Allowing Aria Automation users to manage property groups without granting them assembler administrator role.
search cancel

Allowing Aria Automation users to manage property groups without granting them assembler administrator role.

book

Article ID: 446212

calendar_today

Updated On:

Products

VCF Automation

Issue/Introduction

  • Users with the default Assembler User role are unable to create or edit Property Groups within their projects.
  • Property Groups appear as read-only or are restricted to reference-only for non-admin users.
  • Administrators need to delegate Property Group management to specific project users without granting the full Assembler Administrator role (often required in multi-tenant or shared environments).

Environment

  • Aria Automation 8.x
  • vCFA 9.x

Cause

By default, the ability to create and manage Property Groups is restricted to the Assembler Administrator role. The standard Assembler User role only permits the consumption (referencing) of existing property groups within cloud templates.

Resolution

This requirement can be met by utilizing the Custom User Roles feature available in both Aria Automation 8.18.x and VCF 9.x. This allows for granular permission mapping without elevating a user to a full administrator.

Procedure

For Aria Automation (8.18.x and earlier)

To define the user roles and assign users, open Automation Assembler or Automation Service Broker as a service administrator. You cannot configure the custom roles in Automation Pipelines, however the roles apply to all the services.
1. Select Infrastructure > Administration > Custom Roles.
2. Click New Custom Role and enter a unique Name that you can identify when you assign users to the role.
3. Select the check boxes that correspond to the permissions you want the users to have over the resources.
4. Click Create.
5. In the list, click the custom role name and click Assign.
6. Add the users or groups that you want to have this role and click Add.


For VCF Automation (Version 9.0)

  1. Log in to the VCF 9.0 console.
  2. Select 
    Aminister
    Access Control
    Roles
    .
  3. Click New and enter a unique Name that you can identify when you assign users to the
  4. Select the check boxes that correspond to the permissions you want the users to have over the resources.
  5. Create a custom role that includes the specific capability for property group management.

  6. Assign the role to the users requiring these permissions.