Configure RBAC Roles | Check Point WAF
This guide explains how to assign RBAC roles to users in the Check Point Portal.
RBAC enables administrators to control which actions users can perform within the platform.
Available roles:
Admin
Security Manager
Operator (NOC)
Read Only
Monitor Read Only
Permission Inheritance
If a user is assigned multiple roles, the highest permission level applies.
For example:
A higher-privileged Global Role overrides lower service-role restrictions.
When multiple service roles are assigned, the user receives the most permissive access available across those roles.
Permissions Matrix
| Permission | Admin | Security Manager | Operator (NOC) | Read Only | Monitor Read Only |
|---|---|---|---|---|---|
| View policies | ✓ | ✓ | ✓ | ✓ | ✗ |
| Manage exceptions | ✓ | ✓ | ✓ | ✗ | ✗ |
| Disable / tune protections | ✓ | ✓ | ✓ | ✗ | ✗ |
| View logs and analytics | ✓ | ✓ | ✓ | ✓ | ✗ |
| Create / manage protected applications | ✓ | ✓ | ✗ | ✗ | ✗ |
| Attach protection to new assets (for example, enable protections...) | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage WAF service settings (for example, General Settings) | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage users | ✓ | ✗ | ✗ | ✗ | ✗ |
| Create new behaviors (Response / Trigger) | ✓ | ✓ | ✗ | ✗ | ✗ |
| Adjust existing behaviors (Response / Trigger) | ✓ | ✓ | ✓ | ✗ | ✗ |
| View Monitoring page | ✓ | ✓ | ✓ | ✓ | ✓ |
| Initialize tenant | ✓ | ✗ | ✗ | ✗ | ✗ |
Add a User and Assign Roles
Open the WAF Portal.
Navigate to Account Settings > Users.
Click New or choose an existing user
Under Global Role, select a global role if required.
Under Specific Service Roles:
Select WAF as the service.
- Select one or more RBAC roles.
Click Add.
Roles can also be assigned via the Account Settings > Users Groups