...
This is where the CoreOne Advanced Permission Management comes into place. This optional module allows you to create your own security rules. A security role contain two things, the view permissions and the data access permission. The view permissions are used across all UIs to handle who has access to which views and which actions. The access permissions are used to determinate what data is available to the user or service within the views or APIs. This way you can give certain users access to view and limit them to a subset of the available data.
Built-In Security Roles
Out of the box the CoreOne Suite is deployed with four built-in security roles:
...
CoreOne Suite Security Role
...
Access Level inside CoreOne Suite
...
Available in version
...
Description
...
CoreOne Suite Administrator
...
Full Access
...
>= 4.0
...
Full access to the whole CoreOne Suite
...
CoreOne Suite Approvals
...
Access to approval requests where the assignee is involved
...
>= 5.1
...
Assign this role to users that need to take part in an approval process.
...
CoreOne Basic Access
...
General login access
...
>= 7.0
...
Allows a user to use his SSO account
...
CoreOne Suite Computermanagement Admin
...
-
...
< 7.0
...
deprecated
...
CoreOne Suite DHCP Administrator
...
-
...
< 7.0
...
deprecated
...
CoreOne Suite Legal Entity Activate
...
Activate a legal entity button
...
>= 7.0
...
Allows a user to activate a legal entity in the CoreOne Self-Service Portal
...
CoreOne Suite Legal Entity Confirm Changes
...
Confirm changes to a legal entity
...
>= 7.0
...
Allows a user to confirm changes to a legal entity in the CoreOne Self-Service Portal
...
CoreOne Suite Legal Entity Delete
...
Access to legal entities in which context the security role is assigned to
Delete rights to legal entities in which context the security role is assigned to
...
>= 7.0
...
Allows a user to delete a legal entity for which this security rule is assigned to
...
CoreOne Suite Legal Entity Edit
...
Access to legal entities in which context the security role is assigned to
Update rights to legal entities in which context the security role is assigned to
...
>= 7.0
...
Allows a user to update a legal entity for which this security rule is assigned to
...
CoreOne Suite Legal Entity Employment Create
...
Access to legal entities in which context the security role is assigned to
Create rights to employments in which context the security role is assigned to
Read rights to all employment types
...
>= 7.0
...
Allows a user to create new employments for the the legal entity for which this security rule is assigned to
...
CoreOne Suite Legal Entity Employment Delete
...
Access to legal entities in which context the security role is assigned to
Delete rights to employments in which context the security role is assigned to
Read rights to all employment types
...
>= 7.0
...
Allows a user to delete an employments for the the legal entity for which this security rule is assigned to
...
CoreOne Suite Legal Entity Register
...
Read rights to organization unit types
...
>= 7.0
...
Allows a user to create a new legal entity in the state of activation pending
...
CoreOne Suite Manage Representations
...
Full access to representations where he is apart of
Full access to representation relationships where he is apart of
...
>= 7.0
...
Allows the user to create and manage representations and delegations
...
CoreOne Suite OpenID Service
...
>= 7.0
...
CoreOne Suite Patch Management Admin
...
-
...
< 7.0
...
deprecated
...
CoreOne Suite Patch Management User
...
-
...
< 7.0
...
deprecated
...
CoreOne Suite Self-Service User
...
Access to the Self-Service Portal
Access to his own Core Identity
Access to his own Identities
Access to orderings and approvals
...
>= 4.0
...
Gives users basic rights to perform actions like resetting the password for his own accounts or ordering a role for himself
...
CoreOne Suite Service Desk
...
Access to basic Identity Management and Management Features
...
>= 4.0
...
Can be used to give Service Desk employees basic rights such as seeing all employees, reset passwords and so on.
Data Access Permissions
Data access permissions are configured by specifying the entity type, a security mode and a security filter. The entity type defines to which entity, i.e. a Core Identity or a Role, a user has access to. The security mode defines the nature of the access such as read, write, delete or similar. And finally the security filter specifies which conditions have to be met in order to give access. This can be anything from full access to only if a specific condition is met. You will find more on that in the https://itsense.atlassian.net/l/c/MVGBrzfx Data Access Permissions section. But it’s important to understand that you can configure security filters based on relations and other attributes of the entity.
...
If you use any of our default security roles, you have to be aware that they can change. They are intended to cover a standard use case as described in the documentation. But even though that standard use case might match your use case today, does not mean it will automatically match your use case after an update. We might add some rights to the default security rule that will not match your use case, so you should check the release notes carefully.
Creating Custom Security Roles
You can create custom security roles in the Admin UI. Go to Administration
-> Securityroles
and click create. Make sure to choose a good name for you rule.
This will automatically create a Ressource with the same name. You can use this ressource to assign your new security rule to core identities.
Best practices
Testing, testing, testing
...