You use roles to manage access control for user accounts in VMware Telco Cloud Service Assurance.
In this procedure, you add a new role and assign administrative permissions to the role.
Procedure
- Navigate to Administration > Access > Roles.
- Click Add.
- Enter the Name of the role.
- Provide description about the role in the Description.
- In Policy Assignment section:
- Select the policy from the drop-down.
Note: Admin can select any policy from the list. Predefined policy "default_wo_filter" allow access to all data.
- Provide the name for the policy assignment.
- Provide the description for the policy assignment.
- Select the policy from the drop-down.
- In the Filter Details section select the proper value for the following:
- Select the required Property from the drop-down.
- Select the Expression type from the drop-down.
- Provide the Value.
Note:- For some specific boolean columns, select Yes or No from the drop-down.
- For a selected integer or string column, provide the exact value as input.
- To add multiple values for a single attribute, click "+" icon. The operation is "OR" between the values like ("ROUTER" "MATCHES" "SWITCH OR ROUTER "). To remove any attribute, click the cross icon.
- Within the filter set, all operations are "AND" operations and between the filter set all operation are "OR" operation.
- For one attribute, you can have multiple values.
- In the Remediation Details field, select Yes or No from the drop-down menu.
- In the Category field, select a category for the Remediation Details.
- Select a Group name, in the Group Assignment.
Note: Group name must match exactly with LDAP/KeyClock Group. Group names are case-sensitive.
- In the Permission Assignment section, select at least one Page Access option from the Operation-UI tree.
- In the Permission Assignment section, under Dashboard & Reports click Browse Dashboard.
- From the list of dashboards and dashboard folders, select View Permission and/or Edit Permission for the role.
Note:
- If you provide an edit permission to a folder, then the user will be able to view and edit all the dashboards present in that folder.
- If you provide a view permission to a folder, then the user can only view the dashboards in that folder. You can also choose to provide edit permission to a particular dashboard in that folder for the user to have an edit permission for that dashboard alone.
- Click Assign Permissions.
- Click Save Role.
Note: The user will be able to view or edit the dashboards and reports based on the dashboards or folders that you select in step 10 and the permission you provide in step 11. If you select a dashboard in step 10 then the user will be able to view or edit that dashboard alone. If you select a folder in step 10 then the user will be able to view or edit all the dashboards available in that folder.