Settings - Managing Access
The Settings Module allows users to manage access to the OSDU® Data Platform.
Identity & Access Management
Customers can manage Data Platform users and groups using Identity and Access management. To enable this section, you need to ensure platform status is ON. If platform status is OFF and user clicks on this section, pop up with message " User is not authorized or entitlements service is not ON" is popped up. User management is conducted via the Amazon Cognito instance in the SaaS AWS account created for each Customer. The current process for adding new users relies on an automated back-end process. If you would like 47Lining support to add, modify, or delete users within your instance, it can be done from Settings page. You can also submit a support ticket and a support agent will coordinate with you to make the changes on your behalf.
To enable Identity & Access Management, click on the arrow
Add Users
To add new users to the Data Platform, click on Add new user button
.
When you click on Add new user, a pop up window "Create New user" is displayed.
.
Fill in the email-id of users who needs access.
Access Configuration
Basic - Basic access to the Data Platform will be provided.
Advanced - Advanced access to the Data Platform will be provided.
Role
Member
Owner
Once you enter Email id ,click Create User button
Remove Users
To remove the user from the Data Platform, click on remove user
Groups
The users are assigned to service and data groups through which users gain access to APIs and data.
Entitlements service is used to enable authorization in Data Ecosystem. A group name defines a permission. Users who are added to that group obtain that permission.
To add new group, click on Add group. Once you click on Add group, a
pop up dialog
Group Type
Service groups - used for service authorization
Data groups - used for data authorization
User groups - used for hierarchical grouping of user and service identities
Select from the drop-down list based on requirements
Permissions
Owners - Data platform users and groups with read and write access to the service
Viewers - Data platform users and groups with only read access to the service. They don't have write access.
Resource name
The name of the resource to be created needs to be entered.
After selecting group type, permissions and resource name, click on Add group.
Manage Group
User can click on Manage group
to remove group or add members/owners to the group. On Clicking Manage
group, a pop up window
is displayed.
Clicking on Remove will remove the selected group from the OSDU Data Platform.
Add Member- You can specific user to the group by entering email of the user which needs to be added to specific group.