1. Description
Here you select roles and their permissions for this SSO profile.
Consists of the following elements:
-
Create tool (Fig. 1.(1));
-
Records registry refresh tool (Fig. 1.(2));
-
Records registry (Fig. 1.(3));
-
Pagination (Fig. 1.(4)).
When creating a new SSO profile, the following users/roles are added to the records registry, depending on the following:
-
if there are no entries in the Managed by records tab of the "sso" section — only the User who creates the profile.
-
if there are entries on the Managed by records tab of the "sso" section:
-
the user who creates the profile;
-
those Grantees are listed on the Managed by records tab in the "sso" section for whom the Grantor is the creator of the profile. All the Roles of the User who created the new profile and the User himself are considered as the Grantor.
-
The entered Roles and their rights concerning this profile are used when Managed by records is enabled on the Objects page (switch in the On position) in the "sso" section.
The Permissions tab shows only the Roles and Users that you can view. If you do not have permission to view other Users, you will only see yourself and your Roles on the Permissions tab, if they are configured there.
1.1. Create tool
The add button is used to add a role. Clicking the add button
To quickly find the needed user or role, the Role field can be used as a search field: enter the name of the user or role you're looking for, and the dropdown list will display only users or roles containing the entered name.
Users and roles can be distinguished by icons:
-
- role;
-
- user.
Clicking on a specific role or user selects it. Clicking the Add button adds the selected role to the records registry. Clicking the Close button closes the modal window without adding an entry. Clicking the close button (
An added role or user has the following parameters by default:
-
Read – Allow;
-
Edit – Forbidden;
-
Delete – Forbidden.
These parameters can be changed by selecting the required value in the column's dropdown list.
The user who created the new SSO profile has Allow with delegation access for all actions.
1.2. Records registry refresh tool
Updating the records registry table is performed by clicking the refresh button.
1.3. Records registry
Consists of the following columns:
-
Name — role name;
-
Read — dropdown list with read permissions;
-
Edit — dropdown list with edit permissions;
-
Delete — dropdown list with delete permissions.
The delete
Access options:
-
Allow — the action is allowed;
-
Allow with delegation — allowed with delegation (the user has the permission themselves and can grant it to others);
-
Forbidden — the action is forbidden.
1.4. Pagination
It consists of the Rows per page field, which indicates the number of entries (it is possible to set from 1 to 1000) per page, and forward and backward buttons for switching pages.
2. Opportunities
2.1. Adding a role or user to the list of those with access to the SSO profile
|
Goal |
Add a role that will have access to the SSO profile |
|---|---|
|
Preconditions |
|
|
Steps
|
|
|
Result |
The modal window closes. The selected role is added to the registry. |
2.2. Removing a role or user from the list of those with access to the SSO profile
|
Goal |
Remove a role from the list of those with access to the SSO profile |
|---|---|
|
Preconditions |
|
|
Steps
|
|
|
Result |
The Role or User has been removed from the registry. |
2.3. Changing permission for actions on the SSO profile
|
Goal |
Change permission for actions |
|---|---|
|
Preconditions |
|
|
Steps
|
|
|
Result |
The permission for the action is changed in the column. |