Entitle roles | Entitle

Assign each person in your org exactly the level of Entitle access their job needs — from full administrative control to a scoped view of their own team, without giving everyone the same all-or-nothing admin rights. Roles can be assigned to IdP groups, not just individual users, so a role stays current automatically as group membership changes.

See Grant Entitle roles once you've decided who needs which role.

Entitle has five roles:

  • User: requests access and responds to approvals for themselves.
  • Manager: everything a User can do, plus management of their direct reports' access and requests.
  • Integration admin: admin control only to the integrations they own.
  • Read-only admin: can see everything an Admin can see across the organization, but can't create, edit, or delete anything.
  • Admin : full control over the entire organization.

Compare roles at a glance

CapabilityUserManagerRead-only adminIntegration adminAdmin
Access requestsRequest access and respond to approvals for themselvesAlso view and act on behalf of their direct reportsView all requests org-wideView and manage requests for their owned integrationsConfigure how access is granted and who approves it, org-wide
PermissionsView their own permissionsView their direct reports' permissionsView all permissions org-wideView and revoke permissions for their owned integrationsReview and revoke permissions for all users, org-wide
IntegrationsRequest access to integrated resourcesSame as UserView all integrations, read-onlyManage settings, resources, roles, and rules for owned integrationsAdd, configure, and manage all integrations
Approval workflows & policiesUse workflows and policies set by adminsSame as UserView all workflows and birthright policiesNo accessCreate, edit, and manage all workflows and policies
BundlesRequest bundlesSame as UserView all bundlesNo accessCreate and manage all bundles
User managementManage their own profileView their direct reportsView the full user list, read-onlyNo accessAdd or remove admins, manage all users
Org settings & audit logsNo accessNo accessView org settings and audit logs, read-onlyView settings for owned integrations onlyFull control over org settings and audit logs

User

The default role for anyone who needs to request and use access, without administering Entitle itself.

A User can:

  • Request just-in-time access to applications and resources, including on behalf of other users.
  • Respond to access requests they're an approver for.
  • Track their own past and current access requests.
  • View the permissions they currently hold.
  • Request to renew permissions that have expired or are expiring soon.
  • Request bundles, the same way they'd request any other resource.
  • Use Entitle through the web app, Slack, or Microsoft Teams.

Manager

Everything a User can do, plus read-only visibility into their direct reports.

A Manager can additionally:

  • View permissions and requests for their direct reports, in addition to their own.
  • Request access on behalf of their direct reports.
  • Revoke permissions from their direct reports.
  • Filter Users, Permissions, and Requests history to their team.

A Manager doesn't get access to integrations, workflows, policies, or org-wide settings — their added visibility is limited to the people who report to them.

Read-only admin

Full visibility into everything an Admin can see across the organization, with no ability to make changes.

A Read-only admin can:

  • View all integrations, resources, roles, and rules, without editing or creating them.
  • View all approval workflows and birthright policies.
  • View all bundles.
  • View the full list of users and their permissions, org-wide.
  • View org settings and audit logs.

A Read-only admin can't create, edit, or delete anything — no adding integrations, changing workflows, revoking permissions, or managing users. This role fits an auditor, or anyone who needs full visibility for oversight without the ability to change configuration.

Integration admin

Full admin control, scoped to only the integrations they own.

An Integration admin can:

  • Manage settings, resources, and roles for their owned integrations.
  • View and revoke permissions tied to their owned integrations.
  • Sync and troubleshoot their owned integrations.

An Integration admin has no visibility into integrations they don't own, and no access to org-wide settings, workflows, policies, bundles, or user management. This role fits a team or application owner who should manage their own integration without needing full admin rights.

Admin

Full control over the entire Entitle organization.

An Admin can:

  • Configure how access is granted and who approves requests, org-wide.
  • Add, configure, and manage all integrations.
  • Create, edit, and manage all approval workflows, birthright policies, rules, and bundles.
  • Review and revoke permissions for any user in the organization.
  • Add or remove other admins, and manage all users.
  • Configure org settings, including audit log webhooks, API tokens, and allowed request durations.

Ownership and maintenance capabilities

Separate from the roles above, Integration Owner, Integration Maintainer, Resource Owner, and Resource Maintainer can be assigned to any user — Admin or not. These control ownership and delegated maintenance of a specific integration or resource rather than granting broader Entitle access:

  • Integration Owner — the designated owner of an integration, used for approval workflows and administrative purposes. For bundles, this includes the owner of each integration.
  • Integration Maintainer — a secondary administrator of an integration, supporting access and permission management. Can include IdP groups.
  • Resource Owner — the designated owner of a resource. For bundles, this includes the owner of each resource.
  • Resource Maintainer — secondary ownership of a resource, supporting access and permission management. Can include IdP groups.

Did this page help you?

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.