Overview
Turbo360 uses a role-based access control model to manage who can view and modify resources within the Business Applications module. Roles are assigned at a specific scope (the entire module, a Business Application group, or an individual Business Application) and determine what each user can do within that boundary.
The first user who signs up for Turbo360 is assigned the Account owner role, which grants full access to the entire account. Account owners can add users to Business Applications and assign them system-defined or user-defined roles.
This article covers role management in Business Applications. For role management in other modules, see:
Business value
Granular role assignments reduce security risk by limiting each user to only the access they need. Scope-based permissions let you apply different levels of access across module, group, and application boundaries without creating separate accounts.
How it works
Every user in Business Applications has a role assigned at one or more scopes. The role defines what the user can do; the scope defines where that role applies.
Scope
The scope of a role determines the level within Business Applications at which the user's permissions apply. There are three scope levels:
- Entire module: the user's role applies across all Business Application groups and applications in the module.
- Business Application group: the user's role applies only within a specific group and its applications.
- Business Application: the user's role applies only to a specific application.
The Scope column in the user list indicates why each user has access: as an account owner, module owner, through a group-level role assignment, or via a direct application-level role assignment.
System-defined roles
Business Applications includes three system-defined roles:
| Role | Access |
|---|---|
| Owner | Full access to the module, including user and role management. Only Account owners and module Owners can manage users and roles. |
| Contributor | Full management access at the assigned scope. |
| Reader | Read-only access at the assigned scope. |
Specify custom permissions
When adding a user, you can assign them a system-defined or user-defined role at a specific node level (a Business Application group or an individual Business Application) rather than across the entire module. This lets you grant precise access without giving the user visibility into unrelated groups or applications.
The Specify custom permissions dialog lists all Business Application groups and their child applications. Each node can be individually enabled or disabled using the Revoke / Grant access toggle. A Role dropdown next to each entry lets you assign either a system-defined or user-defined role at that specific scope.
Key behaviors:
- Enabling a Business Application group automatically includes all child applications within it, unless individual applications are toggled off separately.
- The role assigned at a group level applies to all its child applications unless overridden at the application level.
- You can assign different roles at different levels in a single operation; for example, Contributor on a test group and Reader on a production group.
User-defined roles
Account owners and module owners can create user-defined roles to grant precise combinations of permissions. A user-defined role contains three permission categories:
- Account permissions: controls account-level capabilities such as managing notification channels.
- Management permissions: controls whether the role can manage users and their permissions, and manage escalation policies.
- Feature permissions: controls access to specific Business Applications features. Available feature permissions are:
| Feature | Permission levels |
|---|---|
| Dashboard | Read / Manage |
| Service Map | Read / Manage |
| Automated Task | Read / Manage |
| Run and cancel automated task | Enable (sub-permission under Automated Task) |
| Monitoring | Read / Manage |
| Monitoring profile | Read / Manage |
| AI Agents | Disable / Enable |
- Resource permissions: controls access to individual Azure resource types. Each resource supports Read and Manage permissions. Select resources also support Reprocess, Repair & Reprocess, Purge, Upload, and Manage Filter permissions where applicable.
Available resource types include API Endpoint, API App, APIM API, APIM Operation, APIM Product, APIM Service, App Registration, App Service Certificate, Application Insight, Azure Function, and others. Use Select all or Unselect all to manage permissions across all resources at once.
For example, if a team manages Service Bus resources across all applications but should not access other features, you can create a role with Manage permission on Service Bus only and assign it to those users.
Manage users permission
The Manage users management permission allows the role to add or remove users and update user permissions within the Business Applications module. It does not grant the ability to create, edit, or delete roles; that stays limited to Account owner and Owner.
System-defined vs user-defined roles
System-defined roles (Owner, Contributor, Reader) apply broadly at the assigned scope. User-defined roles allow finer-grained control within that scope.
Operations on a Business Application or group (such as editing or deleting it, adding or removing resources, or managing service principals) require at least a Contributor role at the relevant scope. A user-defined role with limited permissions cannot perform these operations.
Steps
Use the following steps to create, manage, and delete roles, and to export user permission data. Navigate to the Roles tab within User management in Business Applications to get started.
Create a role
Creating a user-defined role lets you define a precise combination of management, feature, and resource permissions for a specific team or responsibility.
- Click Add role in the Roles tab.
- Enter a role name and an optional description.
- Toggle the Account permissions you want to include (e.g. Manage notification channels).
- Toggle the Management permissions you want to include (e.g. Manage users, Manage escalation policy).
- Set Feature permissions for each feature: toggle to enable, then select Read or Manage (or Enable for AI Agents).
- Set Resource permissions for each Azure resource type: toggle to enable, then select Read, Manage, or additional permissions where available.
- Click Next, review the summary, then click Update to save.
Delete a role
Deleting a role requires assigning a replacement to all users currently holding that role, so no user loses access.
- In the Roles tab, click Delete role in the Actions menu next to the role you want to remove.
- Select a replacement role for users currently assigned the role being deleted.
- Confirm the deletion.
Export user permissions
Exporting user permissions produces a CSV file listing all users and their permission assignments across every scope in the module.
- Navigate to User management in Business Applications.
- Click the Export icon.
The downloaded CSV file includes each user's permissions at all assigned scopes within the account.
Example scenario
A team supports two Business Application groups: OrderProcessing-Prod and OrderProcessing-Test. The lead engineer needs full management access to both groups. Junior engineers need to manage Service Bus resources in the test group only, with no access to other features or production.
You create a user-defined role called ServiceBus-Test-Manage with Manage permission on Service Bus only. You assign the lead engineer Contributor at the module level, and the junior engineers ServiceBus-Test-Manage scoped to the OrderProcessing-Test group using Specify custom permissions.
Troubleshooting
-
A user cannot manage users or roles in Business Applications
Cause: The user does not have the Owner role or Account owner status. Contributor and Reader roles (and all user-defined roles) cannot manage users or roles.
Fix: Assign the user the Owner role at the appropriate scope, or ask a module Owner or Account owner to perform the user management task. -
Deleting a role fails or is blocked
Cause: The role is currently assigned to one or more users and no replacement role has been selected.
Fix: When prompted during deletion, select a valid replacement role to reassign to all affected users before confirming. -
A user-defined role cannot edit or delete a Business Application
Cause: Structural operations on Business Applications and groups require at least a Contributor role. User-defined roles with feature or resource permissions only do not grant this access.
Fix: Assign the user a Contributor role at the relevant scope in addition to any user-defined role. -
Resource permissions are not visible when creating a role
Cause: The resource permissions step is on a separate page of the role creation wizard. The first page covers account, management, and feature permissions; the second page covers resource permissions.
Fix: Click Next after completing the first page to reach the Specify resource permissions step. -
Exported CSV does not include a user
Cause: The user may not have been added to the Business Applications module yet, or they were added after the last export.
Fix: Verify the user is listed under User management in Business Applications. If absent, add the user and assign a role before exporting again.
FAQs
-
Can a user have different roles in different Business Application groups?
Yes. Roles are assigned per scope. You can assign a user Contributor on one group and a read-only user-defined role on another using Specify custom permissions. -
What happens to users when a role is deleted?
You must select a replacement role before the deletion completes. All users assigned the deleted role are automatically reassigned to the replacement role. No user loses access to Business Applications. -
Can a user-defined role include both feature and resource permissions?
Yes. A single user-defined role can combine account permissions, management permissions, feature permissions, and resource permissions in any combination. This lets you tailor access precisely to a team's responsibilities.