Skip to main content
Version: 10.2.9

Segregate Administrator permissions

By default, after Work.AI is installed, the Administrator Role has ultimate permissions regarding the User Management and Control Tower. It is very convenient to give all permissions to a person who sets up the environment to the organization's needs. However, after the initial environment setup, your organization may want to involve more people in administration while limiting their responsibilities and the platform capabilities with which they can interact.

Some routine administration operations include establishing new roles in the organization and onboarding new users. It's not rare that different people perform these two functions to prevent administrators from getting enough permissions to be technically able to grant themselves even more authorizations and potentially harm the system. In the guide below, this case is used to illustrate how you can segregate administrator permissions in Work.AI.

By default, it's assumed that all operations are performed by the user with the Administrator Role in the Workfusion realm. It is also assumed that all users are local. However, the approach can be easily adapted when users come from an external federation or when an external Identity Provider is used. Still, the organization's policy assumes that local user records should be manually linked to the records in an external Identity Provider. The only requirement is to have local role management.

Set role that can only define other roles

For simplicity, let's call it the Role Manager. Within Work.AI, the Role Manager is to define roles or groups mapped to client-specific roles and, if applicable, specify the permissions of the client-specific roles under particular clients.

note

You can use roles and groups interchangeably. In this document, groups are used because you can get the optional benefit of a structured hierarchy. So, for every organization role, a new group is created.

To set the Role Manager role, follow the steps below:

  1. Log in to the User Management and create the Role Manager role for the two clients:

    • wf-control-tower (Control Tower)

    • wf-workspace (Workspace)

  2. Create a group and name it Role Admins:

  3. For the created group, in the Role Mappings tab, specify the client-level roles for the members of the Role Admins group:

    • For wf-control-tower, specify the newly created Role Manager role.

    • For wf-workspace, specify the newly created Role Manager role.

    • For realm-management (User Management UI), specify the following roles:

      • query-groups

      • wf-manage-groups-only

      • wf-manage-client-roles-only

      • query-clients

    note

    To utilize realm-level roles instead of groups, the realm-management client roles must also include wf-manage-realm-roles-only and query-clients. For other clients, don't specify any groups.

  4. Switch to Control Tower and go to System Settings > Role management. Find the Role Manager role and click it to navigate to its permissions.

  5. In the permission list, select Restricted Manage Control Tower Permissions. This authorizes the Role Admins group members for the Control Tower client to manage the permissions of all roles, except for Role Manager.

  6. Switch to Workspace and go to the Roles tab.

    1. Find the Role Manager role and go to its permissions.
    2. Select Manage other user roles. This allows the members of the Role Admins group for Workspace to manage the permissions of all roles, except for Role Manager.

As a result, the members of the Role Admins group have the following capabilities:

ComponentRole Admins capabilities
User Management UI
  • Access lists of groups and roles, accounting for the restrictions below:
    • Create new groups.
    • Modify and delete groups, except for the Role Admins group and other groups where a particular user becomes a member outside of this guide, including implicit membership in all parent groups up the hierarchy.
    • Create realm roles.
    • Modify and delete realm roles, except for the realm roles assigned to them outside of this guide.
  • Access the list of clients in the read-only mode:
    • Create client roles for all clients.
    • Modify and delete client roles for all clients, except for all client roles a particular user effectively has, irrespective of whether the client role is given directly or transitively via realm roles, composite roles, or groups.
Control Tower
  • Access the Application switcher and navigate to the User Management UI.
  • Access the Role Management page, accounting for the restrictions below:

    Modify Control Tower permissions for the wf-control-tower client roles, except for the Role Manager role and the other wf-control-tower roles a particular user is granted outside of this guide.

Workspace
  • Access the Roles page, accounting for the restrictions below: Modify the Workspace permissions for the wf-workspace client roles, except for the Role Manager role and other wf-workspace roles a particular user is granted outside of the guide.

Set role that can only create users

For simplicity, let's call the role User Access Manager.

To set the role, follow the steps below:

  1. Create a group and name it User Access Managers.

  2. In the Role Mappings tab, specify client-level roles for the members of the User Access Managers group. In particular, for the realm-management (User Management UI) client, specify the manage-users and view-users roles.

    note

    If you have to link local user records to external Identity Provider records manually, you also need to add the view-identity-providers role for the realm-management client.

As a result, every member of the User Access Managers group can access only the User Management UI by the direct link: <https://<dns_name>-uath-lb1.<domain>/auth/admin/<realm>/console/#/>.

Allow User Access Managers to access User Management UI via redirect from Control Tower

This setup is optional.

The option to access the User Management UI from the left menu of Control Tower is unavailable since the group doesn't have any Control Tower role mappings. If you still want your User Access Managers group members to access Control Tower, you can do the following:

  1. Go to the User Management UI. For the wf-control-tower client, create a role and name it User Access Manager.

  2. Go to the Groups tab and find the User Access Managers group. Open it and go to the Role Mappings tab.

  3. Select the wf-control-tower client and add the User Access Manager role mapping to the group.

  4. Switch to Control Tower and go to System Settings > Role management. Find the User Access Manager role and go to its permissions.

  5. In the permission list, select at least one checkbox corresponding to a menu element.

    The most restrictive option is to select Platform Monitor only. If you choose the option, the members of the User Access Managers Group cannot access Platform Monitor without configuration in the User Management. However, they can log in to Control Tower and access User Management from the top menu.

    After logging in to Control Tower, User Access Managers group members will see the following: