Grant permissions to modify DNS and redirect rules for a subset of domains

What is the name of the domain?

example.com

What is the error number?

N/A

What is the error message?

N/A

What is the issue you’re encountering

User with permissions to a domain group is not able to add redirect rules

What steps have you taken to resolve the issue?

Searched the internet for ideas.

What are the steps to reproduce the issue?

I have a bunch of domains in my Cloudflare account. I want to let the marketing team modify DNS and redirect rules for the marketing domains, but not the other domains.

My attempt to accomplish that:

  1. I put the marketing domains in a domain group[1] called “marketing”
  2. I added my marketing co-worker to the Cloudflare account, granting them the “Domain DNS” permission for the “marketing” domain group.

My coworker logged in to Cloudflare and tried adding a redirect rule but was not able to.

  • Is there a way to accomplish what I want? Are there permissions specifically for creating redirect rules, without granting too much other access.
  • Another option is to create a separate Cloudflare account for the marketing domains. (Cloudflare doesn’t let me create another account with the “[email protected]” trick, so maybe I’ll have to create a new email account?)

[1] Role scopes | Cloudflare Fundamentals docs

No, there isn’t.

And “DNS Management” is not sufficient: you need “Domain Administrator” role to manage Redirects when the team member’s access is scoped to a domain/group.

As the doc (linked below) notes, the Domain Administrator role: “Grants full access to domains in an account, and read-only access to account-wide Firewall, Access, and Worker resources.”

So granting the “Domain Administrator” role for domains in this group to these users should not enable them to “mess” with any account-level services.

But if even that’s not an option for you at all, then your only choice is to use a different Cloudflare account.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.