Introduction
The Roles define the access permissions of each user in your organization to each resource. You can create multiple roles pertaining to how you want to control the resources in the organization. The administrator role is the highest level that can access and control each resource. You can assign more than one role to a user or user group while creating them in your organization. At the same time, do more actions like delete and search from the Roles page.
Creating roles
To create roles:
- Select Setup > Account Management > Roles.
- Click +Add.
The CREATE NEW ROLE page is displayed with six tabs. - Enter the following details for the Role Details tab and click Next:
- Name: Refers to the name of the role
- Scope: Refers to the type of user: Partner or Client.
If you select Partner, enter Description.
If you select Client, enter the following details and Description:- Applied To: Refers to the selection of clients in your organization. You can either assign the role to all clients or to a selected client in your organization.
- Client: Refers to the list of clients depending on the option selected in the Applied To field.
- If you select All Clients for Applied To field, then Everyone is the default selection for Client.
- If you select Selected Client, then from the drop-down option of Client you need to select a client.
- Description: Refers to the details provided to describe the role.
The User Group tab is displayed.
- From the User Group Details tab, select the User Groups and Users and click Next.
Note: Click Skip if you do not want to select user groups or users. The Resource Group Details tab is displayed if you had selected Clients and the Assign Clients tab is displayed if you had selected Partners in the Scope. - From the Assign Clients tab, select one of the following three options to apply visibility of clients to the role you are creating and then click Next:
- All Clients: Select this option if you want all clients in the partner to view the users in this role.
- Selected Clients: Select this option if you want the role to have the visibility of specific clients in the Client List.
The screen displays Assign Clients section after you select the Selected Clients option.- Select the desired client from Available Clients and move to the Assigned Clients section.
- From the Resource Group Details tab, select one of the following three options to apply visibility of devices
to the role you are creating and then click Next:
- All Resources: Lets a role have visibility of all resources in the client list.
- No Resources: Prevents the role from having visibility of resources in the client list.
- Resources: Lets a role have visibility of a specific resource. Resource Group screen displays Select Resource Groups and Select Resources sections after selecting the Resources option.
- Select Resource Groups and Resources: Lets a role have visibility of only the selected resources in the client list.
Perform the following steps to select resources:- Select desired resource group from Select Resource Group > Available Resource Groups and move to Assigned Resource Groups box.
- For Select Resources, select a client from Select Client and then device category from Select Device Type.
The devices are displayed with details. - Select the desired devices and click forward arrows to move to Assigned Devices.
Assign Credentials tab is displayed.
- From the Assign Credentials tab, select one of the following three options to apply visibility of credentials
to the role you are creating and then click Next:
- All Credentials: Lets a role have visibility of all credentials in the client list.
- No Credentials: Prevents the role from having visibility of all credentials in the client list.
- Selected Credentials: Lets a role have visibility of only the selected credentials in the client list.
Perform the following steps to select credentials:- Select desired client from Select a Client drop-down options.
The list of available credentials of the selected client appear with Client Name. - Select the desired credentials and click forward arrows to move to Assigned Credentials. Assign Shared Dashboards tab is displayed.
- Select desired client from Select a Client drop-down options.
- From the Assign Shared Dashboards tab, select any shared dashboard and click Next.
Assign Permission Sets tab is displayed with a list of Permissions Sets and related details.
Note: You can now restrict other users from accessing the default dashboards. Users can access only those default dashboards that are added in the Assigned dashboard section. - Select the desired permissions and click Save.
The ACCESS DETAILS page displays the new role with the details.
You can click Edit to modify.
Notes
- All shared dashboards assigned to any role are visible only to the assigned user with the respective role permissions. The user can view the list of dashboards of the assigned role under the Shared Dashboards list.
- Users can access a shared dashboard only using Roles. OpsRamp performed a one-time migration process to transfer all existing partner and client users (who had access to shared dashboards before OpsRamp 5.4.0) to the Partner Dashboard Share Role and Client Dashboard Share Role, respectively.
- All existing users can continue to access the shared dashboards using the dashboard share roles created by OpsRamp. At the same time, the Partner Dashboard Shared Role and Client Dashboard Shared Role are assigned to Partner Dashboard Share Permission Set and Client Dashboard Share Permission Set, respectively.
Deleting roles
To remove a role, from the console:
- Select Setup > Account Management > Roles.
- From the Roles page, select the desired roles and click Remove.
- Click Yes to delete.
Note
The Delete option deletes roles that are no longer used.Searching roles
Roles can be searched by the role name with the Search and Advanced Search options.
- Search: Used to search for a single role.
- Advanced Search: Used to search for multiple roles (typically, roles that share the same criteria).