Access
Role-based access control allows you to set the resources and permissions available to IBM Spectrum Protect Plus user accounts. Through role-based access control you can tailor IBM Spectrum Protect Plus for individual users, giving them access to the features and resources they need. Once resources are available to IBM Spectrum Protect Plus, they can be added to a resource group along with high level IBM Spectrum Protect Plus features such as hypervisors and individual screens. Roles are then configured to define the actions that can be performed by the user associated with the resource group. These parameters are then associated with one or more user accounts, which can be native to IBM Spectrum Protect Plus or imported as part of an LDAP group.
Configure role-based access control in the following sections of the Accounts pane.
Resource Groups - A resource group defines the resources that will be made available to a user. Every resource added to IBM Spectrum Protect Plus can be included in a resource group, along with individual IBM Spectrum Protect Plus functions and screens. This gives you the ability to finely-tune the experience of a user. For example, a resource group could include an individual hypervisor, with access to only backup and reporting functionality. When the resource group is associated with a role and a user, the user will only see the screens associated with backup and reporting for the assigned hypervisor. To view available resource groups and their usage, see Resource Group Types.
Roles - Roles define the actions that can be performed on the resources defined in a resource group. While a resource group defines the resources that will be made available to an account, a role sets the permissions to interact with the resources defined in the resource group. For example, if a resource group is created that includes IBM Spectrum Protect Plus Backup and Restore jobs, the role will determine how a user can interact with the jobs. Permissions can be set to allow a user to create, view, and run the Backup and Restore jobs defined in a resource group, but not delete them. Similarly, permissions can be set to create administrator accounts, allowing a user to create and edit other accounts, set up sites and resources, and interact with all of the available IBM Spectrum Protect Plus features. To view available permissions and their usage, see Permission Types.
Users - A user account associates a resource group with a role. To enable a user to log on to IBM Spectrum Protect Plus and use its functions, you must first add the user to IBM Spectrum Protect Plus as a native user or as part of an imported group of LDAP users, then assign resource groups and roles to the user account. The account will have access to the resources and features defined in the resource group as well as the permissions to interact with the resources and features defined in the role.
IBM Spectrum Protect Plus 10.1.2
Licensed Material - Property of IBM Corp. © IBM Corporation and other(s) 2018. IBM is a registered trademark of the IBM Corporation in the United States, other countries, or both. | 8/23/2018