Understanding roles and permissions

Decision Intelligence provides different roles to control who can access your environments and what permissions they have.

Roles and permissions are assigned at three resource levels: account, subscription, and service. You can assign a user to more than one role, but the role with greater privileges takes precedence.

Account
An account is the highest-level resource in the hierarchy and represents the IBM SaaS Console account that owns one or more subscriptions.
Account-level roles provide broad administrative capabilities, including managing users, groups, and role assignments across the entire account. Depending on the role, permissions range from viewing account information and users to full administrative control over all subscriptions and service instances that are associated with the account.
Account-level access control rules
  • An account admin user or user group cannot perform any actions that are related to the account owner.
  • An account owner or account admin cannot perform any subscription-related actions without subscription owner or admin access.
  • An account owner or account admin cannot perform any service-related actions without service owner or admin access.
Subscription
A subscription sits beneath an account and contains one or more services instances (also referred to as tenants).
Subscription-level roles govern access to the subscription itself, including visibility into subscription details, billing and usage information, and management of the service instance lifecycle, such as creating and deleting tenants.
Note: Users assigned a subscription role automatically inherit the account viewer role.
Subscription-level access control rules
  • A subscription admin user or user group cannot perform any actions that are related to the subscription owner.
  • A subscription owner or subscription admin cannot perform any service-related actions without service owner or admin access.
User access
  • Users with the account viewer role can only view account and subscription information, as well as instances.
Service
A service is an individual provisioned Decision Intelligence tenant and is the most granular resource in the hierarchy.
Service-level roles control access to the Decision Intelligence application and its tenant-specific resources. Permissions can include using the application, managing tenant users, and generating API keys.
Note: Unlike subscription roles, service roles do not automatically include the account viewer role. If account-level visibility is required, the account viewer role must be assigned separately.
Service-level access control rules
  • A service admin user or user group cannot perform any actions that are related to the service owner.
  • Service administrator permissions include creating, reading, updating, and deleting users, roles, groups, service IDs, and API keys for a service instance. This also includes all permissions that are associated with an administrator role within the context of the service instance.
  • Service users have no permissions that are related to service instance user management. Permissions are solely defined by the role name within the service instance.

Decision Intelligence provides nine predefined roles that are organized by resource type. Each role has specific permissions that are tailored to different user responsibilities. The following table summarizes the nine predefined roles and their associated permissions across all resource levels:

Table 1. Roles and permissions
Scope Actions Account owner Account admin Account viewer Subscription owner Subscription admin Subscription viewer Service owner Service admin Service viewer
Account Create, update and delete users, groups, and roles              
View users, groups, and roles ✓¹ ✓¹  
View account details ✓¹ ✓¹  
View list of subscriptions ✓¹ ✓¹  
Subscription View subscription details ✓¹ ✓¹  
View subscription usage ✓¹ ✓¹  
View list of instances ✓¹ ✓¹  
Create, update, and delete instances          
Service Access service instance            
Create, update, and delete service users and roles             ✓¹ ✓¹  
View service details ✓¹  
Create, update, and delete service IDs and API keys ✓²   ✓² ✓²   ✓¹ ² ✓¹ ²  
  • ✓¹ indicates that the permission is granted only if the user is also assigned the account viewer role. Service role holders do not inherit account viewer access automatically; the account viewer role must be separately assigned.
  • ✓² indicates that the permission is granted only for the users' own personal API keys.
  • ✓¹ ² indicates that both conditions apply:
    • The user must also be assigned the account viewer role.
    • The user can manage only their own personal API keys.