Skip to content

Identity Authorization ​

This scenario guides platform administrators through setting organizational boundaries with tenants, packaging permissions in roles, assigning roles to users, and verifying menu, button, and resource access.

Target Outcome ​

  • The user belongs to the correct tenant and has a role appropriate to the job.
  • The user sees only authorized subsystems, menus, and buttons.
  • Platform governance permissions remain separate from regular tenant permissions.
  • Changes can be verified by a new session and traced through records.

Applicable Roles ​

  • operator: confirms operational access requirements without taking ownership of permission metadata.
  • provider and enduser: validation accounts for the resulting access model.

Before You Start ​

  1. Confirm the tenant, tenant, and responsibilities of the user.
  2. Prefer built-in roles and create a custom role only when responsibilities are not covered.
  3. List required and explicitly prohibited menus, actions, and resource scopes.
  4. Prepare a validation account that does not carry production workloads.

Procedure ​

StepActionReferenceCompletion Signal
1Understand tenant, user, role, and menu relationshipsIdentity and Access ModelBoundaries and role choice are clear
2Select a role from the default capability matrixRole ComparisonRole matches responsibilities
3Confirm member ownership in Tenant Settings and Team MembersTenant Settings, Team MembersThe member is active in the correct tenant
4Select a built-in role or create a least-privilege roleRolesThe role contains only necessary permissions
5Sign in with the validation account and inspect menus, actions, and resource scopeRolesAllowed items work and prohibited items do not
6Review the permission change and validation in Operation LogsOperation LogsTime, operator, and target are traceable

The Role Management view is used in steps 3-5 to confirm the role record and its scope before signing in with the validation account.

Confirm the role and member count in Roles

Completion Checklist ​

Purpose: These are the exit criteria for the current feature task. Use them to decide whether the result is observable and reviewable and whether you can continue to the next step in the scenario. They do not repeat the procedure; if any item fails, follow the troubleshooting section below.

CheckPass Criteria
1The user belongs to the correct tenant and is active.
2The role matches responsibilities without unnecessary platform permissions.
3Required menus and actions are available.
4Prohibited menus, actions, and resources are unavailable.
5A fresh session reflects the change and records are traceable.

Troubleshooting ​

SymptomCheck First
Target menu is missingTenant assignment, role assignment, menu permission, and a fresh session
Menu is visible but actions failAction permission code, API permission, and role-menu mapping
User sees another tenant's resourcesTenant boundary, resource authorization, and business filters
Changes do not take effectSession cache, re-login, role state, and whether changes were saved
Custom role is too broadCompare it with built-in roles and remove unrelated menus and APIs

User Manual ​

Open the user-manual entry and choose the subsystem whose access you are configuring