OneCloud security is easy to set up and provides flexibility to tailor access by different groups of users. In this tutorial, read-only access is provided to a PROD environment, and Admin privileges' to the DEV Environment.
Create a Group
-
Using the left navigation, select Applications ➡️ Admin ➡️ Users & Groups ➡️ Groups.
-
From the lower-right corner, click the Add Group button.
-
Name the group: "OneCloud Developers" and provide a suitable description.
-
Use the (+) button to add users to the group.
-
Save the group.
Configure Group Access
If deviated from, return to the User Groups page: Select Applications ➡️ Admin ➡️ Users & Groups.
-
Using the left navigation, under Users & Groups, select Access.
-
Under Integration Studio Permissions, select the "OneCloud Developers" button.
-
All of the Workspaces are listed. Set the Learning OneCloud Workspace Permissions to Read.
-
Set the "PROD" Environment access to Read.
-
Click "Chain Permissions".
-
The "Simple Extract Chain" is the only chain in the "PROD" Environment back in Integration Studio.
-
Set access to Execute by clicking the corresponding box.
-
Select the back-arrow ⬅️ to the left of the group name - OneCloud Developers.
-
For the "DEV" Environment, set access to Admin.
-
Click "Chain Permissions.
-
Ensure all the "Chain Permissions" are set to Admin and select the back-arrow ⬅️ to the left of the group name.
Add Users
It is difficult to test access with only one user since one user always has to belong to the Admin group. Add another user to OneCloud and assign this newly added user to the "OneCloud Developers" group.
If deviated from, return to the User Groups page: Select Applications ➡️ Admin ➡️ Users & Groups.
-
Using the left navigation, under Users & Groups, select ➡️ Users.
-
Add a user by clicking the "Invite Users" icon in the lower-right corner
-
Add an email address and assign the user to the group "OneCloud Developers".
-
Invite the User by clicking "Invite" near the upper-right corner.
-
An email has been sent to confirm the account, whereby the new user may log in.
