Add Tenant
The guide describes configuring a new Tenant to pass data via DW REST API.
The guide describes configuring a new Tenant to pass data via DW REST API.
Property|Description|Default
An access control list (ACL) is a list that shows which users can see certain items and what they can do with them. For Workspace, ACL is used to control access, with each assignment having an owner and its own ACL restrictions.
You can set up WorkFusion User Management (Keycloak) to authenticate users based on identities from external providers.
User Federation
Install Java
The guide describes how to configure Workspace to work in a multi-tenant environment.
Secrets Vault use cases
You can set the two-factor authentication flow right after installation or at any time later. When you enable two-factor authentication after installation, make sure to set the flow before configuring user roles.
Instead of mapping attributes and roles to individual users, you can create groups of users sharing common attributes and role mappings.
To deactivate users means to disable them after a configured inactivity period has elapsed. For WorkFusionRealm, the default period is set to 90 days, meaning that all users who are inactive for more than 90 days are automatically disabled. For all other realms, the default value is zero days, meaning the User deactivation feature is off, and users won't be deactivated automatically.
To update the database connections for the CT vault, do as follows:
Sensitive customer information is protected by encryption at the Data Store level. However, the same data is used in Manual Tasks, namely, in Worker answers from Workspace, thus persisting in system tables without encryption.
Sensitive customer information is protected by encryption at the Data Store level. However, the same data is used in Manual Tasks, namely, in worker answers from Workspace, thus persisting in system tables without encryption.
WorkFusion User Management is based on the Keycloak single sign-on (SSO) solution integrated into the out-of-the-box Work.AI package to implement access control list (ACL).
Superset is an open-source analytics tool that WorkFusion has integrated into its Product to monitor various process metrics.
The role-based access mechanism (RBAC) limits access to data through Analytics dashboards based on the following filter categories:
Microsoft Windows uses a global certificate storage to keep certificates. The certificates must be imported to each workspace, to enable the browser to pass the certificate chain check successfully.
The document describes the integration of ADFS SSO with WorkFusion services.
WorkFusion User Management features two levels of roles:
In Control Tower, the Role Management page lists all roles available for the application users and allows managing associated permissions.
Each realm comprises a set of clients and users with assigned roles. Realms are isolated from one another, allowing you to manage and authenticate only the users that belong to them.
The data stored in Secrets Vault is not shown in recordings, logs, system files, or Bot Configurations. This allows you to share scripts with other users without exposing confidential data.
To manage secure properties, install the designated utility on the main installation server:
As soon as a user logs into a realm, WorkFusion User Management maintains their session and tracks their activities. Admins can view the data on all or particular user sessions and log out users of all or a particular session.
Each authenticated WorkFusion user can manage their account via the User Account Service:
Users always belong to and are created within a particular realm or imported to a realm from an external identity or storage provider.
To access any Workspace functionality, each user must have a role and permissions assigned to them.
The Work.AI platform no longer supports qualifications. Instead, Workspace employs an approach to managing user permissions and restrictions, where:
A migration tool is available as part of the platform installer, enabling you to seamlessly migrate users, groups, qualifications, roles, and related mappings.
When working with an integrated identity provider (IdP) using REST API, you cannot utilize your IdP ID or password. The recommended approach is to explicitly set passwords for users locally in Keycloak. Thus, users can log in to the user interface with their IDP credentials and log in via REST API with a local password set up in Keycloak.
s3
Secrets Vault API enables credentials management.
Secrets Vault plugins provide the functionality to manage Secrets Vault. Secrets Vault plugins work using the /secrets-vault WorkFusion Rest API. To learn more, refer to Secrets Vault API.
Property|Description|Required
By default, after Work.AI is installed, the Administrator Role possesses full permissions for User Management and Control Tower. It is very convenient to give all permissions to a person who sets up the environment to the organization's needs. However, after the initial environment setup, your organization may want to involve more people in administration while limiting their responsibilities and the platform capabilities with which they can interact.
Managing Analytics-related roles and permissions can involve the following, depending on your needs:
The WorkFusion User Management UI comprises the following clients that are available by default:
Transparent Data Encryption (TDE) is the MS SQL feature to encrypt database data and transaction log without changing an application. The database engine encrypts or decrypts data during execution of queries.
To validate the accessibility of an S3 object from a different host, follow the steps below:
The guide describes the procedure of updating TLS certificates (server.crt, server.key, and ca.crt) on the already installed WorkFusion platform environment.
This guide describes the update of passwords for the installed WorkFusion platform. The guide may be helpful in the following cases:
Create the following users on the corresponding servers before the installation.
The WorkFusion API lets you launch, post data to, and receive results from the WorkFusion platform automatically. Using it, you can manage simple tasks and more complex Business Processes (BPs) representing a workflow of various manual and automated tasks.