Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space DEV and version r0810

...

Info

NOTE: Authorization manages access to object types. It does not cover access to individual objects of a specified type. For example, access to a specific flow is governed by ownership of the flow (owner) and sharing of the flow by the owner (to a collaborator). If a flow is shared with a user who is not permitted to access flows, then the user cannot access the flow.

Account Roles

A member can have one of the following roles:

Member role

The Member role enables the user to access all product functionality that is enabled for the product edition.

Admin role

The Admin role enables all capabilities of the Member role, plus:

...

D s webapp

...

Resource Roles and Privileges

...

D s webapp

...

Info

NOTE: The Admin role is a super-user. It should be granted on a limited basis.

Resource Roles and Privileges

Access to 

D s item
itemobjects
 is governed by roles in the user account. 

  • A

    role

    is

     is a set of zero or more privileges.

     
  • A privilege is an access level for a type of object. 
  • A  A user may have one or more assigned roles in it

    Info

    NOTE: Roles are additive. If a user has multiple roles, the user has access at the highest level of privileges from each role.

  • privilege is an access level for a type of object. A role may have one or more privileges assigned to it.

  • All accounts are created with the default role role, which provides a set of basic privileges.

Standard roles

default role

All new users are automatically assigned the default role role. By  By default, the default role enables full access to all types of of 

D s item
itemobjects
.

  • If you have upgraded from a version of the product that did not support authorization, the default role  role represents no change in behavior. All existing users can access access 
    D s item
    itemobjects
     as normal.

Since roles in a user account are additive, you may choose to reduce the privileges on the default role  role and then add privileges selectively by creating other roles and assigning them to users. See the example below.

...

Info

NOTE: In future releases of the software, additional objects may be made available. A level of access may be defined in the default role. No other roles will be modified.

Workspace admin role

...

  • access to all 
    D s webapp
     objects, unless specifically limited. See Resource Roles and Privileges below.
  • administration functions and settings within the 
    D s webapp
    . 
Info

NOTE: This role enables for the user owner-level access to all objects in the project or workspace and access to all admin-level settings and configuration pages in the admin console. This role should not be assigned to many users. At least one user should always have this role.

Custom role(s)

As needed, administrators can create custom roles for users of the project or workspace. For more information, see Create Role.

Privileges

For a complete list of privileges for each type of object, see Privileges and Roles Reference.

...

In the following model, three separate roles have been created. Each role enables the highest level of access to a specific type of object. 

The default object  object has been modified:

  • Since all users are automatically granted the default role role, the scope of its permissions has been reduced here to view-only. 
  • There is no viewer privilege  privilege for Plans ( noneauthor). 

...

Privilege/RoledefaultRole ARole BRole CNotes
Flowsviewerauthornonenone
ConnectionsviewernoneauthornonePaid product editions only
PlansnonenonenoneauthorPremium product editions only

...

  • User can create, schedule, modify, run jobs, and delete flows (full privileges).
  • User can create, modify, and delete connections (full privileges).
  • User can create, schedule, modify, run jobs, and delete plans (full privileges).

D s also
labelauthorizationroles