Role-based access control in the Adminapp
This chapter focusses on role-based access control to the Adminapp. Role-based access control is based on predefined admin roles that are assigned to predefined actions in the Config Editor.
Adminapp access is permitted based on predefined roles assigned to an administrator. These roles are specified and assigned to actions in the Config Editor. They are fixed, set during configuration; changing roles and corresponding actions needs a configuration change.
The admin roles are assigned to administrators in the Adminapp with the Administrators Management feature.
Example admin roles are:
- useradmin
- tokenadmin
- helpdesk
- ...
In the Config Editor, you define these roles under Adminapp >> Administrators >> Administrators Management.
Airlock IAM does not limit the set of administrator roles; they can be chosen arbitrarily.
It is possible to translate the configured role names into languages not covered by the Adminapp UI by default. For information about how to add translations, see Customizing text elements in the Adminapp UI.
Example actions are:
- View User Details (technical name:
viewUser) - Lock User (technical name:
lockUser) - View Log Files (technical name:
viewLog) - ...
In the Config Editor, the available admin roles are assigned to actions under Adminapp >> Access Control.
If multiple roles are assigned to an action, an administrator must hold at least one of these roles to perform the action.
Example
The following screenshot provides an example of role-action combinations related to User Management. Here, the helpdesk role can only perform a limited set of user actions, whereas the useradmin role has access to almost all user actions.
Segeration of duties and users
To provide fine-granular access to user management and user groups, Airlock IAM offers segration of duties and users:
- Segregation of duties allows to assign a combination of roles to each administrator.
- Segregation of users means that administrators can be restricted to managing specific sets of users.
Both concepts are explained in the next articles.
