Identity Provider Roles
Identity provider roles define your identity and control which platform features you can access. These roles come from Ataccama’s identity provider, which synchronizes with your organization’s identity provider and passes roles to Ataccama ONE.
| We do not recommend creating new identity provider roles in ONE nor editing the existing ones. Contact your identity provider admin if any changes are required. |
What identity provider roles are for
Identity provider roles serve two purposes:
-
Control feature access: Determine which platform features are available to a user.
-
Simplify governance role assignment: Can be mapped to governance roles within groups, so users automatically receive appropriate permissions.
Some platform features require specific identity provider roles, which are assigned in ONE. See Reserved identity provider roles.
Environment admins
During environment setup, environment admin users are designated through the Cloud Portal. These admins are imported into ONE and automatically receive multiple admin roles.
If you need admin-level access, contact your environment admin.
Default role assigned to every user
Every user account in ONE includes a role named default-roles-<tenant-name>, for example, default-roles-acme-production.
<tenant-name> matches your environment’s tenant name, shown in the Ataccama Cloud Portal.
The role is generated and maintained by the Ataccama identity provider, and assigned to every user automatically, including users who sign in through your organization’s identity provider and aren’t a member of any group mapped in ONE.
In ONE, default-roles-<tenant-name> carries no permissions. It isn’t mapped to any group or governance role, and you can’t edit, remove, or extend it. You might come across it in Global settings > User management > Roles, but you can otherwise ignore it.
The role also has no effect on who can sign in to ONE. Sign-in is managed entirely by your organization’s identity provider, such as application or group assignment in Entra ID or Okta. See Set Up Entra ID SSO or Set Up Okta SSO to control which users can sign in.
Assign identity provider roles to users
You can assign and remove reserved identity provider roles directly in ONE. Other identity provider roles are assigned in your identity provider or the Ataccama Cloud Portal.
|
Prerequisites
To edit identity provider roles in ONE, you need the organizationconfig-admin role. Environment admins typically receive this role through the Cloud Portal. |
To manage a user’s identity provider roles:
-
Go to Global settings > User management > Users.
To access Global settings, select the Ataccama logo. -
Select a user to open their details.
-
Select Assign roles to add roles, or select the X icon next to a role to remove it.
When you assign or remove a role, synchronization between the identity provider and ONE starts automatically and no further action is needed.
| If you’ve assigned a role but the user still can’t access the feature, have them log out and log back in. |
Reserved identity provider roles
Certain identity provider roles are loaded from the identity provider but are built-in within ONE. In other words, these roles grant you specific capabilities, without which you cannot access a certain module or action.
| For the majority of functionalities, no identity provider role is needed. Access is instead handled using access levels, assigned through stewardship or sharing. |
The following roles are built-in in ONE:
| Functionality | Role | Description |
|---|---|---|
|
Can use AI features but cannot manage AI settings (such as which tools are allowed). |
|
|
Can manage AI settings and use all AI features. |
|
dataobservability-admin |
Can manage Data Observability settings. |
|
|
Superuser for lineage. |
|
|
Read and write access, can run lineage import. |
|
|
Read-only access, can view lineage diagrams. |
|
dpm-admin |
Can access DPM jobs in the Processing Center. These jobs might contain details that should be available only to admin users. |
|
notifications-admin |
Can manage notification settings. |
|
contentorchestrator-promotion-admin |
Can manage the environments and promotion settings for asset promotion. Granted automatically to the environment admins defined in the Ataccama Cloud Portal. |
|
contentorchestrator-export-operator |
Can create and delete exports and the content packages they produce. |
|
contentorchestrator-promotion-publisher |
Can publish content packages to other environments and withdraw them. |
|
contentorchestrator-import-promotion-operator |
Can import available content packages into the target environment. |
Was this page useful?