User interface permission for user groups

You can manage user group permissions in the AS4 Microservice user interface with Systems Mangement > User Groups.

To create a user with Master Account Administrator permissions, you must log in to AS4 Microservice user interface as maccountadmin. Similarly, to create a user with the System Administrators permissions, you must log in as sysadmin. For more information about configuring a user profile, see Configuring a user profile

Roles and permissions for users created under the user groups are predefined. The following table provides the details of the access permissions.

Table 1. User groups and permissions in AS4 Microservice
User group Access permission
Master Account Administrators
A user in the Master Account Administrator group can create, view, update, and delete the following resources in AS4 Microservice:
  • User profiles
  • User groups
  • Organizations
  • Exchange profiles
  • Conformance policies
  • Receivers
  • Destinations
  • Security policies
  • Organization credentials
  • Digital certificates
  • Certification revocation lists
  • HTTP servers
  • HTTPS servers
  • Retry policies
  • User exits
  • Advanced search - to view transaction details
Note: A user might not be able to update or delete a resource if it is being used in an exchange.
A user in the Master Account Administrator can view the following resources in AS4 Microservice:
  • System settings
  • Thread pools
  • Message queues

Additionally, MasterAccountSecurity role is supported in the master account administrator group. Users with MasterAccountSecurity role can create, read, update, and delete user groups under the master account administrator group.

MasterAccountSecurity is not supported out of the box. You must add a user group and assign the MasterAccountSecurity role, and then add user profiles to that group.

System Administrators
A user in the System Administrator group can create, view, update, and delete the following resources in AS4 Microservice:
  • Message queue
  • Thread pool
  • Visibility event subscription
  • User profile
  • System setting - adding content type for canonicalization
  • User group
Note: A user might not be able to update or delete a resource if it is being used in an exchange.

Additionally, SystemSecurity role is supported in the system administrator group. Users with SystemSecurity role can create, read, update, and delete user groups under the system administrator group.

SystemSecurity is not supported out of the box. You must add a user group and assign the SystemSecurity role, and then add user profiles to that group.