--- title: "Screen Sharing User Role Permissions" slug: "permission" updated: 2026-07-23T22:47:14Z published: 2026-07-23T22:47:14Z canonical: "docs.screenmeet.com/permission" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.screenmeet.com/llms.txt > Use this file to discover all available pages before exploring further. # Screen Sharing User Role Permissions ## Screen Sharing User Role Permissions ### Overview This article describes the roles and permissions that control ScreenMeet screen sharing through Tanium Direct Connect, including how each Tanium role maps to a ScreenMeet role and which permissions govern unattended sessions. Assign these roles in Tanium; ScreenMeet applies the matching role automatically. --- ### Roles | Tanium Role | ScreenMeet Role | Grants | | --- | --- | --- | | `Screen Sharing Administrator` | `ScreenMeet Admin` | Change settings, features, and policies; access data; join active sessions created by other users; open the ScreenMeet console to configure organization settings using a magic link. | | `Screen Sharing Agent` | `ScreenMeet Agent` | Start sessions and use standard ScreenMeet features. Includes the `Screen Sharing Console` permission for console access without the ability to modify organization settings. | --- ### Permissions for Unattended Sessions Two permissions control unattended sessions. Neither is assigned to any default role, and both must be added to a custom role. | Permission | Effect | | --- | --- | | `Screen Sharing Support Session Unattended Execute` | Establish unattended sessions with Windows endpoints that do not require endpoint user permission. After the session ends, the endpoint locks by default. | | `Screen Sharing Support Session Disable Autolock Execute` | Leave the endpoint unlocked after an unattended session ends. Requires the `Screen Sharing Support Session Unattended Execute` permission. | Unattended Access Is Restricted by Design The default `Integration Admin - ScreenMeet`, `Screen Sharing Agent`, and `Integration Viewer - ScreenMeet` roles do not permit unattended sessions. To grant unattended access, build a custom role and persona. See [Unattended Screen Sharing Sessions and Personas](/docs/permission#). --- ### Additional Permissions - `Screen Sharing Product Options Read`: When `Let the Agent Decide` is set for Session Recording in the ScreenMeet console, this permission lets the operator choose whether to record a session. - `Screen Sharing Console` or `Screen Sharing Console Admin`: Required to open a session with an endpoint that has no Tanium Client. - `Integration Admin - ScreenMeet`: Required to view all sessions, join sessions started by other operators, and view the Audit Log. --- ### Best Practice Use Least Privilege Assign screen sharing users only the roles and permissions they need. Restrict unattended-session permissions to a custom persona scoped to specific computer groups and users. --- ### Where Roles Are Configured Role Setup in Tanium Roles, permissions, and personas are created in Tanium Console under **Administration > Permissions**. More information is surfaced in the Tanium documentation at [Tanium Direct Connect User Guide: Screen Sharing user role permissions](https://help.tanium.com/bundle/ug_direct_connect_cloud/page/direct_connect/screen_share.html). ---