Decision Intelligence provides different roles
to control who can access your environments and what permissions they have.
Roles and permissions are assigned at three resource levels: account, subscription, and service.
You can assign a user to more than one role, but the role with greater privileges takes
precedence.
- Account
- An account is the highest-level resource in the hierarchy and represents the IBM SaaS Console
account that owns one or more subscriptions.
- Account-level roles provide broad administrative capabilities, including managing users, groups,
and role assignments across the entire account. Depending on the role, permissions range from
viewing account information and users to full administrative control over all subscriptions and
service instances that are associated with the account.
-
- Account-level access control rules
-
- An account admin user or user group cannot perform any actions that are related to the account
owner.
- An account owner or account admin cannot perform any subscription-related actions without
subscription owner or admin access.
- An account owner or account admin cannot perform any service-related actions without service
owner or admin access.
- Subscription
- A subscription sits beneath an account and contains one or more services instances (also
referred to as tenants).
- Subscription-level roles govern access to the subscription itself, including visibility into
subscription details, billing and usage information, and management of the service instance
lifecycle, such as creating and deleting tenants.
-
Note: Users assigned a subscription role automatically inherit the account viewer role.
-
- Subscription-level access control rules
-
- A subscription admin user or user group cannot perform any actions that are related to the
subscription owner.
- A subscription owner or subscription admin cannot perform any service-related actions without
service owner or admin access.
-
- User access
-
- Users with the account viewer role can only view account and subscription information, as well
as instances.
- Service
- A service is an individual provisioned Decision Intelligence tenant and is the most granular resource in
the hierarchy.
- Service-level roles control access to the Decision Intelligence application and its tenant-specific
resources. Permissions can include using the application, managing tenant users, and generating API
keys.
-
Note: Unlike subscription roles, service roles do not automatically include the account viewer role.
If account-level visibility is required, the account viewer role must be assigned separately.
-
- Service-level access control rules
-
- A service admin user or user group cannot perform any actions that are related to the service
owner.
- Service administrator permissions include creating, reading, updating, and deleting users,
roles, groups, service IDs, and API keys for a service instance. This also includes all permissions
that are associated with an administrator role within the context of the service instance.
- Service users have no permissions that are related to service instance user management.
Permissions are solely defined by the role name within the service instance.
Decision Intelligence provides nine predefined roles
that are organized by resource type. Each role has specific permissions that are tailored to
different user responsibilities. The following table summarizes the nine predefined roles and their
associated permissions across all resource levels:
Table 1. Roles and permissions
| Scope |
Actions |
Account owner |
Account admin |
Account viewer |
Subscription owner |
Subscription admin |
Subscription viewer |
Service owner |
Service admin |
Service viewer |
| Account |
Create, update and delete users, groups, and roles |
✓ |
✓ |
|
|
|
|
|
|
|
| View users, groups, and roles |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| View account details |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| View list of subscriptions |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| Subscription |
View subscription details |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| View subscription usage |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| View list of instances |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
✓¹ |
|
| Create, update, and delete instances |
✓ |
✓ |
|
✓ |
✓ |
|
|
|
|
| Service |
Access service instance |
|
|
|
|
|
|
✓ |
✓ |
✓ |
| Create, update, and delete service users and roles |
|
|
|
|
|
|
✓¹ |
✓¹ |
|
| View service details |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓ |
✓¹ |
|
| Create, update, and delete service IDs and API keys |
✓ |
✓² |
|
✓² |
✓² |
|
✓¹ ² |
✓¹ ² |
|
- ✓¹ indicates that the permission is granted only if the user is also assigned the account viewer
role. Service role holders do not inherit account viewer access automatically; the account viewer
role must be separately assigned.
- ✓² indicates that the permission is granted only for the users' own personal API keys.
- ✓¹ ² indicates that both conditions apply:
- The user must also be assigned the account viewer role.
- The user can manage only their own personal API keys.