Nexeed

Multitenant Access Control

    • Developer documentation
      • Concepts
        • Authentication
        • Authorization
        • Resources
        • Roles
        • Sharing
      • Getting started
        • Registration
        • Authentication
        • Authorization
        • Multitenancy
      • How-to
        • Get & handle tokens
        • OAuth 2.0 for Mobile and Native Apps
        • Evolve authorization in your application lifecycle
        • Use Web Core for user login
        • Handle our integration events
        • Do automated testing
        • Advertise things to colleagues
      • Deep dives
        • OAuth2 and its flows
        • OpenID Connect endpoints
      • Troubleshooting
Multitenant Access Control
  • Industrial Application System
  • Core Services
    • Block Management
    • Deviation Processor
    • ID Builder
    • Multitenant Access Control
    • Notification Service
    • Reporting Management
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • Global Production Overview
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Product Setup Management
    • Part Traceability
    • Process Quality
    • Setup Specs
  • Execution
    • Line Control
    • Material Management
    • Order Management
    • Packaging Control
    • Rework Control
  • Intralogistics
    • AGV Control Center
    • Stock Management
    • Transport Management
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
    • Maintenance Management
    • Tool Management
  • Enterprise & Shopfloor Integration
    • Archiving Bridge
    • Data Publisher
    • Direct Data Link
    • Engineering UI
    • ERP Connectivity
    • Gateway
    • Information Router
    • Master Data Management
    • Orchestrator
Nexeed Learning Portal
  • Multitenant Access Control
  • Roles
✎

Roles

Access management is based on a concept for assigning corresponding roles to users, groups and modules.

Application roles

A module provides an application role. The module predefines the permissions. Administrators can use application roles to control access to a module. Application roles are write-protected for users.

Application roles can be assigned to users, groups, modules and contracts.

If no application role has been assigned to the user for a corresponding module, the menu does not appear in the Nexeed Industrial Application System.

Organization roles

An organization role can be defined, created, managed and changed by a user.

Organization roles can be assigned to users, groups and modules.

Organization roles cannot be assigned to a contract.

Role Overview

The role overview displays the name and description of all roles. New roles can be created and roles that are no longer required can be deleted.

mac_roles_detail_2023-02-01

After you select a role, the role data appears in the detailed view on the right. In this view, you can update role data and add or remove users to or from a role.

Detailed view

Icon/element Description

Details

Displays role details

Assigned users

Displays users that are assigned to a role

Authorizations

Displays the role permissions and permission filters by static and dynamic resources.

View permissions

Prerequisite

Access Manager role

Procedure

  1. Call up the Access management > Roles menu.

  2. In the Domain drop-down list, select one or more modules.

    Or:

    Enter the required role designation in the Search text field.

  3. Select the required role from the overview.

    In the detailed view on the right, the role data is displayed in the Permissions tab.

    mac_roles_privileges_2024_01

Adding a Role

Organization roles are roles added by a user.

Prerequisite

Access Manager role

Procedure

  1. Call up the Access management > Roles menu.

  2. Click add_border.

    The Add role dialog window will open with the Details step.

    mac_create_role_2_22
  3. Complete the Name and Description fields in the Details step.

  4. Click Next.

    The Permissions step appears.

    mac_create_role_assign_permissions
  5. To limit the number of roles displayed, implement the following settings:

    In the Modules drop-down list, select the module in which the required role is located.

    Or:

    Enter the required role designation in the Search text field.

    Or:

    Use the Resources drop-down list to filter by resource type.

  6. To assign the required permissions to the selected roles, click the corresponding icon:

    • Create objects add

    • Read objects watch-on

    • Edit objects edit_blue

    • Delete objects delete_blue

    • Execute objects automation-start_blue

      Selected permissions are displayed in white on a blue background.

  7. To revoke permissions, click the required permission again.

    Deselected permissions are displayed in blue on a white background.

  8. To assign or withdraw all permissions, click checkmark-frame-tripple_blue.

    Permissions that cannot be assigned, for example, due to a lack of permission from the current user, appear in gray and cannot be selected.

  9. Click Next.

    The Summary step will open.

    mac_create_role_summary
  10. To edit details, click on Back or on the required step.

  11. To save the details, click Save in the Summary step.

The role is created and is displayed in the overview.

  • To change a role’s data, continue with Updating a Role.

  • To assign a user to a role, continue with Assigning a User to a Role.

Updating a Role

Only organization roles can be updated.

Prerequisite

Access Manager role

Procedure

  1. Call up the Access management > Roles menu.

  2. To limit the number of roles, implement the following settings:

    Set the Organization filter in the Domain drop-down list.

    Or:

    Enter the required role designation in the Search text field.

  3. Select the required role from the overview.

    In the detailed view on the right, the role data is displayed in the Details tab.

    mac_roles_update 2024-01
  4. To change the role permissions, click mdm_edit_icon.

    If the edit icon is not displayed, this role is not an organization role and cannot be edited.

    The Edit role dialog window appears.

  5. Update the permissions.

  6. Click Next.

    The Summary step will open.

  7. Check all the information and adjust if necessary.

  8. Apply changes with Save.

The role data is updated and will be displayed in the overview.

Assigning a User to a Role

Prerequisite

Access Manager role

Procedure

  1. Call up the Access management > Roles menu.

  2. To limit the number of roles, implement the following settings:

    In the Domain drop-down list, select the module in which the required role is located.

    Or:

    Enter the required role designation in the Search text field.

  3. Select the required role from the overview.

    In the detailed view on the right, the role data is displayed in the Details tab.

  4. In the detailed view, go to the Assigned users tab.

    When a user name is clicked, the Nexeed Industrial Application System changes to the Access Management > Users menu.

    mac_assign_role_to_a_user_2023_02

    User names preceded by service-account- and followed by an alphanumeric code (example: service-account-w68ysarkiyx171246mrtaocj) identify modules. The alphanumeric code corresponds to the client ID of the module.

  5. Click add.

    The Select user dialog window will appear.

    mac_groups_add user 2024-01
  6. Select the required users.

  7. Click Assign.

The selected users are assigned to the role and are displayed in the detailed view in the Assigned users tab.

  • To remove a user from a role, continue with Unassigning a User from a Role.

Unassigning a User from a Role

Prerequisite

Access Manager role

Procedure

  1. Call up the Access management > Roles menu.

  2. To limit the number of roles, implement the following settings:

    In the Domain drop-down list, select the module in which the required role is located.

    Or:

    Enter the required role designation in the Search text field.

  3. Select the required role from the overview.

    In the detailed view on the right, the role data is displayed in the Details tab.

  4. In the detailed view, call up the Assigned users tab.

    When a user name is clicked, the Nexeed Industrial Application System changes to the Access Management > Users menu.

    mac_assign_role_to_a_user_2023_02
  5. Click delete next to the user you want to delete.

The user is unassigned from the role and is no longer displayed in the Assigned users tab.

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2025, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses