Roles in Lazsa Platform

The Lazsa Platform provides role-based access control (RBAC). Roles in the Lazsa Platform are predefined sets of permissions that govern user access and actions within the platform. By assigning roles to users, you can effectively manage access control, ensuring that users have appropriate permissions to perform tasks relevant to their roles while maintaining security and compliance within the platform ecosystem.

Contents

Types of Roles in Lazsa Platform

In the Lazsa Platform, roles are categorized into the following types:

Role Type Description
Platform Role These roles allow users to perform actions at the platform level. This includes managing global configurations, such as global settings on the Platform Setup screen or connection details of tools integrated with the Lazsa Platform, dashboard management, release train management, user administration, and organizational hierarchy management, among others.
Product Role These roles allow users to perform actions at a product level within the platform. These actions include managing business requirements, user feedback, user stories, design artifacts, technologies, source code repository branch templates, data pipelines, and several other tasks related to technology deployment.
System-Defined Role

Currently, the Lazsa Platform provides 13 default roles comprising eight platform-level roles and five product-level roles. You cannot edit the basic details and permissions assigned to a system-defined role. However, you can manage assigned users for a system-defined platform role and enable access to tools and assign tool-level permissions to a system-defined product role.

See System-Defined Roles and Associated Permissions.

Custom Role

You can create custom roles to manage user access as per your requirements. To create a custom role, you need to be a Tenant Administrator, or a Configuration Administrator or must have a custom role created for role management.

See Creating Custom Roles.

 

Managing Roles in Lazsa Platform

To manage roles, go to Configuration > Platform Setup > Users, Roles, Teams & Organization Hierarchy > Roles. Here, all your system-defined and custom roles are listed. System-defined roles are distinguished by the System-Defined tag in the list.

To manage roles, you can do the following.

 

Search Roles

To search for a specific role in the list, start typing the name of your desired role in the search bar.

Use Filters

You can filter roles based on their type.

  • Custom
  • Platform
  • Product
  • System-Defined

For example, to filter only system-defined product roles from the list, select Product and System-Defined checkboxes.

Export Role Details

Click to export the details of your existing roles to a CSV file. The CSV file contains the details such as role names, descriptions, assigned users, and role types. This feature helps you maintain records of your role definitions, permissions, and user associations. You can use these records as a reference in audits, compliance checks, and overall management of access control.

Manage System-Defined Roles

System-defined roles provide predefined access controls for both platform-wide and product-specific functionalities. These roles allow administrators to efficiently manage user access and tool permissions without needing to create custom roles from scratch. Managing system-defined roles involves two key tasks:

  • Assigning users to a platform role

  • Configuring tools' access for a product role and assigning the role to users within a product team

For more details, see Managing System-Defined Roles in Lazsa.

Create Custom Roles

If the access control and permissions offered by system-defined roles do not meet your specific requirements, you can create custom roles. To create a custom role, click .

See Creating Custom Roles.

Edit a Role

You can edit custom roles. Also, you can change access privileges and permissions related to tools within a system-defined product role.

To edit a role, click the ellipsis (...) on the extreme right of the role details row and click Edit.
See Editing Roles.

Manage Users

On the Roles tab, you can manage user assignments for platform roles. (You assign product roles to individual users or team members within a product.)

  1. Click the ellipsis (...) on the extreme right of a platform role and click Manage Users.
  2. In the side drawer, add new users or remove existing users and save your changes.

    Managing users for a platform role

Delete a Role

You can delete custom roles. To delete a role, do the following:

  1. Click the ellipsis (...) on the extreme right of the role details row and click Delete.
  2. In the confirmation dialog, enter a comment explaining the reason for deletion and confirm your action.
    Confirm deletion of a custom role
    If the role is already assigned to users, you cannot delete it until you remove the role assignment.
    Unable to delete role until role assignments are removed

    Note:

    You cannot delete a system-defined role.

Review Role Details

To review role definition details, do the following:

  • Click a role name to access its details. On the role details screen, you can view basic information like role name, type, and description.

  • Permissions
    Click the Permissions tab to review the assigned permissions for the role.

    Review permissions granted to a role

  • Users
    Click the Users tab to review the list of users assigned to a platform role.

    Review user assignments for the role

  • Tools
    Click the Tools tab to review which tools a product role can access, and the actions the role can perform on each tool.

  • Audit History
    Click the Audit History tab to track changes made to the role over time.

    • The audit history is presented in reverse chronological order.

    • You can filter updates by date range or specific users.

    • Each audit record includes details such as changes in role definition, date and time of the change, and name of the user who initiated the change.
      Audit History of role updates

      Audit history helps you maintain transparency and accountability in role management processes.

Other Actions on Role Details Screen

On the role details screen of a role, in the upper right corner, click the ellipsis (...) and do the following:

More actions on role details screen

  • Click Edit to modify your role definition (in case of custom roles only). See Editing Roles.

  • Click Manage Users to assign new users to the role or remove existing users (in case of a platform role only). See Manage Users.

  • Delete the role (in case of custom roles only). See Delete a Role.

Related Topics Link IconRecommended Topics

What's next? Creating Custom Roles