Manage member permissions

更新时间:
复制 MD 格式

This topic describes common roles and the steps to grant permissions for these roles.

Roles and applicable scopes

The common roles in mPaaS are as follows:

Role

Description

mPaaS administrator

Has all permissions for all mPaaS components.

Administrator of a specific component

For example, an AB experiment administrator has all permissions for the AB experiment component.

Observer of a specific component

For example, an AB experiment observer has permissions to view AB experiment reports and query logs.

Other roles

Some components also support roles such as developer and operator.

When you grant a role to a member in the console, a list of roles appears. After you select a role, the permissions for that role are displayed. For more information, see Role authorization steps below.

mPaaS lets you limit the applicable scope of a role by two dimensions: application and environment.

  • mPaaS lets you create multiple applications. Therefore, you can grant a user a specific role within a specific application.

  • The mPaaS console supports multiple environments, also known as workspaces. Therefore, you can grant a user a specific role within a specific environment.

For more information, see the description of the authorization scope in the Role authorization steps section below.

Role authorization steps

  1. Log on to the console and click Management Console at the top of the page.

  2. In the navigation pane on the left, choose Account Management > Member Management.

  3. On the Tenant Members page, find the member in the list. Click Grant in the Operation column to go to the Add Authorization page.

  4. Select a role.

    • You can search for roles by keyword.

    • Select a role from the list to view its detailed permissions on the right side of the page.

  5. If needed, customize the Permission Scope. For more information about permission scopes, see Roles and applicable scopes above.

    • Validity Period: Set the validity period for the member's role.

    • Environment: Select the environment where this role applies.

    • Authorization Scope: Select All applications of the Fintech Cloud tenant or Custom.

      • If you select All applications of the Fintech Cloud tenant, the role applies to all applications.

      • If you select Custom, the following additional options appear:

        • Application Group: Select one or more applications from the list.

        • Under Condition, first select Mobile Permission Dimension, and then:

          • If needed, select Mobile Application Identity and enter the application ID (appId). Then, click Add.

          • If needed, select Mobile Environment Identity and enter the environment ID (workspaceId). Then, click Add.

            Note
            • To obtain the appId and workspaceId, log on to the mPaaS console, select an application, and go to the Code Management > Code Configuration page to download the application configuration file. You can find the values for appId and workspaceId in the .config file.

            • After you add a condition, you must click Add to save it.

  6. Click OK. A message appears to confirm that the role is granted successfully: authorized