Configuring Secret Template Permissions

You can assign users and groups to specific secret templates so they can either manage or create secrets based on those templates. This allows you to have more granular control over what secret templates are seen by users and groups when they are managing the templates or creating secrets. To configure permissions:

Secret template access is dependent on configuration in Groups / Everyone / Secrets. Without modifying this, the group or user assignment on secret templates changes nothing.

  1. Select Admin > Secret Templates. The Secret Templates page appears:

    image-20220606092132102

  2. Click the name of the template for which you wish to configure permissions. The Secret Template Detail page appears on the General tab:

    image-20220606092210202

  3. Click the Permissions tab:

    image-20220606092503096

  4. Click the Edit button in the Secret Template Permissions section. The Secret Template Permissions section enters edit mode:

    image-20220606092543861

  5. To change the permissions of a user or group that has already been assigned permissions, select a new permission from the Administrator drop-down list. Template Create Secret allows a user or group to create secrets based on the selected secret template. Template Owner allows a user or group to edit a secret template and create secrets based on the selected secret template. By default, the Everyone group that targets all users of Secret Server can create secrets based on any secret template.

    User's secret template permissions are based on the permissions directly assigned to them, as well as the permissions assigned to all of the groups the user belongs to. If a user or group does not have Template Create secret or Template Owner permissions, they are unable to create a secret based on that secret template or see that it exists in Secret Server.
  6. To add permissions for a new user or group, click the Add button. The Users popup appears:

    image-20220606092636274

  7. Click to select the check box for the user or group.

  8. Click the Add button.