How do I work out which role gives access to a feature?

What is the name of the domain?

example com

What is the issue you’re encountering

I would like a assign a member the role required to activate Under Attack mode on specific domains. It should be the least privileged role that allows this action, ideally not just Domain Administrator or Super Administrator

What steps have you taken to resolve the issue?

I have read Under Attack mode · Cloudflare Fundamentals docs and Account roles · Cloudflare Fundamentals docs. I can only find brief descriptions of each role. Is there somewhere in the documentation where the full mapping of features and roles that can access them is laid out?

2 Likes

Good day,

Is there somewhere in the documentation where the full mapping of features and roles that can access them is laid out?

The dev docs are the related document for your request. Can you explain which specific role are you requesting for ?

Kindly review this related blog post : https://blog.cloudflare.com/domain-scoped-roles-ga/

Thank you !

Thank you for the blog post link. I have read that.

Can you explain which specific role are you requesting for ?

That is exactly my point, I do not know which role I am requesting. I know the permission I am requesting, which is the ability to enable and disable “Under Attack Mode” as described at Under Attack mode · Cloudflare Fundamentals docs

What I want to understand is how I would work out which role includes that permission. As an example, here is a Microsoft document covering the built-in roles in Entra, and the permissions that are included in each role.

Is there something like that for Cloudflare roles?

Failing that, do you know which roles would include the permission to enable the Under Attack Mode feature?

1 Like

The admin role does
Screenshot 2025-05-08 at 3.01.17 PM

Good approach. In reading the doc you shared, I was curious if enabling it selectively would be an option with a less permissive role, in testing that I don’t think it does. Great question and suggestion, I’ve tagged your topic for our docs team to review.