Configure Environment-scoped Permissions
Environment-scoped permissions add an Environment scope to permissions. Use this feature when you need users to have different permissions across different Environments.
Plan the rollout
List the users and automation identities that require Test, intermediate, and Production access. Review design, Connection-value, API-key user, release, status, logs, and operational responsibilities separately.
Environment access does not grant an action by itself; the user's Site role or Security Group must also permit that action.
Enable the feature
- Open
Settings→Site settings. - Enable
Environment-scoped permissions enabled. - Click
Save changes.
Console grants the enabling administrator access to all current Environments so the rollout can be completed.
Assign users
- Open
Settings→Site users. - Open a user and manage permissions.
- Select the required Security Group or role scope.
- Assign only the Environments the user needs.
- Save the user.
- Ask the affected user to sign out and sign in again.
Repeat for every user who needs Environment-specific access. Newly added Environments require a fresh assignment review.
Verify safely
Use a non-administrator test user to confirm visible Environments, designer read/write behavior, Connection values, logs, releases, and status controls. Also verify Cookie and Delegate MCP user API Keys: permitted-user authorization is intersected with effective Environment access.
Environment-list administration requires access across the current list so a partially scoped administrator cannot silently change Environments they cannot see.
See Security Groups, Site Settings, and Site Environment.