Skip to content

Role Inventory

Auto-generated from the Terraform output globalaccount_metadata - do not edit by hand. Regenerate with make docs (SPEC-TF-004; ADR-TF-008 / ADR-TF-009).

Flat inventory of all roles in the Global Account, as reported by btp_globalaccount_roles (SPEC-TF-003 v2, ADR-TF-006). Roles contained in role collections are also shown on the Roles & Role Collections page; this page lists every role exactly once.

Total roles: 13

Role Role template App ID Read-only
Auditlog_Auditor Auditlog_Auditor auditlog-management!b6316 true
Auditlog_Auditor Auditlog_Auditor auditlog-viewer-initial-content!t6316 true
Directory Admin Directory_Admin cis-central!b14 true
Directory Usage Reporting Viewer Directory_Usage_Reporting_Viewer uas!b36585 true
Directory Viewer Directory_Viewer cis-central!b14 true
Global Account Admin GlobalAccount_Admin cis-central!b14 true
Global Account Usage Reporting Viewer GlobalAccount_Usage_Reporting_Viewer uas!b36585 true
Global Account Viewer GlobalAccount_Viewer cis-central!b14 true
Subaccount System Landscape Administrator Subaccount_System_Landscape_Administrator cmp!b70961 true
System Landscape Administrator GlobalAccount_System_Landscape_Administrator cmp!b70961 true
System Landscape Viewer GlobalAccount_System_Landscape_Viewer cmp!b70961 true
User and Role Administrator xsuaa_admin xsuaa!t1 true
User and Role Auditor xsuaa_auditor xsuaa!t1 true

Scopes

  • Auditlog_Auditor (Auditlog_Auditor)
  • auditlog-management!b6316.ReadAuditLogs - View audit logs
  • Auditlog_Auditor (Auditlog_Auditor)
  • auditlog-viewer-initial-content!t6316.ReadAuditLogs - View audit logs
  • uaa.user - Default scope for user
  • Directory Admin (Directory_Admin)
  • cis-central!b14.account-automation-request.read - Get Cloud Automation requests in a global account
  • cis-central!b14.account-automation-request.update - Manage Cloud Automation requests to execute solutions in a global account
  • cis-central!b14.catalog.product.delete - Delete a product from the products catalog for the current global account
  • cis-central!b14.catalog.product.update - Update a product in the products catalog for the current global account
  • cis-central!b14.directory.entitlement.read - Get directory entitlements
  • cis-central!b14.directory.entitlement.update - Update directory entitlements
  • cis-central!b14.global-account.account-directory.create - Create an account directory entity
  • cis-central!b14.global-account.account-directory.delete - Delete an account directory entity
  • cis-central!b14.global-account.account-directory.read - Get account directory entities
  • cis-central!b14.global-account.account-directory.update - Update an account directory entity
  • cis-central!b14.global-account.entitlement.read - Get assignments of service plans and entitlement definitions
  • cis-central!b14.global-account.entitlement.subaccount.update - Update assigned entitlements to subaccount
  • cis-central!b14.global-account.read - Get global account entities
  • cis-central!b14.global-account.region.read - Get available regions
  • cis-central!b14.global-account.subaccount.create - Create subaccount entity
  • cis-central!b14.global-account.subaccount.delete - Delete subaccount entity
  • cis-central!b14.global-account.subaccount.read - Get subaccount entities
  • cis-central!b14.global-account.subaccount.update - Update subaccount entity
  • cis-central!b14.global-account.update - Update global account entity
  • cis-central!b14.job.read - Get statuses for jobs
  • xs_account.access - Enable account navigation
  • Directory Usage Reporting Viewer (Directory_Usage_Reporting_Viewer)
  • uas!b36585.UAS.reporting.directory.read
  • xs_account.access - Enable account navigation
  • Directory Viewer (Directory_Viewer)
  • cis-central!b14.global-account.account-directory.read - Get account directory entities
  • cis-central!b14.global-account.entitlement.read - Get assignments of service plans and entitlement definitions
  • cis-central!b14.global-account.read - Get global account entities
  • cis-central!b14.global-account.region.read - Get available regions
  • cis-central!b14.global-account.subaccount.read - Get subaccount entities
  • cis-central!b14.job.read - Get statuses for jobs
  • xs_account.access - Enable account navigation
  • Global Account Admin (GlobalAccount_Admin)
  • cis-central!b14.account-automation-request.read - Get Cloud Automation requests in a global account
  • cis-central!b14.account-automation-request.update - Manage Cloud Automation requests to execute solutions in a global account
  • cis-central!b14.account-budget.create - Create a cost management budget for the global account.
  • cis-central!b14.account-budget.delete - Delete a cost management budget from a global account.
  • cis-central!b14.account-budget.read - Get the cost management budgets in a global account.
  • cis-central!b14.account-budget.update - Update a cost management budget in a global account.
  • cis-central!b14.catalog.product.delete - Delete a product from the products catalog for the current global account
  • cis-central!b14.catalog.product.update - Update a product in the products catalog for the current global account
  • cis-central!b14.directory.entitlement.read - Get directory entitlements
  • cis-central!b14.directory.entitlement.update - Update directory entitlements
  • cis-central!b14.event.read - Get cloud management events on the central region
  • cis-central!b14.global-account.account-context.read - Get the account context of a specified entity for a specific global account.
  • cis-central!b14.global-account.account-directory.create - Create an account directory entity
  • cis-central!b14.global-account.account-directory.delete - Delete an account directory entity
  • cis-central!b14.global-account.account-directory.read - Get account directory entities
  • cis-central!b14.global-account.account-directory.update - Update an account directory entity
  • cis-central!b14.global-account.entitlement.read - Get assignments of service plans and entitlement definitions
  • cis-central!b14.global-account.entitlement.subaccount.update - Update assigned entitlements to subaccount
  • cis-central!b14.global-account.read - Get global account entities
  • cis-central!b14.global-account.region.read - Get available regions
  • cis-central!b14.global-account.subaccount.create - Create subaccount entity
  • cis-central!b14.global-account.subaccount.delete - Delete subaccount entity
  • cis-central!b14.global-account.subaccount.read - Get subaccount entities
  • cis-central!b14.global-account.subaccount.update - Update subaccount entity
  • cis-central!b14.global-account.update - Update global account entity
  • cis-central!b14.job.read - Get statuses for jobs
  • xs_account.access - Enable account navigation
  • Global Account Usage Reporting Viewer (GlobalAccount_Usage_Reporting_Viewer)
  • uas!b36585.UAS.reporting.GA_Admin
  • xs_account.access - Enable account navigation
  • Global Account Viewer (GlobalAccount_Viewer)
  • cis-central!b14.account-budget.read - Get the cost management budgets in a global account.
  • cis-central!b14.directory.entitlement.read - Get directory entitlements
  • cis-central!b14.event.read - Get cloud management events on the central region
  • cis-central!b14.global-account.account-context.read - Get the account context of a specified entity for a specific global account.
  • cis-central!b14.global-account.account-directory.read - Get account directory entities
  • cis-central!b14.global-account.entitlement.read - Get assignments of service plans and entitlement definitions
  • cis-central!b14.global-account.read - Get global account entities
  • cis-central!b14.global-account.region.read - Get available regions
  • cis-central!b14.global-account.subaccount.read - Get subaccount entities
  • cis-central!b14.job.read - Get statuses for jobs
  • xs_account.access - Enable account navigation
  • Subaccount System Landscape Administrator (Subaccount_System_Landscape_Administrator)
  • xs_account.access - Enable account navigation
  • System Landscape Administrator (GlobalAccount_System_Landscape_Administrator)
  • cmp!b70961.application.application_template:read - Read application application template
  • cmp!b70961.application.auths:read - Read application auths
  • cmp!b70961.application.webhooks:read - Read application webhooks
  • cmp!b70961.application:read - Read applications
  • cmp!b70961.application:sync - Sync applications
  • cmp!b70961.application:write - Register and update applications
  • cmp!b70961.application_template.webhooks:read - Read application templates webhooks
  • cmp!b70961.application_template:read - Read application templates
  • cmp!b70961.automatic_scenario_assignment:read - Read automatic scenario assignments
  • cmp!b70961.automatic_scenario_assignment:write - Register and update automatic scenario assignments
  • cmp!b70961.bundle.instance_auths:read - Read consumption bundle auths
  • cmp!b70961.consent.scopes:read - Read consent scopes
  • cmp!b70961.consent.state:write - Approve or reject consents
  • cmp!b70961.consent:read - Read consents
  • cmp!b70961.consent:write - Create consents
  • cmp!b70961.facilitator_template:read - Read facilitator templates
  • cmp!b70961.formation.state:write - Write formations providing value for state
  • cmp!b70961.formation:read - Read formations
  • cmp!b70961.formation:write - Write formations
  • cmp!b70961.formation_template:read - Read formation templates
  • cmp!b70961.formation_template:write - Write formation templates
  • cmp!b70961.integration_edge_template:read - Read integration edge templates
  • cmp!b70961.integration_edge_template:write - Modify integration edge templates
  • cmp!b70961.operation:read - Read operations
  • cmp!b70961.operation:schedule - Reschedule existing operations
  • cmp!b70961.product:delete - Delete products
  • cmp!b70961.product:read - Read products
  • cmp!b70961.product:write - Write products
  • cmp!b70961.runtime:read - Read runtimes and runtime contexts
  • cmp!b70961.system_template_default:read - Read default system templates
  • cmp!b70961.tenant_registry:read - Read tenant registry and its sub entities: system templates, input json schema,...
  • cmp!b70961.tenant_set.webhooks:read - Read tenant set webhooks
  • cmp!b70961.tenant_set:read - Read products
  • cmp!b70961.tenant_set:write - Create/Edit tenant sets
  • cmp!b70961.webhook:write - Write application webhooks
  • xs_account.access - Enable account navigation
  • System Landscape Viewer (GlobalAccount_System_Landscape_Viewer)
  • cmp!b70961.application.application_template:read - Read application application template
  • cmp!b70961.application.auths:read - Read application auths
  • cmp!b70961.application.webhooks:read - Read application webhooks
  • cmp!b70961.application:read - Read applications
  • cmp!b70961.application_template.webhooks:read - Read application templates webhooks
  • cmp!b70961.application_template:read - Read application templates
  • cmp!b70961.automatic_scenario_assignment:read - Read automatic scenario assignments
  • cmp!b70961.bundle.instance_auths:read - Read consumption bundle auths
  • cmp!b70961.consent:read - Read consents
  • cmp!b70961.facilitator_template:read - Read facilitator templates
  • cmp!b70961.formation:read - Read formations
  • cmp!b70961.formation_template:read - Read formation templates
  • cmp!b70961.integration_edge_template:read - Read integration edge templates
  • cmp!b70961.operation:read - Read operations
  • cmp!b70961.product:read - Read products
  • cmp!b70961.runtime:read - Read runtimes and runtime contexts
  • cmp!b70961.tenant_registry:read - Read tenant registry and its sub entities: system templates, input json schema,...
  • cmp!b70961.tenant_set.webhooks:read - Read tenant set webhooks
  • cmp!b70961.tenant_set:read - Read products
  • xs_account.access - Enable account navigation
  • User and Role Administrator (xsuaa_admin)
  • xs_account.access - Enable account navigation
  • xs_apicredential.read - Read api credentials
  • xs_apicredential.write - Change api credentials
  • xs_authorization.read - Read permission for XS roles and role collections
  • xs_authorization.write - Write permission for XS roles and role collections
  • xs_idp.read - List Identity Providers
  • xs_idp.write - Change Identity Providers
  • xs_user.read - Read permission for XS users
  • xs_user.write - Write permission for XS users
  • User and Role Auditor (xsuaa_auditor)
  • xs_account.access - Enable account navigation
  • xs_apicredential.read - Read api credentials
  • xs_authorization.read - Read permission for XS roles and role collections
  • xs_idp.read - List Identity Providers
  • xs_user.read - Read permission for XS users

Generated from the Terraform output globalaccount_metadata (SPEC-TF-004). Global Account 24767a6d-72de-4bb7-8d44-221f3286a7e7 - subdomain vinehousesolutionsltd - generated 2026-10-02T21:34:30Z (UTC).