Assigning user groups to object groups

To specify which users can access which objects, assign users to user groups and user groups to object groups. You must have administrator permissions to assign user groups to object groups, that is, you must have the OBJECTGROUP_WRITE permission.

About this task

You can assign one or more user groups to an object group. Different user groups can have different sets of permission for the same object group. For example, you might have two user groups like these:

  • A group of regular users who can view network packages and deployment locations.
  • A group of administrators who can update and execute network packages and deployment locations.

For more information about how to create user groups and add users to them, see Mapping users to LDAP roles and groups.

Procedure

  1. Log in to the IBM Cloud Pak® console. For more information about how to log in, see Logging in to the IBM Cloud Pak console.
  2. From the navigation menu Navigation menu icon, click Define > Network automation object groups.
  3. Click the overflow menu Vertical overflow menu icon next to the object group where you want to assign user groups, then click Update user groups.
  4. Click the Update user groups button.
  5. Enter the user group name that you want to assign to the object group, and click Assign group. You can assign one or more user groups to the object group. When the groups are added, click Next.
  6. Review the summary of the object group details, then click Update.

Results

The user groups that you selected are assigned to the object group. Users that belong to the object group can access only the objects that the user group has permissions to access.

What to do next

You can assign permissions for the user groups. User groups can access objects based on the permissions that are assigned to them.

For more information about how to assign permissions for user groups, see Assigning permissions to user groups.