You can manage the user privileges for working with tags and categories. The procedure for assigning permission to tags is the same as the procedure for tag categories.

Permissions for tags work the same way as permissions set for vCenter Server inventory objects. To learn about permissions and roles, see vSphere Security .

You can set permissions on common tag operations to manage the operations over the inventory objects. You must have vSphere administrator credentials to set and manage permissions for tags and organize user's activities. When you create a tag, you can specify which users and groups can operate with that tag. For example, you can grant administrative rights only to administrators and set read-only permissions for all other users or groups.


Grant the privilege.InventoryService.Tagging.label privilege to users that administer tags and tag categories


  1. Log in to vSphere Web Client with administrator credentials.
  2. From the vSphere Web Client Home, click Tags & Custom Attributes.
  3. Click the Tags tab.
  4. Select a tag from the list, right-click the tag, and select Add Permission.

    You see a list with all default permissions for the selected tag.

  5. Click the Add Permission Icon icon to add a permission to the existing list.

    The Add permission dialog box appears.

  6. In the Users and Groups pane, click Add, select all the users and groups you want to add, and click OK.
  7. (Optional) Select a user or a group from the list and select a role from the Assigned Role list.
  8. (Optional) Select Propagate to children to propagate the privileges to the children of the assigned inventory object.
  9. Click OK to save the new tag permission.