The following permission sets are required to perform the patch activity on OpsRamp.

CategoryPermission TypePermission ValueAction
Account AdministrationDevicesViewTo view the Patch Management module in the UI.
AutomationPatch ApprovalsView
  • View the patch status.
  • View the configured patch install jobs under the patch configuration page.
AutomationPatch ApprovalsManage
  • Patch configuration page, where users can create, edit, and delete a patch install job.
  • Patch approval page, where a user can approve patches for a set of devices.

Follow these steps to enable the above permission set:

  1. Navigate to Setup > Account > Users and Permissions.
  2. Click the Permissions Sets tab.
  3. Click + ADD. The Add Permission page is displayed.
  4. Under Permission Set Details screen, enter a Permission Set Name and short Description.
  5. Select the above mentioned permissions and click Save.

Refer to the Permission Sets document for more details on obtaining the necessary permissions.

RBAC Enforcement for Patch Management

If the resource‑level restriction is enforced in Patch Management, allowing users to perform actions only on the resources or resource groups permitted by their role selection.

How RBAC enforcement works for Patch Management

Once enforced, Patch Management honors the Resources Visibility configuration in a role:

  • Users can view patch jobs only for resources included in their role.
  • Users can approve, schedule, and execute patch jobs only on those allowed resources.
  • Resources outside the assigned scope are hidden or inaccessible in Patch Management workflows, ensuring strict access control.

How to enable RBAC enforcement

To enforce RBAC for Patch Management, configure resource visibility at the role level:

  1. Navigate to Setup → Account → Users and Permissions → Roles.
  2. Open the required Role.
  3. In the Resource Visibility section:
    • Select Specified Resources.
    • Add the resource groups or individual resources that the role is allowed to manage.
  4. Enable Enforce to Patch Management checkbox.
  5. Save the role configuration.
patch management