Permission and roles
Web Portal creates following permissions and roles during startup.
| All users who need access to Web Portal must have the role Web Portal user role assigned. Without this role the side navigation is empty. Roles and permissions are not inherited. That is, a user with the role Web Portal Admin must also have the role Web Portal User. If the roles and resources are no longer needed (e.g., if the functionality has changed and the resources and roles are no longer used), then these roles and resources must be deleted manually. |
| Role | Permissions | For | Comment |
|---|---|---|---|
Web Portal User |
View (read) side navigation. |
User |
Required to use Web Portal. Grants access to the side navigation. |
Web Portal Admin |
View (read) and maintain (modify) customer configuration of Web Portal (e.g., footer and skinning configuration). |
User |
Required for Business Role "Administrator". |
Web Portal Operator |
Un-register (delete) system registration (un-register modules from Web Portal). View (read) integration status of modules (of the same organization). View (read) and upload (modify) the default group structure of the menu. View (read) detailed health endpoint information. |
User |
Operator users of sub-organizations cannot view integration status of modules registered on the BCI organization. |
Web Portal Registration |
Register (read + add + modify) modules at Web Portal |
User / Application Client |
Module registration at Web Portal via API (assigned to auth provider clients of integrated modules). |
Web Portal Custom Registration |
Register custom modules and custom views (read + add + modify + delete) modules at Web Portal |
User / Application Client |
Module custom registration at Web Portal UI (custom modules and views in Web Portal configuration, assigned to Web Portal Admin users). |
DigitalWorkplace Keyuser |
View (read) the DigitalWorkplace Link section on the support page |
User |
Users with this role will see a link to the DigitalWorkplace ticket system from BCI/OPS on the support page. It requires a separate user that’s why the link is not shown to all users. |
Web Portal User Profile Reader |
View (read) profiles of users |
Application Client |
Grants access to profiles of users. |