The following permissions can be applied to roles in the DDI orchestrator application. When a user or group is assigned a role, they inherit that role's permissions to access information and perform tasks on objects in DDI orchestrator.
Permission prerequisites
In DDI orchestrator, various permissions have prerequisite permissions that must be assigned in order to provide appropriate access. For example, The View zone history permission requires the View zone, View DNS service, and View history permissions.
The following table outlines the additional parent access permissions that need to be assigned to a user in order for a specific permission group to provide its access:
| Permission group | Additional parent access |
|---|---|
| Any DDI orchestrator permission | View organization |
| Any DNS service permission |
|
| Any DHCP service permission |
|
| Any zone permission |
|
| Any range or DHCP scopes permission |
|
| Any organization permission |
|
| Any cloud network permission |
|
| Any cloud service permission |
|
Permissions in DDI orchestrator
| Permission type | Permissions |
|---|---|
| Cloud networks |
|
| Cloud services |
|
| Devices |
|
| DHCP services |
|
| DNS |
|
| DNS services |
|
| History |
|
| Import data |
|
| IP ranges |
|
| Organizations |
|