Skip to Main Content
Cloud Management and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Workspace Instana
Categories Access Control
Created by Guest
Created on Mar 9, 2026

Want the ability for Teams and Roles to only be accessible within a single Unit

Today, when you define a Team or Role, they are available across all Units within a tenant.  That makes it difficult to control what people have access to.   For example, within Unit 1 a person might need  administrative permissions like creating Smart Alerts.  But, within Unit 2 and 3, they should not be able to create Smart Alerts.   With today's behavior, once I grant the ability to create Smart Alerts via a  Role, then the person has that capability across all Units.   

The suggestion would be to have an optional feature flag that would allow a customer to change the behavior so that Teams and Roles only apply to a single Unit.   We want this to be a feature flag so that we don't disrupt existing customers.

The customer does not want to use multiple tenants because longer term, they do want the ability to query data across multiple Units within a single UI.   And, there is more administrative overhead in setting up multiple tenants.

 

Idea priority Urgent
  • Admin
    Máté Návay
    Mar 17, 2026

    Roles and Teams are created on tenant, as authentication and thus mapping has to happen for the tenant.
    Units inherently need to be unique for Teams, as the entities in scope are only applicable in the unit.
    Roles can potentially be synced across units if needed, but since the scope of each unit is different, providing different sets of permissions can still make sense.

    The only way to keep Teams and Roles separate is with single-unit tenants, which per the last paragraph the customer doesn't want to do.