Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents

Info

This page describes the details of some useful permissions for a reseller administrator role.

...

Introduction to reseller admin

A reseller admin role can have a range of privileges depending on how you will manage resellers and cloud users on the platform. So how the reseller will "manage its customers" will vary, depending on the privileges.

Before you create a reseller admin, we recommend that you first modify the standard ENTERPRISE_ADMIN role to create a basic tenant admin role to cover all features for your platform, including public cloud. See Modify user roles to add public cloud. Also remove any privileges for features that you are not using, such as persistent templates.

...

Reseller privileges to switch enterprises

The base privileges for standard reseller admins are these Home view privileges:

  • List enterprises within scope

  • Allow user to switch enterprise

When you assign these privileges to a reseller admin role, the user can view a list of their enterprises (in scope) in the Home view and switch from one enterprise to another to manage virtual resources.

...

If you wish to maintain a separate administrator account for each tenant, the administrator can log in with a separate user to each tenant that they will administer. In this case, the user will not use a shortcut button to switch enterprises. So you do not need to add the List enterprises within scope or the Allow user to switch enterprise privilege. We only recommend this option for resellers with a small number of tenants.

...

For example, if you manage all cloud user accounts with a centralized system, such as LDAP, you may wish to remove the Manage users privilege from the reseller administrator.

...

Manage users

If you are not using a centralised user management system, you may wish to have an administrator who can manage users. They can then perform the tasks of creating, editing, and deleting the users in the enterprises in their user scope only.

If your reseller will be managing users, in addition to the Manage users privilege that is part of the standard tenant admin role, you can assign additional privileges.

To allow the reseller to manage enterprises and users in a single pane of glass, and not by switching enterprises, assign the privileges to Manage to Manage enterprises and Manage and Manage users of all enterprises. Although this  This privilege refers to "all enterprises", but it means all enterprises within the administrator's scope

Note that each enterprise must have a default Default scope, which the platform will automatically assign to all new users in the enterprise. Note that administrators Administrators can then change the user scope. However, administrators who can manage scopes

Administrators with the Manage scopes privilege can also assign the enterprise scope to users, even if it is higher has more privileges than or is completely different to their own scope! HoweverBut, if you are using data aggregation for resellers or key nodes, the enterprise default scope must define the hierarchy for each reseller and key node, so it would not be convenient to change it for administrator security.

...

Shared resource management

...

Note that it is possible for enterprises to belong to more than one scope and this means that you can create a scope just to create a group of tenants who will all use the same resources.

...

Resellers creating tenants and the scope hierarchy

If your reseller administrator is able to create their own tenantstenant enterprises, Abiquo will automatically add these to the reseller's scope. 

If the reseller's tenants are part of a scope hierarchy and your reseller does not need to manage their users or enterprises, then you can remove them from the reseller's scope. If you wish to allow your reseller to manage their own scope hierarchy, assign the Manage the Manage scopes privilege. This means that the reseller can add their tenants to a scope hierarchy beneath their own scope.