> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CoPilot User Account Administration

> This section discusses user accounts for Aviatrix CoPilot and user account permissions required to use CoPilot features and functionality.

This section discusses user accounts for Aviatrix CoPilot and user account
permissions required to use CoPilot features and functionality.

<Note>
  Users should be granted only the permissions needed to perform their work.
  Review user privileges on a routine basis to confirm they are appropriate for
  current work tasks.
</Note>

<a id="end-help-cp-service-acct" />

If you use an identity provider (IdP) to allow users to log in to Aviatrix
Controller via SAML authentication, you can also allow users to log in to
Aviatrix CoPilot via SAML authentication. See

<a href={"/docs/enterprise/" + "10.1" + "/guides/platform-administration/saml-login-setup"}>SAML Login Setup</a>
.

<a id="copilot-service-account" />

<a id="start-help-cp-service-acct" />

## About User Account to Be Used as CoPilot Service Account

Aviatrix CoPilot requires a dedicated service account. This account is used to
retrieve data and make configuration changes on the Controller without requiring
a logged-in user. You must create this service account on the Aviatrix
Controller. See

<a href={"/docs/enterprise/" + "10.1" + "/guides/controlplane/copilot-planning-deployment#create-copilot-serviceaccount"}>Create Your CoPilot Service Account</a>
.

During the initial setup of CoPilot, you will be prompted to specify the user
account to be used as the CoPilot service account.

<Note>
  The CoPilot service account must be added to the built-in `admin` permission
  group. This ensures full access to all CoPilot features, including: Topology
  data collection, ThreatIQ alerts and blocking, Distributed Cloud Firewall
  (DCF), Gateway scaling and performance monitoring.
</Note>

<Note>
  Removing the Service Account will limit CoPilot's ability to perform critical
  tasks, including fetching topology data, collecting performance metrics, and
  applying configuration changes.
</Note>

## About CoPilot User Accounts

This section describes user accounts for CoPilot and permissions required for
some features.

All valid user accounts created on Aviatrix Controller can log in to Aviatrix
CoPilot.

For a user to enable ThreatIQ alerts or ThreatIQ blocking in CoPilot, they must
log in to CoPilot with a user account that has `all_write` or
`all_security_write` permissions.

## CoPilot Read-Only Access Views

CoPilot hides/disables some actions in the UI for users logging in with a
read-only account. The `read_only` permission group is a built-in permission
group. It allows only full read access.

Controller user accounts that belong to a group that has read\_only permissions
cannot perform actions, such as:

* Deleting change-set data (Topology Replay)

* Resolving and deleting alerts (Notifications)

* Creating and deleting network domains (Security)

For actions that are reserved for groups with all\_write and all\_security\_write
permissions, see
[Permissions Required for CoPilot Features](#permissions-required-for-copilot-features).

User accounts with read-only permissions are able to perform the following
tasks:

* Saving and deleting filter groups (FlowIQ)

* Saving and deleting topology layouts (Topology)

## Permissions Required for CoPilot Features

The CoPilot ThreatIQ and Distributed Cloud Firewall features require that the
CoPilot service account have a minimum of all\_firewall\_network\_write
permissions. The CoPilot gateway scaling feature requires a minimum of
`all_gateway_write` permissions to manage the spokes and transits.

The admin permissions (`all_write`) have full access to all CoPilot features.
The admin permissions are required to perform the following:

* Adding, changing, or deleting Aviatrix networking constructs and policies

* Enabling CoPilot features.
