Creating Custom Email User Roles

You can create custom email user roles for access to Email Reporting, Message Tracking, and quarantines.

For descriptions of the access that each of these options permits, see About Custom Email User Roles and its subsections.

Note
To grant more granular access or access to other features, reports, or policies, create custom user roles directly on each Email Security appliance.

Procedure


Step 1

[New Web Interface Only] On the Security Management appliance, click to load the legacy web interface.

Step 2

Choose Management Appliance > System Administration > User Roles.

Step 3

Click Add Email User Role.

Tip

Alternatively, you can create a new role by duplicating an existing Email User Role: Click the Duplicate icon in the applicable table row, then modify the resulting copy.

Step 4

Enter a unique name for the user role (for example, “dlp-auditor”) and a description.

  • Email and Web custom user role names must not be duplicated.

  • The name must contain only lowercase letters, numbers, and dashes. It cannot start with a dash or a number.

  • If you grant users with this role access to centralized policy quarantines, and you also want users with this role to be able to specify those centralized quarantines in message and content filters and DLP Message Actions on an Email Security appliance, the name of the custom role must be the same on both appliances.

Step 5

Choose the access privileges to enable for this role.

Administrators can create custom roles with read-only option for Quarantine messages. The read-only option prevents users from deleting or releasing messages and only have read-only access to quarantine.

Step 6

Click Submit to return to the User Roles page, which lists the new user role.

Step 7

If you limited access by Reporting Group, click the no groups selected link in the Email Reporting column for the user role, then choose at least one Reporting Group.

Step 8

Commit your changes.

Step 9

If you granted this role access to quarantines, enable access for this role: