Delegated Admin
A tenant admin has all the access rights to all the consumers. A delegated administrator has restricted access specific to a consumer. In this case, the consumer is Secrets Manager. You can apply policies on the resources of this consumer. This admin can delegate another user to be a Secrets Manager admin, and a Secrets Manager admin can then delegate other users to be node-wise administrators.
Steps to assign a delegated admin:
Adding a User
Login to Britive as a tenant admin.
Click on System Admin -> Identity Management.
Click on the Add User button.
Enter the user details on the Add User page for the delegated Secrets Manager admin.
Click Add User.
Delegating a Secrets Manager Administrator
Login to Britive as a tenant admin.
Click on System Admin->Role & Policy Management.
Click on the Policies tab.
Click Add Policy to create a new policy.
Enter Policy Name.
Click Members->Users.
Select a delegated admin user in Select Users.
Click Roles and select Add Role and select the predefined role SMAdminRole,
Click Add.
Click Save and Enable to enable this policy.
Log in as a delegated admin user. In the navigation menu, you can see Admin along with MyAccess and My Secrets.
Click Admin to see the Secrets Manager tile available to this delegated admin user to manage all the secrets.
Delegating another user to manage a particular node in the vault
Log in to Britive as a delegated secrets manager admin.
Click on Admin->Secret Management.
Click on the Britive Vault tab.
Create Add Folder in the vault.
Click Add Policy to create a new policy under this node.
Enter Policy Name.
Click Members-> Users.
Select a delegated node admin user in the Select Users tab.
Click Permissions. You can see permissions specific to Secrets Manager. Choose one of the following:
View: View the secrets.
Create, Edit: Create and edit secrets.
Manage: Manage all the resources under this node.
Click Save and Enable to enable this policy.
Log in as a delegated node admin user. In the navigation menu, you can see Admin along with MyAccess and My Secrets.
Click System Admin to see the Secret Management menu.
Click on the vault and see this particular node is available to this delegated node admin.