Specific roles - User Guide - Micetro - 25.2.0

Micetro Admin Guide

ft:locale
en-US
Product name
Micetro
Version
25.2.0

Specific roles are roles whose permissions are not automatically applied to objects in Micetro. These roles are intended to allow access management on a per-object basis.

To create a Specific role, follow the instructions on roles and use the Role type dropdown to select Specific in the Create new role dialog. The default type for new roles is General.

Example: The specific role example.com editor has the permission Edit zone options enabled. No DNS zone-type object in Micetro, whether existing or future, will be accessible to users/groups assigned to this role unless specifically added to the object.

Warning: Specific roles are only intended for edge use cases and should not be regarded as the preferred method of access control in Micetro.

Using Specific roles

Access defined through Specific roles isn’t applied until explicitly configured on objects.

To use a Specific role and control access to an object:

  1. Open the relevant page in the Web Application (DNS or IPAM) and select the object to which you’d like to restrict access.
    Note: Using Specific roles on an object is only possible individually, per object.
  2. Use the Access or Row ... menu to select Manage access.
  3. In the dialog, remove all unneeded General roles and/or users (legacy only) configured for the object by selecting Exclude on the Row menu.
    Note: General roles can be restricted from accessing single objects. Refer to Object access.
  4. Use the dropdown to search for and select the Specific role and select + Add.
  5. Select Save.

Access to the object will be restricted to the selected users/groups assigned to the Specific role.

Note: Situations may arise that adding a Specific role to an object does not take effect because of missing permissions on parent objects. Micetro will calculate the necessary permissions needed, and can automatically add them to the relevant objects.

A notification will be displayed in the Save comment dialog, detailing the additional changes. If the user doesn’t have the necessary access to set permissions of these objects, an advisory message will be displayed.