Description
Custom User Levels now include Workflows with read-only access split into two views: Workflows Viewer for configuration and Workflow Auditor for configuration plus execution history. Identity Security Cloud admins can assign either level so users can inspect workflows without create, edit, test, or execute rights.
What You Need to Know
-
Read-only Workflows access is split into two views: Workflows Viewer and Workflows Auditor.
-
Both views are strictly read-only. Users can view and download, but cannot create, edit, save, duplicate, test, enable/disable, delete, change owner, upload scripts, or use Config Hub import/export.
-
Assignment is optional. Existing Org Admin and full Workflows access is unchanged.
-
Workflows Viewer can open Admin > Workflows, use search and filters in the manager page, view details, open View in Builder, and Download Script. They cannot see the Executions tab or Identity Security Cloud Search workflow history.
-
Workflow Auditor includes the Viewer view plus the Executions tab (playback and CSV, JSON, and script downloads) and Identity Security Cloud Search workflow history. They still cannot cancel executions or change workflows.
Problem
Today, anyone who needs to inspect a workflow requires admin access. This over-privileges operators, support, and audit teams who only need read-only access to configuration or executions.
Solution
-
Two read-only views: Workflows Viewer for configuration; Workflow Auditor adds execution history for audit.
-
Strictly read-only: Both views grant visibility without write, test, or execute permissions.
-
Assign in Custom User Levels: Pick the view that matches what each user needs.
Who is affected?
Identity Security Cloud admins who assign Custom User Levels, plus operators, support, and audit users who need read-only Workflows access.
Action required: None.
Important dates
-
Sandbox (STG):
- Aug 26, 2026
- Aug 31, 2026
-
Production:
- Sep 2, 2026
- Sep 7, 2026
- Sep 9, 2026
