. What does the magic wand icon signify next to certain operations?
Operations accompanied by a magic wand icon indicate Administrator-level operations. If a custom role includes any of these wand-marked operations, it is treated akin to an Administrator role. You can create multiple custom roles with such operations, but the role only counts towards the license when assigned to a user in PAM360. For example, if your licensing permits 10 administrators and you assign a custom role with wand-marked operations to a user, it consumes one of the 10 allotted licenses.
2. Who has the authority to create custom roles in PAM360?
Creating custom roles is primarily an administrative task. Only Administrators, Privileged Administrators, and Super Administrators (if created) possess the privilege to create custom roles. Additionally, you can authorize a custom role to create future custom roles by enabling the Create Custom Roles option under Custom Settings. Moreover, enabling the Enable Super Admin capabilities for this role checkbox allows users assigned this role to be promoted to Super Administrator during user creation. After configuring the role settings, clicking on Preview and Save initiates a preview listing the chosen operations, and a further Save will create the role and queue it for pending approval from another administrator. Once approved, the role can be assigned to users accordingly.
3. Why am I unable to delete a custom role?
There are two scenarios where a role cannot be deleted immediately: