1.2. Who can use User Access
To initially view and manage User Access on the Red Hat Hybrid Cloud Console, you must be an Organization Administrator. This is because User Access requires user management capabilities that are designated from the Red Hat Customer Portal at Customer Portal. Those capabilities belong solely to the Organization Administrator.
The User Access administrator role is a special role that the Organization Administrator can assign. This role allows users who are not Organization Administrator users to manage User Access on the Red Hat Hybrid Cloud Console.
The User Access administrator role is delegated by the Organization Administrator and used for user and group management tasks that apply to managing human users and service accounts. This role is not allowed to do the following:
- Assign the Organization Administrator role.
- Add members, either users or service accounts, to any group assigned the User Access administrator role.
- Create new groups and assign the User Access administrator role to the group.
These restrictions are intentionally enforced to uphold the core cybersecurity Principle of Least Privilege and secure the administrative tier from allowing a higher level of permissions than are needed to perform the User Access administrator tasks.