Skip to main content
Version: 8.8 (unreleased)

Access control

If authorization control is enabled for your Orchestration Cluster, users require the following authorizations to work with Identity.

note

If you already have another administration user, they can assign these in the Identity UI. See the introduction to authorizations for a list of all available authorizations.

Mandatory authorizations

The following mandatory authorizations are required to work with Identity:

Authorization typeResource typeResource IDPermission
Identity component accessComponentidentity or * (for access to all web components)ACCESS

Authorizations per resource

The following authorizations are required to manage each User, Group, Role, Authorization, Mapping Rule, and Tenant resource:

Authorization typeResource typeResource IDPermission
Create/Read/Update/Delete resourceOne of User, Group, Authorization, Mapping Rule, TenantID of the resource or * (for access to all resources and to create resources)Any of CREATE, READ, UPDATE, DELETE