Realm-based access control and administration

Airlock IAM offers two models to limit administrators to a subset of users by realm:

  • Realm administration: A flexible model based on first-class realm attributes, realm roles, and delegations of fine-grained permissions. In this model, administrators can manage users across one or more realms (1: n), depending on the roles and delegations assigned to them.
  • Simple realm administration: A lightweight model based on a realm context-data item assigned to both administrators and users. Access is granted through ordinary roles. In this model, an administrator can manage only users who belong to the same realm as the administrator (1:1).

The two models cannot be combined in one Adminapp instance.

 
Notice

The simple realm administration model is a legacy model. We recommend using the realm administration model whenever possible.

This chapter decribes both models and explains how to configure them.

Realms versus tenants

Realms provide a way to segregate users. Airlock IAM also supports user segregation through tenants. The following table compares realms and tenants, including their respective use cases, to help you determine which approach best suits your setup.

Realm

Tenant

Use case

  • One IAM instance with one database schema.

This use case supports the distributed administration of end-users in a shared application landscape.

  • Multiple IAM instances (or one instance with multiple contexts acting as distinct instances) share one database schema.

This use case allows saving costs if database pricing is based on database schema.
 

Limitation: All IAM instances must always use the same IAM version.

User base

Suitable for managing end users within the same organization through different administrative entities or organizational units.

Suitable to manage end-users from different organizations.

Operation

Realms are created at runtime and do not require activation of a new IAM configuration.

Tenants are explicitly configured. Any change requires activating a new IAM configuration.

Security

  • Limited segregation on the software layer. Superadmins have access to all users and all realm administrators.
  • No segregation on the user level.
  • Strong segregation on the database layer over all tables and without exceptions.

Administration

  • A superadmin can administer administrators across all realms.
  • Administrators can also manage users across multiple realms, depending on the roles and delegations assigned to them.
  • There is no superadmin across tenants. Each tenant must be administered separately.