Deploy-Only Role
Users with the Deploy-Only role can do the following:
- Deploy staged changes to a device, or to multiple devices. 
- Revert or restore configuration changes for ASA devices. 
- Schedule or manually start image upgrades for devices. 
- Schedule or manually start a security database upgrade. 
- Utilize the Change Request Management action. 
Deploy-Only users cannot do the following:
- Manually switch between Snort 2 and Snort 3 versions. 
- Create a template. 
- Change the existing OOB Change settings. 
- Edit System Management settings. 
- Onboard devices. 
- Delete devices. 
- Delete VPN sessions or user sessions. 
- Create, update, configure, or delete anything on any page. 
- Onboard devices. 
- Step-through the tasks needed to create something like an object or a policy, but not be able to save it. 
- Create Security Cloud Control user records. 
- Change user role. 
- Attach or detach access rules to a policy.