12.2 Modern Folder Hierarchy, User/Robot Assignment & Permissions

Key Takeaways

  • Modern folders organize automations in a tree of folders and subfolders within one tenant.

  • Tenant entities include users, robot accounts, machines, roles, packages, and webhooks; folder entities include processes, jobs, triggers, queues, assets, storage buckets, and actions.

  • Tenant roles such as Orchestrator Administrator and the Allow to be roles pair with folder roles such as Folder Administrator, Automation Developer, Automation Publisher, and Automation User.

  • Machine templates plus runtimes allow dynamic allocation: a job can run under any assigned account on any machine connected through the folder's template.

  • Access flows down the tree as a union of privileges: inherited roles cannot be removed in a subfolder, so isolate sensitive areas by assigning accounts only on that branch.

Last updated: September 2026

12.2 Modern Folder Hierarchy, User/Robot Assignment & Permissions

Core Concept: Modern Folders represent the foundational multi-tenant and organizational segmentation architecture in UiPath Orchestrator. Modern Folders organize automation resources into hierarchical trees of root folders and subfolders, strictly separating global infrastructure (Tenant Entities) from operational workloads (Folder Entities). Through fine-grained Role-Based Access Control (RBAC) and Dynamic Robot Allocation, Modern Folders eliminate static machine-robot pairings, enabling elastic, secure, and multi-departmental automation management.

In early versions of UiPath Orchestrator, "Classic Folders" enforced a rigid, flat organizational structure. Robots were tightly coupled to specific Windows user credentials and fixed physical machine names. Managing access across diverse corporate divisions required configuring separate Orchestrator tenants, resulting in fragmented infrastructure, duplicated package feeds, and severe licensing overhead. Modern Folders resolve these legacy constraints by introducing hierarchical scoping, user-group synchronization, dynamic machine pooling, and contextual role permissions.


1. Modern Folder Hierarchical Architecture

A Modern Folder structure mirrors corporate organizational hierarchies through a nested tree model. Within a single Orchestrator tenant, administrators construct Root Folders representing business divisions or geographic regions, branching into nested Subfolders representing specific functional teams or automation domains.

Orchestrator Tenant Hierarchy
├── [Root Folder] Finance
│   ├── [Subfolder] AccountsPayable
│   │   ├── [Subfolder] InvoiceProcessing
│   │   └── [Subfolder] VendorReconciliation
│   └── [Subfolder] AccountsReceivable
│       └── [Subfolder] BillingCollections
├── [Root Folder] HumanResources
│   ├── [Subfolder] EmployeeOnboarding
│   └── [Subfolder] Payroll_Confidential (accounts assigned directly)
└── [Root Folder] SupplyChain
    ├── [Subfolder] InventoryAudit
    └── [Subfolder] LogisticsDispatch

Structural Characteristics of Modern Folders

  • Nesting: Folders can contain several levels of subfolders, so the tree can follow departments, teams, and processes.
  • Logical Boundary Isolation: Each folder acts as an isolated sandbox for its workloads. A robot executing a process in Finance/AccountsPayable has zero visibility into assets, queues, or jobs residing in HumanResources/Payroll_Confidential unless explicitly authorized.
  • Contextual Path Resolution: Workflows and API queries address entities using relative or fully qualified folder paths (e.g., FolderPath: "Finance/AccountsPayable/InvoiceProcessing").
  • Multi-Tenancy vs. Modern Folders: While Orchestrator Tenants provide absolute database-level isolation (used for distinct legal entities or strictly segregated Dev/Test/Prod environments), Modern Folders provide logical segregation within a shared tenant database, sharing licenses, machine templates, and user directories while maintaining strict data access boundaries.

2. Tenant Entities vs. Folder Entities

A fundamental architectural principle in Modern Orchestrator is the strict taxonomy separating Tenant Entities from Folder Entities.

+-----------------------------------------------------------------------------------+
|                         ORCHESTRATOR ENTITY SCOPES                                |
|                                                                                   |
|  +-----------------------------------------------------------------------------+  |
|  |                               TENANT ENTITIES                               |  |
|  |  (Global Infrastructure, Identities, Governance & Licensing Resources)      |  |
|  |                                                                             |
|  |  - Users & Directory Groups      - Roles & Global Permissions               |  |
|  |  - Machine Templates & Hosts     - Robot Accounts (Service Principals)      |  |
|  |  - Licenses & Runtime Pools      - Tenant Webhooks                          |  |
|  |  - Credential Store Configs      - Audit Logs & System Settings             |  |
|  |  - Tenant Package Feed (.nupkg)  - Alerts                                   |  |
|  +-----------------------------------------------------------------------------+  |
|                                          │                                        |
|                                          ▼ Assigned / Mapped to                   |
|  +-----------------------------------------------------------------------------+  |
|  |                               FOLDER ENTITIES                               |
|  |  (Operational Workloads, Automation Data & Execution Runtime Context)       |  |
|  |                                                                             |
|  |  - Processes (Releases)          - Queues & Queue Items                     |  |
|  |  - Jobs (Execution Instances)    - Assets (incl. Credential, Secret)        |  |
|  |  - Triggers (Time & Queue)       - Storage Buckets (Binary Objects)         |  |
|  |  - Action Catalogs (Tasks)       - Test Sets & Test Execution Data          |  |
|  +-----------------------------------------------------------------------------+  |
+-----------------------------------------------------------------------------------+

Tenant Entities (Infrastructure Layer)

Tenant entities exist at the root tenant level and represent global infrastructure, identity definitions, and security policies shared across the organization:

  • Users & Groups: Human identities imported from corporate directories (Microsoft Entra ID, Okta) or local Orchestrator accounts.
  • Robot Accounts: Dedicated non-human service identities created specifically for unattended robot execution, independent of personal employee credentials.
  • Machine Templates: Shared connection definitions defining execution capacity and runtime licenses.
  • Roles: Permission definitions establishing what actions can be performed at the tenant level or folder level.
  • Packages: Published automation binaries (.nupkg files) stored in the tenant package feed.

Folder Entities (Workload Layer)

Folder entities represent the actual automated business processes and runtime data. They exist strictly within the boundary of a specific folder:

  • Processes (Releases): Bindings between a published NuGet package version and specific folder runtime settings.
  • Jobs: Running or finished automation execution instances.
  • Triggers: Time, queue, event, and API triggers that start jobs.
  • Queues & Transactions: Work item queues storing transactional data (New, In Progress, Successful, Failed).
  • Assets & Credentials: Environment parameters and secure authentication objects.
  • Storage Buckets: Unstructured binary file repositories.

3. Role-Based Access Control (RBAC): Tenant vs. Folder Roles

UiPath Orchestrator enforces a two-tier Role-Based Access Control (RBAC) model. Permissions are explicitly divided into Tenant Permissions and Folder Permissions.

+-----------------------------------------------------------------------------------+
|                         TWO-TIER RBAC PERMISSION MODEL                             |
|                                                                                   |
|  +-------------------------------------+  +------------------------------------+  |
|  |            TENANT ROLES             |  |            FOLDER ROLES            |  |
|  |  - Orchestrator Administrator       |  |  - Folder Administrator            |  |
|  |  - Allow to be Folder Administrator |  |  - Automation Developer            |  |
|  |  - Allow to be Automation Developer |  |  - Automation Publisher            |  |
|  |  - Allow to be Automation User      |  |  - Automation User                 |  |
|  +------------------┬------------------+  +------------------┬-----------------+  |
|                     │                                        │                    |
|                     ▼ Governs                                ▼ Governs            |
|        [Global System Configuration]             [Folder-Specific Entities]       |
|        - Provisioning users & groups             - Viewing / Editing Assets       |
|        - Registering Machine Templates           - Managing Queues & Items        |
|        - Allocating Runtime Licenses             - Starting & Stopping Jobs       |
|        - Inspecting Global Audit Logs            - Creating Process Triggers      |
+-----------------------------------------------------------------------------------+

Tenant-Level Roles

Tenant roles grant permissions for tenant entities. Holding a tenant role does not by itself give access to the data inside folders:

  • Orchestrator Administrator: all tenant-level permissions, for the people who manage every tenant entity. Combined with Folder Administrator at the folder level, it replaces the older mixed Administrator role, which is no longer available for new tenants.
  • Allow to be Folder Administrator, Allow to be Automation Developer, Allow to be Automation Publisher, and Allow to be Automation User: the minimum tenant permissions that go with the folder role of the same name. UiPath's documentation pairs them: an account with the tenant role should also get the matching folder role, and the other way round.
  • The deprecated mixed Robot role is replaced by Allow to be Automation User at the tenant level plus Automation User at the folder level.

Built-in Folder-Level Roles

Folder roles grant contextual permissions strictly within the folders where the user or group is assigned:

Folder RoleIntended AudienceKey Permissions & Operational Boundary
Folder AdministratorAutomation Leads & Department AdminsFull control over folder entities: create/edit/delete processes, triggers, queues, assets, and storage buckets. Can assign folder roles to other users within that folder.
Automation DeveloperRPA Engineers & Workflow AuthorsRead and execute access: view assets, queues, and storage buckets; create and manage test sets; start debugging jobs; inspect job logs. Typically lacks permission to delete production assets or alter folder user mappings.
Automation PublisherDevelopers who publish but do not manage the folderCan publish processes to Orchestrator; assigned on top of Automation User to both publish and run.
Automation UserBusiness Users & Attended WorkersMinimal execution rights: can view assigned processes and trigger attended jobs via UiPath Assistant. Cannot view credential values, modify queues, or alter triggers.

Designing Custom Granular Roles

Enterprise security policies frequently dictate the creation of custom folder roles adhering to the principle of least privilege. For example:

  • Queue Data Auditor: Assigned Queues.View and Transactions.View, allowing compliance officers to inspect transaction results without granting rights to trigger jobs or view encrypted assets.
  • Asset Manager: Assigned Assets.View, Assets.Create, and Assets.Edit within a specific staging folder, allowing environment managers to update configuration strings without exposing workflow deployment permissions.

4. Dynamic Robot Allocation & Machine Templates

In legacy Classic Folders, a Robot was defined as a rigid trinity: [Windows Domain\Username] + [Host Machine Name] + [Dedicated License]. If that specific physical machine was rebooted or offline, the robot was completely incapacitated, even if ten other identical runner machines sat idle.

Modern Folders introduce Dynamic Robot Allocation, which completely decouples the user identity from the execution host machine.

+-----------------------------------------------------------------------------------+
|                         DYNAMIC ROBOT ALLOCATION DYNAMICS                         |
|                                                                                   |
|  [Tenant Machine Pool]                       [Modern Folder Scope]                |
|  Machine Template: "Fin_Pool_Template"       Assigned Folder: "Finance/AP"        |
|  Capacity: 10 Unattended Runtimes            Assigned User: "CORP\svc_rpa_ap01"   |
|             │                                                 │                   |
|             └───────────────────────┬─────────────────────────┘                   |
|                                     │                                             |
|                                     ▼                                             |
|                           [Job Execution Trigger]                                 |
|                                     │                                             |
|                                     ▼                                             |
|                 Orchestrator inspects available host agents                       |
|                 connected via "Fin_Pool_Template"                                 |
|                                     │                                             |
|             ┌───────────────────────┼───────────────────────┐                     |
|             ▼                       ▼                       ▼                     |
|     [Host VM: Node-01]      [Host VM: Node-02]      [Host VM: Node-03]            |
|       Status: BUSY            Status: AVAILABLE       Status: BUSY                |
|                                     │                                             |
|                                     ▼                                             |
|                     Dynamic Allocation Matches:                                   |
|                     - Target Host: Node-02                                        |
|                     - Session: Launch Windows session for CORP\svc_rpa_ap01       |
|                     - Package: Download & Execute InvoiceProcessing.xaml          |
+-----------------------------------------------------------------------------------+

The Mechanics of Machine Templates

  1. Machine Template Creation: An administrator defines a Machine Template at the Tenant level (e.g., Prod_Unattended_Pool) and specifies the number of allocated Unattended Runtimes (licenses).
  2. Unified Machine Key / Client Credentials: The template generates a single set of connection credentials (Client ID and Client Secret or Machine Key). This single credential set is deployed across an entire farm of runner virtual machines (e.g., 50 cloud VMs in an Azure Virtual Desktop or AWS auto-scaling group).
  3. Folder Assignment: The Machine Template is assigned to one or more Modern Folders. This grants the folder permission to execute jobs across that machine pool.
  4. User / Robot Account Provisioning: Service accounts (Robot Accounts) are assigned to the Modern Folder with their corresponding Windows execution credentials configured (Domain\Username and Windows Credential Asset).
  5. Dynamic Runtime Binding: When Orchestrator triggers an unattended job in the folder, it dynamically scans the connected machines. It routes the job to any available host machine registered under the template, dynamically opening a secure Windows desktop session under the designated robot account.

High-Density Unattended Robots

Dynamic robot allocation natively supports High-Density Robots on Windows Server operating systems running Remote Desktop Services (RDS):

  • A single powerful Windows Server host connects to Orchestrator using a Machine Template configured with multiple runtimes.
  • Orchestrator simultaneously spawns multiple independent Windows user sessions on the same physical host machine.
  • Multiple robot accounts execute distinct automation processes concurrently in completely isolated desktop sessions, maximizing hardware utilization and drastically reducing infrastructure licensing costs.

5. User-Robot Inheritance & Directory Synchronization

Enterprise identity governance requires seamless synchronization between corporate identity providers (IdPs) and UiPath Orchestrator.

Directory Integration via SCIM & SAML / OIDC

UiPath Orchestrator integrates directly with enterprise directory services (Microsoft Entra ID, PingFederate, Okta) via SAML 2.0 / OpenID Connect for authentication and SCIM (System for Cross-domain Identity Management) for automated provisioning:

  • Group-Based Access Control: Administrators map corporate Active Directory / Entra security groups (e.g., SG_RPA_Finance_Developers, SG_RPA_AP_BusinessUsers) directly to Orchestrator.
  • Zero Manual User Provisioning: When a new developer joins the organization and is added to the corporate Entra group, they automatically inherit the corresponding folder roles upon their first login to Orchestrator or UiPath Studio.
  • Deprovisioning: When an employee changes department or leaves, removing them from the directory group removes the folder access that the group granted.

Subfolder Access: Union of Privileges

Orchestrator applies access downward through the folder tree:

  • An account assigned at a parent folder automatically gets access, with the roles assigned there, to every subfolder under it.
  • You can add roles in a subfolder on top of the inherited ones, but inherited roles cannot be removed in the subfolder.
  • Assigning an account directly to a subfolder gives it access to that subfolder and everything below it, without access to the parent or to sibling folders.

UiPath calls this the union of privileges model: an account's rights in a folder are everything granted there plus everything inherited from above. There is no switch that cuts a subfolder off from its parent. To isolate a sensitive area such as payroll, do not assign the broad group at the parent level; assign the payroll team and its robot account directly to the sensitive subfolder instead.

[Parent Folder: HumanResources]
  Direct: Group_HR_All (Automation User)
  │
  ├── [Subfolder: Onboarding]
  │     Inherited: Group_HR_All (Automation User)
  │     Added here: Group_RPA_Devs (Automation Developer)
  │
[Separate top-level folder or branch: HR_Restricted]
  └── [Subfolder: ExecutivePayroll]
        Direct only: Group_HR_Executive (Automation User),
                     Payroll robot account
        Group_HR_All has no access, because it was never
        assigned on this branch.

6. Enterprise Governance and Migration Strategies

Organizations operating large automation estates adhere to standardized Modern Folder design patterns:

  1. Environment Segregation: Separate Development, Test/UAT, and Production either into completely distinct Orchestrator Tenants (recommended for strict regulatory compliance and audit isolation) or top-level Root Folders with distinct machine pools and credential stores.
  2. Segregation of Duties (SoD): Developers must never hold Folder Administrator or Jobs.Create permissions in Production folders. Deployment to Production is restricted to CI/CD service accounts or designated Release Managers.
  3. Robot Accounts over Personal Credentials: Always execute unattended production jobs under non-interactive Robot Accounts rather than personal employee user accounts, preventing process failure when employees rotate passwords or depart the enterprise.
Loading diagram...
Modern folder hierarchy, entity scopes, and inherited access
Test Your Knowledge

Which of the following resource groupings consists EXCLUSIVELY of Orchestrator Folder Entities?

A

Users, Machine Templates, Assets, and Webhooks.

B

Roles, Storage Buckets, Packages, and Robot Accounts.

C

Processes, Queues, Assets, Storage Buckets, and Triggers.

D

Machine Templates, Directory Groups, Licenses, and Jobs.

Test Your Knowledge

What is the primary operational difference between the built-in Folder Administrator role and the Automation User role in a Modern Folder?

A

Folder Administrators can manage processes, triggers, queues, and assets within the folder, whereas Automation Users can only view processes and execute attended automations via UiPath Assistant.

B

Folder Administrators can modify tenant-wide licensing settings, whereas Automation Users can only create subfolders.

C

Folder Administrators are restricted to running Studio debug sessions, whereas Automation Users manage Machine Templates.

D

Automation Users have full permission to delete production assets, whereas Folder Administrators have read-only access.

Test Your Knowledge

How does Dynamic Robot Allocation in Modern Folders execute an unattended job across an enterprise machine pool?

A

It permanently binds a specific Windows user account to a single physical machine MAC address during project compilation.

B

It requires developers to hardcode the destination host machine IP address inside Data\Config.xlsx prior to publishing.

C

It forces all robots to execute sequentially on the primary Orchestrator web server host machine.

D

It dynamically pairs a designated user or robot account with any available host machine connected under the folder's assigned Machine Template.

Sections you finish are checked off in the contents.