A user belonging to a custom group with the necessary permissions (Read, Update, and Generate API Key) is unable to generate their own API key.
Even after logging out and back in to refresh permissions, the option to generate the key remains unavailable or restricted.
Architecture: FlexOrgs
In CloudHealth FlexOrgs, permissions are additive across all assigned user groups and their associated role documents. However, the system follows a "Deny overrules Allow" logic for conflict resolution.
If a user is a member of multiple groups:
The restriction or lack of permission in Group B will take precedence over the "Allow" in Group A, preventing the user from performing the action.
To resolve this conflict and allow the user to generate their API key, follow these steps: