SonicWall Unified Management Administration Guide

Table of Contents

Inventory Roles and Privileges

Inventory Dashboard & Table View (All Products & Subscriptions) depends on the access levels defined in the User Groups.

Access depends on User Group permissions (Tenant Access + Product Access + Platform Operations). When a user belongs to multiple groups, the least‑permissive rule applies.

Least‑permissive Rule Examples

  • Tenant Hidden

    Default Group: Tenant Access = Admin+ Group A: Tenant Access = No Access

    Outcome: The user cannot see tenants from Group A because No Access overrides Admin.

  • Product Access Becomes Read‑Only

    Group A: Tenant Access = Admin, Firewalls = Admin + Group B: Tenant Access = Admin, Firewalls = No Access

    Outcome: User sees all tenants, but firewall products are read‑only because No Access is the most restrictive.

  • Tenant Completely Hidden Despite Product Access

    Tenant Access = No Access+ Product Access = Admin

    Outcome: The tenant does not appear at all. Without Tenant Access, Product Access cannot grant visibility.

Action Privileges Conditions / Examples
Provision an MSP Only the Super Admin of the Master MSP account can provision an MSP.
Provision/Register Products (Annual & Monthly) Super Admins, Admins, and Employees with the required User Access + Tenant Access can provision or register products. Employees with Read‑Only can view but cannot act. Employees with No Access cannot view the option.
Convert Annual Product to Monthly Subscription Super Admins and Admins can convert annual billing products into monthly subscriptions.
Enable or Disable Cloud Management Super Admins and Admins can turn cloud management on or off for a product.
Remove a Product from Monthly Subscription Super Admins and Admins can remove products from monthly subscription plans.
Delete Products (Annual & Monthly) Super Admins and Admins can permanently delete products.