Configure Environment-scoped Permissions

Environment-scoped permissions add an Environment scope to permissions. Use this feature when you need users to have different permissions across different Environments.

Plan the rollout

List the users and automation identities that require Test, intermediate, and Production access. Review design, Connection-value, API-key user, release, status, logs, and operational responsibilities separately.

Environment access does not grant an action by itself; the user's Site role or Security Group must also permit that action.

Enable the feature

  1. Open SettingsSite settings.
  2. Enable Environment-scoped permissions enabled.
  3. Click Save changes.

Console grants the enabling administrator access to all current Environments so the rollout can be completed.

Assign users

  1. Open SettingsSite users.
  2. Open a user and manage permissions.
  3. Select the required Security Group or role scope.
  4. Assign only the Environments the user needs.
  5. Save the user.
  6. Ask the affected user to sign out and sign in again.

Repeat for every user who needs Environment-specific access. Newly added Environments require a fresh assignment review.

Verify safely

Use a non-administrator test user to confirm visible Environments, designer read/write behavior, Connection values, logs, releases, and status controls. Also verify Cookie and Delegate MCP user API Keys: permitted-user authorization is intersected with effective Environment access.

Environment-list administration requires access across the current list so a partially scoped administrator cannot silently change Environments they cannot see.

See Security Groups, Site Settings, and Site Environment.