Quantcast
Channel: VMware Communities : All Content - vRealize Automation Tools
Viewing all articles
Browse latest Browse all 9859

Use Tenants or Business Groups to Segragate Design Blueprints and Software Components?

$
0
0

Hello-

 

I have what will hopefully be a quick question... I am in the process of setting up vRA for use in my companies vSphere environment.  I work for a specific division, and that division has separate groups, each with their own IT administrators.  I would like to set up vRA in such a way that each IT admin can be the masters of their own domains, giving them permissions to create their own blue prints, software components, define their own end users, etc. but within the confines of the resource reservations that I define.  I originally thought I could do this with a single tenant and separate business groups, but what I am finding is that in order to give the group IT admins permissions to create and edit their own catalog items, they have the ability to see other groups stuff and in some cases modify it.

 

For example, if I give the following roles to the IT admin user groups...

-Approval Administrator

-Container Administrator

-Container Architect

-Software Architect

 

... then each group admin can edit their blueprint/software component designs, but they can also see and activate/deactivate the Services of the other group.  Is there something I am missing in order to prevent this from happening, i.e. is it an unecessary permission that I have granted or a missed setting to hide/isolate the items from showing up to different business groups, or is what I am trying to do not possible without separating out the groups to their own tenant spaces? 


Viewing all articles
Browse latest Browse all 9859

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>