Skip to main content

Role-Based Access Control - Restriction on Delete Action

  • August 28, 2025
  • 1 reply
  • 16 views

Abhishek Moriya
Netskope Partner

Hello Netskope Community,

One of our customers has a requirement where a specific role should have the ability to create policies and apply global/general settings, but not be able to delete any policies or settings due to compliance reasons.

Currently, this level of granularity is not supported. The available permission levels—None, View, Manage, and Manage and Apply—provide either read-only or full read-write access to a specific feature or function. However, there is no built-in option to restrict only the delete action for a role.

We would like to know if there are any known workarounds or if this capability is being considered for a future release.

1 reply

notskope
  • New Member III
  • 81 replies
  • August 28, 2025

I can’t answer if Netskope will add that as a feature. 

However, you could use Cloud Exchange to monitor when a user deletes a policy and generate an alert as a compromise.