Cloudflare Docs
Cloudflare Fundamentals
Edit this page on GitHub
Set theme to dark (⇧+D)

Role scopes

When you assign domain specific roles to account members, you can scope these roles to apply to all domains or various combinations of included and excluded domains.


​​ Choose role scopes

You choose the scope of a role when you add a member to your account.

​​ All domains

If you want the member to have a role that applies to all domains within your account, use the following combination of fields.

FieldValue
OperatorInclude
TypeAll domains

​​ Excluding specific domains

If you want the member to have roles associated with most domains, but not one or two specific, more restricted domains, use the following combination of fields.

FieldValue
OperatorInclude
TypeAll domains
FieldValue
OperatorExclude
TypeA specific domain
Nameexample.com

​​ Domain groups

If you want a member with access to a group of specific domains, you can also create a Domain Group.

​​ Create group

To create a domain group:

  1. Log in to the Cloudflare dashboard and select your account (you must be logged in as a Super Administrator and have a verified email address).

  2. Go to Manage Account > Configurations > Lists.

  3. For Domain Group Manager, select Create.

  4. Create your domain group:

    1. Select the domains to include.
    2. Add a Name.
    3. Select Create.

You can also edit and delete these groups as needed.

​​ Use group

To assign a member permissions to a domain group, use the following combination of fields:

FieldValue
OperatorInclude
TypeDomain Group
NameExample Group