You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: Cloudflare CASB adds two new granular roles, CASB Read and CASB, for more precise user access control.
4
+
products:
5
+
- casb
6
+
date: 2025-10-28
7
+
---
8
+
9
+
Cloudflare CASB (Cloud Access Security Broker) now supports two new granular roles to provide more precise access control for your security teams:
10
+
11
+
***Cloudflare CASB Read:** Provides read-only access to view CASB findings and dashboards. This role is ideal for security analysts, compliance auditors, or team members who need visibility without modification rights.
12
+
***Cloudflare CASB:** Provides full administrative access to configure and manage all aspects of the CASB product.
13
+
14
+
These new roles help you better enforce the principle of least privilege. You can now grant specific members access to CASB security findings without assigning them broader permissions, such as the **Super Administrator** or **Administrator** roles.
15
+
16
+
To enable [Data Loss Prevention (DLP)](/cloudflare-one/data-loss-prevention/dlp-profiles/), scans in CASB, account members will need the **Cloudflare Zero Trust** role.
17
+
18
+
You can find these new roles when inviting members or creating API tokens in the Cloudflare dashboard under **Manage Account** > **Members**.
19
+
20
+
To learn more about managing roles and permissions, refer to the [Manage account members and roles documentation](/fundamentals/manage-members/roles/).
Copy file name to clipboardExpand all lines: src/content/docs/cloudflare-one/roles-permissions.mdx
+12-10Lines changed: 12 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,16 +15,18 @@ To check the list of members in your account, or to manage roles and permissions
15
15
16
16
Only Super Administrators will be able to assign or remove the following roles from users in their account. Scroll to the right to see a full list of permissions for each role.
[^1]: The **Cloudflare Zero Trust** role grants administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security.
0 commit comments