- Print
- PDF
Use cases
- Print
- PDF
Here are some of the use cases of the policy-based access control.
Use case 1
Assigning an application management access to a test user.
The Britive navigation tiles are displayed as per the access granted to the user. Once an Admin creates any user, that user has bare minimal access to the app, just the MyAccess tab is available.
An Admin creates a TestUser from Admin->Identity Management tab.
To grant access to the application management for this user TestUser, follow this procedure:
- Click on Admin->Role & Policy Management.
- Click on Policies tab.
- Click Add Policy to create a new policy.
- Enter AppAdminPolicy as Policy Name.
- Click Members-> Users.
- Select *Test User * in the Select Users.
- Click Permissions, select Add Existing Permission and select ApplicationAdminPermission and click Add.
- Click Save and Enable to enable this policy.
- Log in as a TestUser. In the navigation menu, you can see Admin along with MyAccess.
- Click Admin to see the Application and Access Profile Management tile available to TestUser to manage all applications.
Use case 2
Adding a member (a test user) to a predefined policy TenantAdminPolicy to grant that user the system administration access.
TenantAdminPolicy is a predefined policy that provides system administration access to the assigned members. By default, root user is added to this policy. To add a test user 'TestUser' to this policy, follow this procedure:
- Click on Admin->Role & Policy Management.
- Click on the Policies tab.
- Search and select TenantAdminPolicy from the list of policies.
- Click Manage policy.
- Click Edit to update this policy.
- From Users -> Select Users and enter the test user name.
- Click Save.
- Log in using the test user to see all the system administrative access given to the user.
Use case 3
Creating a policy to give view/manage access to a particular application in Application and Access Profile Management.
We need to add two permissions in a policy:
- One permission for listing all resources (*)
- One permission for a specific application with View/Manage permission
- Click on Admin->Role & Policy Management.
- Click on the Permissions tab.
- Select apps in the Consumer drop-down.
- Click Add Permission to add customized permission.
- Select Applications in the Consumer list.
- Select All in the Resources list.
- Select apps.app.list in the Action list.
- Click Save.
- Click Add Permission again to create a new permission.
- Select Applications in the Consumer list.
- Select a specific application from the Resources list.
- Select apps.app.view and apps.app.manage in the Action list.
- Click Save.
- Select Policies from the Role & Policy Management.
- Click Add Policy.
- Enter the policy name and description.
- In the Permissions tab, select Add Existing Permission and select the permission created just above these steps.
- Click Add.
- Click Save & Enable to save this customized policy.
- Login using the test user and click the Application and Access Profile Management tile.
- The user can access only the application selected while creating permission during step 5.2, the access is denied for the rest of the applications.