Skip to main content

Configure Roles & Permissions

Robopack supports granular role-based access control so you can give each team member exactly the permissions they need — no more, no less.

What you'll need

  • Organisation Administrator or Security Writer permissions in Robopack

Step-by-Step Guide

1. Plan your access model

TeamRecommended roles
IT adminsOrganisation Administrator (full access)
Packaging teamPackage Writer + Robopatch Writer
Read-only stakeholdersPackage Reader + Robopatch Reader
Security / complianceSecurity Reader

2. Assign roles in Robopack

Go to Settings > Users, click on a user, select their roles, and save.

3. Assign roles via Entra ID (optional)

For larger organisations, you can assign roles through Entra ID enterprise application group membership:

  1. Go to Entra Portal > Enterprise Applications > Robopack > Users and Groups
  2. Assign users or security groups to the appropriate roles
tip

Using Entra ID security groups means new team members automatically get the right permissions when they're added to the group.

4. Configure per-tenant permissions

If you manage multiple tenants, you can scope permissions per tenant in Settings > Tenants:

PermissionControls
See / Read informationWho can view apps and settings for this tenant
Upload appsWho can import packages to this tenant
Set configurationWho can modify tenant settings
Set permissionsWho can manage access control for this tenant

Access can be granted to all users, specific users, or an Entra ID security group.

5. Set sign-in policy

PolicyUse case
Allow both Entra ID and password sign-insMaximum flexibility
Only allow Entra ID sign-insRecommended for security
Only allow password sign-insFor organisations not using Entra ID
warning

Before switching to Entra ID-only sign-ins, ensure all users who need access are already signing in with Entra ID.

6. Enable two-factor authentication (optional)

For accounts using password sign-in, you can enable 2FA:

  • Per-user: Go to Settings > Account and set up an authenticator app (Microsoft Authenticator, Google Authenticator, etc.)
  • Organisation-wide: Go to Settings > Account > Organisation Settings to require 2FA for all password logins

What's next?