Roles and permissions
A user has one Vertex role in each tenant they belong to: their product role for Entrosity Vertex in that organization on Entrosity Hub. Organization admins give the roles on the Hub (Organization members). Hub platform admins are global admins in Vertex. The server enforces the permissions on every API call; the web interface will only hide what you cannot use.
| Role | Hub role id | In short |
|---|---|---|
| Tenant admin | tenant_admin | Sets Vertex up and manages everything in the directory that the safety layers allow. |
| Helpdesk | helpdesk | Day-to-day user support: passwords, unlocks, enabling and disabling, contact details, group membership. |
| Global admin | (Hub platform admin) | Everything in every tenant, plus the cross-tenant overview and audit log. |
What each role may do
| Permission | Helpdesk | Tenant admin | Global admin |
|---|---|---|---|
| See users, groups, OUs, their attributes and the operations | ✓ | ✓ | ✓ |
| See the directory settings and the overview; read objects live | ✓ | ✓ | ✓ |
| Reset passwords, unlock users | ✓ | ✓ | ✓ |
| Enable and disable users | ✓ | ✓ | ✓ |
| Change users' contact attributes | ✓ | ✓ | ✓ |
| Add users to groups and remove them; change group members | ✓ | ✓ | ✓ |
| Bulk actions: enable, disable, unlock, add to and remove from a group | ✓ | ✓ | ✓ |
| Cancel an operation | ✓ | ✓ | ✓ |
| Create users; change any attribute; move, rename and delete users | ✓ | ✓ | |
| Bulk actions: move and delete | ✓ | ✓ | |
| Bulk imports | ✓ | ✓ | |
| Create, change, move, rename and delete groups | ✓ | ✓ | |
| Create, change, move, rename and delete OUs | ✓ | ✓ | |
| See and change Group Policy | ✓ | ✓ | |
| See and change password policies | ✓ | ✓ | |
| Directory settings (connector, AD account, managed OUs, write switches), test, sync, schema refresh | ✓ | ✓ | |
| See the tenant's members; change tenant settings (retention); read the audit log | ✓ | ✓ | |
| All tenants: overview, tenant list, global admins, global audit log | ✓ |
The contact attributes the helpdesk may change are givenName, sn,
initials, displayName, description, mail, telephoneNumber,
mobile, homePhone, ipPhone, facsimileTelephoneNumber,
physicalDeliveryOfficeName, department, title, company,
streetAddress, l, st, postalCode, co, c, wWWHomePage and
info. An attribute change that touches anything else, or an object that
is not a user, needs a tenant admin.
Every role, the global admin included, is still bound by the safety layers: the write switches, the managed OUs, protected objects, the deny list and the connector's guard. A helpdesk user can, for example, only add users to groups below the managed OUs that are not protected, never to Domain Admins.
Internally these are the permissions directory:read, users:helpdesk,
users:manage, groups:manage, ous:manage, gpos:manage,
psos:manage, directory:manage, members:read, settings:manage,
audit:read and tenants:manage
(entrosity-vertex.backend/internal/rbac); which one an operation needs
is decided in one place (directory.RequiredPermission).
When the connector starts an operation and asks for its secrets, Vertex
checks again that its author is still an active user who holds the
permission for it. A role taken away after the request, or a deactivated
user, stops the operation before anything is written (author_revoked).
Users of a tenant only reach their own tenant. A request for another tenant's data answers 404, as if it did not exist. Isolation is also enforced in the database (row-level security).
Sensitive actions
These need a step-up, a fresh confirmation of your password on the
Hub, used once (POST /api/platform/v1/auth/step-up with product
vertex):
- saving the directory settings;
- deleting a user, group, OU or password policy, and the bulk delete;
- deleting a GPO;
- committing a bulk import.