megachangelog
Feature

Access resource lists now support resource-scoped roles

Members with resource-scoped Access roles can now view and list Access resources in the dashboard and API, with filtering applied to show only resources within their permission scopes. Previously these members needed an additional account-scoped role to access list pages.

Members with only resource-scoped Access roles can now open Access resource list pages in the Cloudflare dashboard and call list endpoints in the API. They no longer need an additional account-scoped read-only role to list resources.

The dashboard and API return only resources included in the member's permission policy scopes. Filtering applies to Access applications, policies, service tokens, and identity providers. This allows administrators to delegate specific Access resources without granting account-wide visibility. Previously, the dashboard blocked these list pages and API list requests returned 403 responses.

For members with the Cloudflare Access App Admin role, policy lists include policies attached directly to the selected application. Reusable policies appear only when the member has the Cloudflare Access Policy Admin role for those policies.

For role definitions and assignment details, refer to Resource-scoped roles and Role scopes.

accessrolesdashboardapipermissions

Source: original entry ↗