05-15-2026 06:22 AM
Is there a timeline or estimated release date for basic or advanced RBAC for Workflows (for SSO dashboard logins)?
Basic:
Advanced
Solved! Go to Solution.
05-18-2026 10:12 AM
@Jeff Orr / @Philip D'Ath / @mloraditch / @mkutka - this feature is committed and presently being tested in production under a feature flag.
RBAC has been the highest priority item since we launched last year. It took coordinated effort with the Auth team to fit within the Dashboard permissions model, hence the amount of time needed to get this working.
What's coming is the ability to assign an admin (write), auditor (read), operator (execute), and deny permissions specifically for Workflows under the Automation menu. You will no longer need lean on the Org Admin role.
The above will come with the "Production Ready" flag, so only workflows you mark as Production Ready will be available for the operator to see/run. In addition, folder support will be delivered soon.
Future enhancements for attribute-based access control (ABAC), where it's down to which specific workflows/folder a user can edit/run is, on the long-term roadmap.
05-15-2026 07:49 AM
I've not seen or heard anything specific to this. I would keep an eye on Cisco Live in a few weeks as lots of stuff tends to get announced there and even if not announced sometimes folks will talk a bit more openly about roadmap. I will be there and will try to remember to ask around and see if I can get a non-nda'd answer.
05-15-2026 01:58 PM
This would be a great feature to add.
05-17-2026 12:30 PM
I've heard/seen some roadmap items around RBAC for Workflows, although i'm unsure if they're committed. I suspect there may be some announcements on these items at Cisco Live US in a few weeks.
05-18-2026 04:18 AM
@Jeff Thank you for reaching out to the community with this question.
I’m happy to confirm that Role-Based Access Control (RBAC) for Cisco Agentic Workflows is coming very soon. We understand how critical this is for managing workflows for network operations effectively.
One of the key features we are introducing is the ability to define specific personas—including a "Network Operator" role. This will allow you to assign limited, granular permissions to your team members, enabling them to run essential workflows while maintaining the security posture of your environment.
We have a lot more exciting information and technical deep dives planned for Cisco Live in just two weeks. We would love to see you there and walk you through these upcoming capabilities in person!
05-18-2026 10:12 AM
@Jeff Orr / @Philip D'Ath / @mloraditch / @mkutka - this feature is committed and presently being tested in production under a feature flag.
RBAC has been the highest priority item since we launched last year. It took coordinated effort with the Auth team to fit within the Dashboard permissions model, hence the amount of time needed to get this working.
What's coming is the ability to assign an admin (write), auditor (read), operator (execute), and deny permissions specifically for Workflows under the Automation menu. You will no longer need lean on the Org Admin role.
The above will come with the "Production Ready" flag, so only workflows you mark as Production Ready will be available for the operator to see/run. In addition, folder support will be delivered soon.
Future enhancements for attribute-based access control (ABAC), where it's down to which specific workflows/folder a user can edit/run is, on the long-term roadmap.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide