share ZeroTrust with colleagues
i have created a tunnels forwarding a local webserver , i want to share with colleagues the managmenet to the zerotrust - tunnel , for them to edit / create ..
on my main account i invited a colleague via email , and gave them all permissions.
1, domain / website is no where to be found on the invited account .
2, to see the domain , the invited account need to switch user to the "inviter" account , and even there the zerotrust is not visible
3, via access somehow i do get into the zero trust section , however when i get into the zerotrust through the main account it says i dont have permissions
there is 3 problems , but the main one is how do i share managmenet to zerotrust
thanks ❤️
2 Replies
You gave them all permissions on a specific domain, not across your account. See how it says "Domain scoped rules"?
If you go to Members you can click "Add a policy" and then Include "All Domains", then you get Account scoped roles and you can give them the various Zero Trust ones (near the bottom) like Cloudflare Zero Trust, Zero Trust Read-only, Zero Trust PII, etc. You'll need to give them a few more permissions too depending on what you want them to do, for example if you wanted to let them make Public Hostnames, which requires making DNS Records, you'd have to give them account level DNS Modification or a domain scoped policy which includes modifying dns for the domains they need it for
ok , found it , thank you very much .
why making it that way though .
what if i want to share only one domain to be "seen"
it make it way difficult and harder to manage .
another question if you may ,
is there an option to share tunnel domain etc.. without giving them the option to share my account .. or them to "enter" my account.
give them the right on their accounts without them needing to enter my account