Users and Roles
Manage VSM users and permissions.
To prepare the users to work with VSM and Make, you need to configure their accounts and set the correct Orchestration Enginge authorizations. The users have to be added to the tenant and assigned to proper user groups with sets of access rights for the roles they will perform.
To achieve this, open the Users and Groups dashboard, which allows you to manage the users' data in general, both for Commerce Engine (CE) and for Orchestration Engine (OE). Using the dashboard, you can add, edit and delete users' data. You can also manage users by filtering or sorting by users' first name, last name, e-mail address, department, or status.
The status types are:
Green - the user is active
Grey - the user account is locked

Definitions
User - an employee using the Emporix Management Dashboard and Value Stream Modeller.
User Group - a group of users that share some common characteristics, like performing similar job. User group defines access controls for the users.
Role - a combination of predefined permissions that allow users to perform some actions on resources within the system. You can apply a role to a user group.
Permission - a mechanism for limiting what actions a user belonging to a role can perform on specific resources.
Access controls - a combination of roles and resources. For example, a user with a manage access control on product resources can view, create, delete, and edit product entities.
Resource or Entity - the object type within the Emporix Management Dashboard and Value Stream Modeller.
Action - the ability to perform an action on entities of specific type.
This diagram shows a high-level view of the relationships between users, groups, and roles:
Creating a user
To create a user of Management Dashboard:
If you decide to stop adding the new user, you can use the Discard option. It clears all the fields and removes the data you'd entered.

It's also possible to add multiple users to your tenant at one time. You can do that through the Developer Portal using the CSV import users feature. For more information, see the Developer Portal documentation.
If the user already had an active account, or is an existing user of a different tenant, they are visible as an active user right away, without the provisioning status.
User groups and roles
To allow your user to access the Management Dashboard, you need to set up the correct access controls. To do this, assign the users to the right user groups. Every user group can be assigned roles with associated permissions. When you assign a user to a group, you give them the permissions that the roles have.

The default groups for OE are:
OE Analyst
The users in the analysts group have read access only to value streams, schedules, and user tasks; they cannot modify anything.
OE read access
None
OE Viewer
The users in the viewers group have read access only; they cannot modify anything.
OE read access
Member
OE Editor
The users in the editors group can edit OE value streams and Make scenarios.
OE read and edit access
Make application developer
integromat.app_developerMake scenario editor
integromat.scenario_edit
OE Manager
The users in the managers group can conduct development tasks, such as creating applications in Make.
OE read, edit and manage access
Make application developer
integromat.app_developerMake scenario editor
integromat.scenario_edit
OE Admin
The users in the admins group can conduct administration tasks, such as adding users to the tenant or creating applications in Make.
OE read, edit, manage and admin access
Make owner
Make scenario editor
integromat.scenario_edit
Creating a user group
We recommend to use only the OE user groups that are provided by default. Still, it's possible to create custom user groups.
The groups are created in the Groups tab. You need to provide a group name with a description, plus set the relevant access controls.
Assign OE roles
For roles specific to OE, choose the Standard role and select Orchestration Engine from the drop-down menu. You can then select one of the predefined access rights - Analyst, Viewer, Editor, Manager or Administrator.
Read access selected: a user is able to see entities of a specific type
Edit access selected: a user is able to see and edit entities of a specific type
Manage access selected: a user is able to see, edit, create, and delete entities of a specific type
Administrate access selected: a user is able to do all available actions on the entities of a specific type
none selected: a user is not able to see entities of a specific type

Set access controls
Set up the group access rights in the Access Controls Assignment section. Depending on the selected role, default access controls are already there. If you want to add additional ones, choose Assign Access Controls.

You can see that the access controls are correlated and selecting one of the available access controls for a specific entity automatically selects the same access control for another one. This behavior ensures that users get the same access to the related resources.
When creating a new group, or editing an existing one, you can add the group's users right away in the Members tab.
Always set the relevant users permissions at the group level. Users can belong to several groups with different access rights. By assigning users to relevant groups, you control what they are able to see and/or edit in the Management Dashboard. Bear in mind that if you assign a user to two groups that have different permissions set for a specific resource, the manage overwrites read permission and the user is able to manage the resource, not only view it.
Synchronizing users between OE and Make
Prerequisites:
The user must be a part of one or more OE user groups.
The user must have at least one of the following roles assigned within the OE user group:
integromat.scenario_editorintegromat.app_developer.
To start with the synchronization:
Assigning users to groups
Choose the users that you want to have access to Make and assign them to the right groups as defined in the prerequisites section. The system automatically scans all OE users' permissions and identifies those users who have the integromat.scenario_edit or integromat.app_developer roles.
When you add a user to your Make organization, they receive an email notification with instructions how to access and set up their accounts.
When any changes are made to the groups a OE user belongs to, the synchronization process is triggered to ensure that the user's access to the Make organization is up-to-date. Users receive a new email invitation whenever their group membership is altered.
If a user loses an OE role that grants Make access (Viewer, Editor, Manager, or Admin), they are automatically removed from the tenant's Make organization or team. OE Analyst users are never provisioned in Make and are not included in this synchronization.
Make-related UI entry points are hidden or disabled for users without Make access (including OE Analyst). This includes the automatic SSO redirect on login, Open in Make links, the Check Scenario menu item, Make links in the trigger-scenario dropdown, and Go to scenarios / Create new scenario links.
To learn more about managing users and groups in the Management Dashboard, see Users and Groups.
To learn more about the way how identity and access management work in Emporix, see Identity and access management (IAM) and IAM Service API documentation.
To learn more about the roles in Make, see Make - Organization Roles.
Last updated
Was this helpful?

