<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Workflows set as Public access are having view and edit access for &amp;quot;Monitoring Viewer&amp;quot; users. Is it the expected beh in Automations</title>
    <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294285#M2501</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;&amp;nbsp; - Does it mean by default "Monitoring Viewer" will be able to edit the workflows set as public ?&lt;/P&gt;&lt;P&gt;Do i need to create specific Attribute based access to restrict the workflow edit access for "Monitoring Viewer" users ?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Feb 2026 20:24:16 GMT</pubDate>
    <dc:creator>RamkumarTIH</dc:creator>
    <dc:date>2026-02-05T20:24:16Z</dc:date>
    <item>
      <title>Workflows set as Public access are having view and edit access for "Monitoring Viewer" users. Is it the expected behavior ?</title>
      <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294279#M2499</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We have the workflows which are set as public are viewable and editable by the "Monitoring Viewer" users.&lt;/P&gt;
&lt;P&gt;They are the read only users in Dynatrace and not suppose to edit any of the workflows.&lt;/P&gt;
&lt;P&gt;Is it the expected behavior ?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 08:04:25 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294279#M2499</guid>
      <dc:creator>RamkumarTIH</dc:creator>
      <dc:date>2026-02-06T08:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Workflows set as Public access are having view and edit access for "Monitoring Viewer" users. Is it the expected beh</title>
      <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294281#M2500</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/80105"&gt;@RamkumarTIH&lt;/a&gt;&amp;nbsp;you can configure your expected access using policies. Role Based Access like Monitoring Viewer is different from Attribute-Based Access Control is more granular. With this you can control the expected behavior of Dynatrace permissions.&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/migrate-roles" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/migrate-roles&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 20:05:29 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294281#M2500</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2026-02-05T20:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Workflows set as Public access are having view and edit access for "Monitoring Viewer" users. Is it the expected beh</title>
      <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294285#M2501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;&amp;nbsp; - Does it mean by default "Monitoring Viewer" will be able to edit the workflows set as public ?&lt;/P&gt;&lt;P&gt;Do i need to create specific Attribute based access to restrict the workflow edit access for "Monitoring Viewer" users ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 20:24:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294285#M2501</guid>
      <dc:creator>RamkumarTIH</dc:creator>
      <dc:date>2026-02-05T20:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: Workflows set as Public access are having view and edit access for "Monitoring Viewer" users. Is it the expected beh</title>
      <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294287#M2502</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/80105"&gt;@RamkumarTIH&lt;/a&gt;&amp;nbsp;I don't have a Vanilla tenant to check basic access but I can assure you that if you set a correct set of &lt;A href="https://docs.dynatrace.com/docs/shortlink/iam-policystatements#automation" target="_self"&gt;ABAC policies&lt;/A&gt; you can restrict all of this items:&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:workflows:read&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to read workflows&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:workflows:write&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to write workflows&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:workflows:run&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to execute workflows&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:workflows:admin&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grant admin permissions for workflows.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:rules:read&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to read scheduling rules&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:rules:write&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to write scheduling rules&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:calendars:read&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to read business calendars&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;automation:calendars:write&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;Grants permission to write business calendars&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Hope it helps.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 05 Feb 2026 20:32:52 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294287#M2502</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2026-02-05T20:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Workflows set as Public access are having view and edit access for "Monitoring Viewer" users. Is it the expected beh</title>
      <link>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294755#M2506</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have assigned the in-built "Standard User" policy to the Operators.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Looks like below one is mandatory for users to access new UI..&lt;/P&gt;&lt;P&gt;//AppEngine&lt;BR /&gt;ALLOW app-engine:apps:run, app-engine:functions:run, app-engine:edge-connects:read;&lt;/P&gt;&lt;P&gt;Have created a custom Denial policy with the rules below and assigned to the group as i am unable to modify the default Standard user policy. Now Operators are able to access both old UI and new UI but with restriction to Workflows App and few others as per DENY statements.. Thanks for the help&lt;/P&gt;&lt;P&gt;//Davis&lt;BR /&gt;DENY davis:analyzers:read, davis:analyzers:execute;&lt;/P&gt;&lt;P&gt;//Davis Copilot&lt;BR /&gt;DENY davis-copilot:conversations:execute, davis-copilot:nl2dql:execute, davis-copilot:dql2nl:execute, davis-copilot:document-search:execute;&lt;/P&gt;&lt;P&gt;//Grail&lt;BR /&gt;DENY storage:bucket-definitions:read;&lt;BR /&gt;DENY storage:fieldset-definitions:read;&lt;BR /&gt;DENY storage:filter-segments:read, storage:filter-segments:write, storage:filter-segments:delete;&lt;/P&gt;&lt;P&gt;//AutomationEngine&lt;BR /&gt;DENY automation:workflows:read, automation:calendars:read, automation:rules:read;&lt;BR /&gt;DENY automation:workflows:write;&lt;BR /&gt;DENY automation:workflows:run;&lt;/P&gt;&lt;P&gt;//Extensions&lt;BR /&gt;DENY extensions:definitions:read;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 20:30:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Automations/Workflows-set-as-Public-access-are-having-view-and-edit-access/m-p/294755#M2506</guid>
      <dc:creator>RamkumarTIH</dc:creator>
      <dc:date>2026-02-13T20:30:56Z</dc:date>
    </item>
  </channel>
</rss>

