Example: Permitting both contract operators and contract administrators to deploy contracts
By default, contract operators for a store can deploy contracts. In some cases, you might want to grant this authority to contract administrators as well.
The flexible design of access control policies offers several methods for implementing this change:
- You can create a new access group containing both contract operators and contract administrators and assign the new access group to the policy that defines who can deploy contracts.
- You can add the deploy contract actions to the policy that specifies the actions a contract administrator can perform.
- You can create a new policy that permits contract administrators to deploy contracts.
This example illustrates the third approach. It shows you how to create a new resource-level policy that authorizes contract administrators to deploy contracts.
To create this policy, do the following:
- Determine the resource-level policy that authorizes contract operators to deploy contracts.
- Note the name of the action group for this policy.
- Note the name of the resource group for this policy.
- Define a new policy for the contract administrator access group, specifying the action group and resource group from the policy that authorizes contract operators to deploy contracts.
Identify the action group and resource group to use in the new policy
- Determine the resource-level policy that authorizes contract operators to deploy contracts The policy is: ContractOperatorsForOrgExecuteContractDeployCommandsOnContractResource.
- From the Organization Administration Console, click Access Management > Policies.
- For View, select Root Organization to display the policies that it owns.
- Locate the policy in the list.
- Note the name of the policy's action group--ContractDeploy. This is the action group use in defining your new policy.
- Note the name of the resource group--ContractDataResourceGroup, This is the resource group use in defining your new policy.
Define the new policy
- Click New to display the New Policy page.
- For Name, specify
ContractAdministratorsForOrgExecuteContractDeployCommandsOnContractResource
Note: This new policy must be assigned to a policy group before it takes effect. The policy assignment must be done through XML. See for more information.
Related reference
Examples: Customizing access control policies using the Organization Administration Console