This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
See this idea on ideas.ibm.com
A client has requested a new user role, with permissions between Automator and Site administrator. The idea is to have a user role with the permissions to manage the policies and to execute actions. Nowadays the Automator can execute the actions but cannot change/manage the policies; and the Site administrator can change/manage the policies and much other possibilities that are not need for a user owner of some namespaces that only need to manage groups, policies, and execute actions. So the request is a user role with the Automator permissions + the possibility of change/manage the policies.
Idea priority | Medium |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Hi team, the client is facing problems even with the Site Admin role, we would need this solution as soon as possible. Adding here their support ticket created today TS019877442.
Hi Dri, I am merging this with other existing RBAC enhancement ideas. We are building a framework that will allow for the creation of custom roles that would exactly solve your problem here.
This woudl be extrelly useful for those large customer where there is a role dedicated to configure the policies that apply to its team and they don't want to have the privileges and vision of other policies. In a practical case, Turbonomic for openshift and a very large OCP cluster with different namespaces managed by different teams. Every team needs to have the ability to modify their namespaces policies and configure them as they are the ones that know what config needs to be put in there.
There is also something that would support this function moving forward as it would only involve to have a site admin role with the option to be "scoped" to a certain group in Turbonomic.
It make a lot of sense to have it in OCP scenarios with large OCP clusters involved which the case of large customers.
If is there any other workaround we could take it's very appreciated.