Skip to Main Content
Cloud and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Functionality already exists
Workspace Instana
Created by Guest
Created on Jun 11, 2026

Enhance Role-Based Access Control (RBAC)

Instana RBAC is currently too coarse. When a user is added to a role, they effectively inherit the same full permissions (e.g., view/edit/delete). We need more granular access control so we can apply least-privilege access.

Current issue

  • Roles can’t easily be configured as read-only.

  • Permissions can’t be limited

  • This forces teams to either over-provision access or restrict adoption.

Requested enhancement - Add granular RBAC permissions, including:

  • Read-only role (view dashboards, traces, metrics, alerts; no changes)

  • Ability to separate actions (Create, Configure/Edit and Delete) into different permission settings

  • (Optional but valuable) Ability to scope access to specific apps/services/environments (e.g., prod vs non-prod, team-owned services) using DFQ / tag

Idea priority High
  • Admin
    Máté Návay
    Jul 6, 2026

    As for the segmented access to infrastructure alerting, currently Custom Events don't support any granular access due to their architecture.
    Infrastructure Smart Alerts today also need an unrestricted infra access, but work is in progress to introduce Infra Perspectives (ETA 4Q26), to allow similar segmentation of entity access and alert scoping, like we offer on Application area. The same will first be introduced on Logging area. (ETA 3Q26)

  • Admin
    Máté Návay
    Jul 6, 2026

    As discussed on the call, for the Automation action team association RFE I created INSTANA-I-4973

  • Admin
    Máté Návay
    Jun 17, 2026

    Since permissions are about configuration, these are not needed for a view only access.
    Our Default role by default provides read-only access already. This is fully possible today.

    Permissions can be limited. Most permissions can apply over a limited scope when providing the role only inside a limited team scope.

    Traces, metrics, alerts can all be read-only, even in a limited team scope, by just not adding the configure permissions.
    Dashboards are an exception, as every user has the possibility to create a private dashboard. Public dashboards can be controlled on a user level for who is allowed to edit.


    Separating Create and Edit makes no sense, as an existing entity could be just edited into something completely different. Allowing a user to only create but not delete will lead to piles of junk entities created with extra effort on admins to clean up.
    Instead, limited team scopes should be used where configuration permissions are granted to some team members. Viewer access can still be kept for everything (via Default role for example)


    Team scope provides exactly the kind of app/service/env scope limitations via assigned Applications, Websites or the additional DFQ access on Infra.