Control user access to application services
Assign user roles to service groups to grant users access to application services in your organization. Your organization may restrict access to some services for security or secrecy reasons.
Before you begin
Also, make sure that you have created service groups as described in Group application services.
Role required: app_service_admin or sm_admin
About this task
- app_service_admin
Creates and modifies application services, creates service groups, views, and edits application service maps.
- app_service_user
Views maps for operational application services and retrieves service content using the getContent - GET REST API. The itil role that serves as the basic helpdesk technician role contains the app_service_user role.
- sm_admin
Sets up the Service Mapping application. Maps, fixes, and maintains application services. Also performs advanced configuration and customization of the product. Assign this role to application administrators.
- sm_user
Views maps for operational application services to plan change or migration, as well as analyze the continuity and availability of services. Assign this role to application users.
- sm_app_owner
Provides information necessary for successful mapping of an application service. Once a service is mapped, this user reviews the results and either approves it or suggests changes. Assign the sm_app_owner role to users who own application services and are familiar with the infrastructure and applications that make up the services.
Event Management provides these preconfigured roles:
- evt_mgmt_admin
- Has read and write access to all Event Management features to configure Event Management.
- evt_mgmt_operator
- In addition to the evt_mgmt_user permissions, can also activate operations on alerts such as acknowledge, close, open incident, and run remediations.
- evt_mgmt_user
- Has read access to all Event Management features. Has write access to alerts to manage the alert life. Has the itil role to be able to manage incidents that are created from alerts.
- evt_mgmt_integration
- Has create access to the Event [em_event] and Registered Nodes [em_registered_nodes] tables to integrate with external event sources.
Typically, enterprises have hundreds of services which makes it impractical to manage them individually. Service groups can make service lists much shorter and easier to manage, especially in large organizations or service providers. In a hierarchy of service groups, access to a parent service group automatically grants access to all the child service groups.
By default, all new services are assigned to the All service group that lets all users view and manage application services. When you assign a role to a service group, the users with this role can access application services in this service group and in the All service group. To enable users with this role to access other services, assign this role to the respective service group. Do not assign user roles directly to the All service group.
Procedure
Example
- Organize the services into the Financial Services group.
- Create a new user role, financial services administrator [financial_services_admin] role, that contains the [app_service_admin] role.
- Assign the Financial Services administrator role to the Financial Services group.