Skip to main content

Platform | Environment Group Permissions and User Role Management

Updated yesterday

Overview πŸ’₯

Liongard has modernized its user permissions and access management model to simplify administration, improve security, and provide more granular control over environment access.

This update consolidates legacy permissions into five clearly defined roles and introduces Environment Groups as the primary mechanism for scoping access.

This article explains:

  • The current user role model

  • How environment scoping works

  • How Environment Groups are used

  • What changed during the migration

  • Best practices for managing users going forward


Why This Change Was Introduced πŸ€”

The previous permissions model relied on multiple overlapping role types and environment assignments, which could become difficult to manage at scale.

The updated model was designed to:

  • βœ… Reduce role complexity

  • πŸ” Improve security through least-privilege access

  • 🧩 Simplify environment access using logical groupings

  • βš™οΈ Make ongoing user maintenance easier and safer


Liongard User Permission Roles 🌟

Liongard roles define what actions a user can perform, while environment scope defines where those actions apply.

🌍 Environment Scope Types

Scope Type

Description

Global

Access to all environments across the platform

Configurable

Access limited to assigned environments or Environment Groups

None

No environment access

πŸ§‘β€πŸ’Ό Available User Roles

Role

Environment Scope

Capabilities

Admin

Global

  • Full read/write access to all platform features

System Integration

Global

  • Read/write access to agents, inspectors, integrations

  • Read access to environments, alerts, metrics, and reports

Manager

Configurable

  • Read/write access to agents, inspectors, environments, alerts, metrics, and reports for assigned environments

Reader

Configurable

  • Read access to platform data; may create and edit reports for assigned environments

User Admin

None

  • Read/write access to user management only

πŸ“ Note
User Admins cannot access environments, inspectors, integrations, or metrics.


Environment Groups Explained πŸ§‘β€πŸ«

Environment Groups allow administrators to logically group environments and assign access at scale.

πŸ” Why Use Environment Groups?

  • Organize environments by customer, region, department, or team

  • Grant access to multiple environments at once

  • Reduce ongoing administrative overhead

πŸ“Œ Common Use Case

  • A service desk team is segmented by territory.

  • Each team should only see customers in their assigned region.

  • Environment Groups make this possible without manual per-environment assignments.


Default Environment Groups πŸš€

Every Liongard instance includes two built-in groups:

Group Name

Description

All Environments

Includes all environments, including your internal company

All Managed Environments

Includes all customer environments, excluding your internal company


Migration Impact for Existing Partners πŸ‘€

Liongard automatically migrated existing users to the new model. No action was required from partners during migration.

πŸ” Role Mapping During Migration

Previous Role

New Role

Notes

Global Reader / Environment Reader

Reader

Scoped to previously assigned environments

Global Environment Manager / Environment Manager

Manager

Scoped to previously assigned environments

Global Admin

Admin

Assigned to All Environments

Global Systems Integrator

System Integration

Assigned to All Environments

User Administrator

User Admin

No change

⚠️ Important
The migration did not create custom Environment Groups beyond the two defaults.


How to Add a User in Liongard 🧐

  1. Navigate to Admin β†’ Access Management β†’ Users

  2. Select Add User

  3. Complete the required fields:

    • First Name

    • Last Name

    • Username

    • Email Address

    • Department

  4. (Optional) Enable Technical Update Emails

  5. Configure Multi-Factor Authentication (MFA) (recommended)

  6. Assign one or more Roles

  7. Assign Environments or Environment Groups (for Manager and Reader roles)

  8. Click Save

πŸ“§ The user will receive an invitation email from roarbot@liongard.com.


Enforcing Global Multi-Factor Authentication (MFA) πŸ”

To enforce MFA for all users:

  1. Click your username

  2. Navigate to Company Settings β†’ Security

  3. Enable Multi-Factor Authentication

βœ… MFA is strongly recommended for all Liongard accounts.


Individual User Maintenance πŸ‘¨β€πŸ”§

From Admin β†’ Access Management β†’ Users, select a user to manage:

Action

Description

Force Logout

Immediately signs the user out

Reset Password

Sends password reset

Reset MFA

Prompts user to reconfigure MFA

Disable Account

Temporarily blocks access

Delete User

Permanently removes account


Bulk User Maintenance πŸ‘₯

Administrators can perform actions on multiple users at once:

  • Activate or deactivate users

  • Reset passwords

  • Force logout

  • Reset MFA

  • Delete accounts

πŸ“ Available via the Users page using the bulk selector and Actions menu.


When to Contact Liongard Support 🦁

Contact Liongard Support if:

  • Users cannot access expected environments after migration

  • Roles or permissions appear incorrect

  • MFA or login issues persist after reset

  • You need guidance on Environment Group design

Did this answer your question?