SD-WAN Orchestrator consists of roles with different set of privileges. As an Operator Super user, you can assign a pre-defined role to a user. Role Customization allows you to customize the existing set of privileges for the Functional roles.

You can customize only the Functional roles and not the Composite roles. When you customize a Functional role, the changes would impact the Composite roles that consist of the customized Functional role. For more information, see Functional Roles.

To activate or deactivate a Partner super user to customize the role privileges of other Partner users and Enterprise users of the Partner, see Configure Partner Information.

To activate or deactivate an Enterprise super user to customize the role privileges of other Enterprise users, see Configure Customers.

The Role customization is applied to the Functional roles as follows:

  • The customizations done at the Enterprise level will override the customizations made at the Partner or Operator level.
  • The customizations done at the Partner level will override the customizations made at the Operator level.
  • Only when there are no customizations done at the Partner level or Enterprise level, the customizations made by the Operator are applied globally across all users in the SD-WAN Orchestrator.

In the Operator portal, click Role Customization.

You can perform the following operations:

  • Show Current Privileges – Displays the current Functional role privileges. You can view the privileges of all the Functional roles and download them in CSV format. For an Enterprise, it displays the privileges of only functional roles for which the customer has licenses.
  • New Package – Enables to create a new package with customized role privileges. See Create New Customized Package.
  • Reset to System Default – Allows to reset the current role privileges to default settings. Only the customized privileges applied to the Functional roles in the Operator portal are reset to the default settings. If your partners or customers have customized their Functional role privileges in the Partner or Enterprise portal, those settings remain the same.

Click Actions to perform the following activities:

  • Upload Package – Allows to upload a customized package. See Upload Customized Package.
  • Clone Package – Enables to create a copy of the selected package.
  • Modify Package – Enables to edit the customization settings in the selected package. You can also click the link to the package to edit the settings.
  • Delete Package – Removes the selected package. You cannot delete a package if it is already in use.
  • Apply Package – Applies the customization available in the selected package to the existing Functional roles. This option modifies the role privileges only at the current level. If there are customizations available at the Operator level or a lower level for the same role, then the lower level takes precedence.
You can also click the Download Icon prior to the package name to download the package as a JSON file.
Note: Role customization packages are version dependent, and a package created on an Orchestrator using an earlier software release will not be compatible with an Orchestrator using a later release. For example, a role customization package created on an Orchestrator that is running Release 3.4.x does not work properly if the Orchestrator is upgraded to a 4.x Release. Also, a role customization package created on an Orchestrator running Release 3.4.x does not work properly when the Orchestrator is upgraded to 4.x.x Release. In such cases, the user must review and recreate the role customization package for the newer release to ensure proper enforcement of all roles.