CloudHealth New Experience - How to control different sections via Role Documents
search cancel

CloudHealth New Experience - How to control different sections via Role Documents

book

Article ID: 399202

calendar_today

Updated On:

Products

CloudHealth

Issue/Introduction

Under CloudHealth New Experience there are a number of new features that will be available to customers. 

Access to these features is controlled via Roles (classic tenant users) and Role documents (FlexOrg tenant users)

To determine if you utilize a Role and Role document validate if on the left navigation bar if you receive under Setup -> Admin, the options Roles and Organizations, or just User Groups and Role documents.

In the case of receiving the Roles and Organization options you will likely be part of a tenant running classic Roles and Organizations, in the case of just receiving User Groups and Role Documents your tenant will be running under FlexOrgs. 

In the former case you will need to make the permission changes to your role, in the latter case you will need to update the Role document associated with the Usergroup you belong to. 

Resolution

The following sections are controlled by these permissions within Roles/Role Documents.

  • Home -> Cost History report, and Reports -> Cost History - Access to these sections is controlled by the Read Cost History (AWS), Read Azure Cost History Report permission (Azure) and Read GCP Cost History Report permission (GCP).

    Note that if for example the Read Azure Cost History Report permission is disabled you'll still have Azure appears in the reporting dropdown, but Cost data won't be returned. 

  • Explore -> Assets -> Inventory - Each section is controlled by the Read <Asset Name> available under Cloud Name -> Assets -> Asset Name -> Read <Asset Name> permission. For example EC2 Instance access could be controlled by removing the permission AWS -> Assets -> AWS Instance -> Read AWS Instance. 

    Removing the permission won't remove the section, but won't allow the user to retrieve asset records for that asset type when attempting to use a query.

  • Recommendations -> Rightsizing - This is controlled by the permission Recommendations -> Rightsizing -> Read Rightsizing Recommendations. 

    This also blocks the Savings Summary, and Rightsizing Summary sections under Recommendations -> Optimization. It will also block the Optimization tab under the Home page.

  • Recommendations -> Commitment Discounts - This is controlled by the permission Recommendations -> Commitment Discounts -> Read Commitment Discounts.

  •  Anomaly Detection - This is controlled by the permission Setup -> Governance -> Anomaly Detection -> Read Cost Anomaly Detection

  • The Realized Savings section doesn't currently have permissions that can be controlled via a Role/Role document and can't be disabled currently. But this will be added in the near future.