Managing users and access

You can authorize users in IBM® Sovereign Core with different permission levels to control access to your organization.

Before you begin

You can authorize users in an account at multiple levels with different scopes and capabilities to control access to your organization. For details about the predefined user roles, see Roles and users in IBM Sovereign Core.

You must have the Owner or Editor role in the account to manage user access.

Use the following guidelines to provide users access to the platform at various levels:
  • Grant only the minimum permissions required to complete a task.
  • Manage permissions by creating groups instead of assigning access to individual users.
  • Review user access periodically and remove unnecessary permissions.
  • Make sure critical tasks require multiple levels of approval.

Procedure

  1. Based on the scope level at which you want to assign a role to a user, navigate to the access management menu as follows:
    System level
    From the navigation menu, select Access management to manage access to the platform and control plane in the system owner account.
    Tenant level
    From the navigation menu, select Access management to manage access in a tenant worker plane in the tenant account.
    Workspace level
    From the tenant account home page, click the workspace name and select the Access management tab to manage user access within the workspace.
    Service instance level
    From the tenant account home page, select the workspace and click the deployed service instance name to a specific service instance within the workspace.
  2. You can choose to manage access individual users at a time or create user groups to assign roles to a multiple users at a time.
    Managing individual users
    1. Click Add user, and enter the email address of the user you want to add to the account. You can add multiple users at a time by providing multiple email addresses.
    2. Assign roles based on the permissions you want to provide to each user. Click Add.
    Managing user groups
    1. Select the User groups tab and click Create user group. Provide a name and description for the user group.
    2. Enter the email address of the users you want to add to the group.
    3. Assign a role based on the permissions you want to provide to the group. Click Create.
  3. You can modify and remove access for users in the account at any time.

What to do next

Based on role you are assigned, you can now authorize other users to access IBM Sovereign Core, publish or deploy service instances, and work with services.