User Groups and Roles
This overview describes the groups and roles that are relevant to Oracle Blockchain Platform. Anyone who uses or administers Oracle Blockchain Platform must be added to the authentication server and granted the correct group.
Groups
Global role groups are used with both OpenLDAP and OIDC.
For OpenLDAP, Blockchain Platform Manager creates the global groups. Their names are fixed constants and are the same for all instances.
For OIDC, you must create and configure the global groups in the external identity provider. The group names do not need to follow a fixed naming pattern.
For instance-specific access, you must explicitly create the instance access group in OpenLDAP and OIDC if you do not use the default access group, Instance Admin.
Below are the group roles that are available for Oracle Blockchain Platform.
| User Group | Group Name in OpenLDAP | Description |
|---|---|---|
| BPM Admin | OBP_CP_ADMIN |
Platform-level administrator users with membership to this group can login in to Blockchain Platform Manager and set/reset/configure IdP providers, rich history, KeyStore, add users, assign roles in OpenLDAP. They cannot create/delete/update/view instances. |
| Instance Admin |
OBP_INSTANCE_ADMIN |
Main administrative group for Besu instance operations: create, delete, update, start, stop, scale, certificate updates. This group can create/delete/scale/stop/start or perform any other life cycle operation on the instances. They can also access service console and perform all the operations on it via UI or console REST APIs (if present). These users have read/write access to both the Blockchain Platform Manager and Blockchain Platform console. |
| Instance Operator | OBP_INSTANCE_OPERATOR |
Read/view access: instance details, operation status, console/API viewing paths, but not lifecycle operations. This group can also access Blockchain Platform Manager and can view instance details (provided the user is part of the access group of the instance as well). The permissions will be read-only and they will not be able to perform any other operations. |
| Instance API Client | OBP_INSTANCE_API_CLIENT |
Proxy client group. Intended for users/clients that interact through RPC proxy APIs. Not able to log in to the Blockchain Platform Manager or data plane. Only REST API access allowed. |
| Fabric CA Admin | OBP_FABRIC_CA_ADMIN |
A Fabric-specific role used to manage Fabric CA identities, such as registering and enrolling users in CA. It does not provide Blockchain Platform Manager administration, instance management, console access, or Besu/RPC access. Not able to log in to Blockchain Platform Manager or Blockchain Platform Console. Specific to Fabric CA. |
| Wallet Super Admin | OBP_WALLET_SUPER_ADMIN |
Allows creation of organization administrators and organization users. Has full access for configuring wallets and policies across multiple orgs. Can log in to Blockchain Platform Manager. |
| Wallet Org Admin | OBP_WALLET_ORG_ADMIN |
Allows creation of org admins and org users in their own org. Has full access for configuring wallets and policies only in their org. Can login to Blockchain Platform Manager. |
| Wallet Org User | OBP_WALLET_ORG_USER |
Has read access for all wallets and policies in their own organization. Cannot login to Blockchain Platform Manager. |
| Digital Assets Super Admin | OBP_DA_SUPER_ADMIN |
Creates a new asset, assigns one or more deployer for the asset, assigns approver based on the GOV policy. Cannot login to Blockchain Platform Manager. |
| Digital Assets Token Admin | OBP_DA_TOKEN_ADMIN |
Manages the lifecycle of the asset Cannot login to Blockchain Platform Manager. |
| Digital Assets Deployer | OBP_DA_DEPLOYER |
Develop and initiate approval for for initial deployment or upgrades. Cannot login to Blockchain Platform Manager. |
| Digital Assets Approver | OBP_DA_APPROVER |
Approves asset deployment. Cannot login to Blockchain Platform Manager. |
Global Groups with Optional Instance-specific Overrides
Configuring global groups once at the identity-provider level would define role aspect for the user for any instance.
Additionally, an instance specific access group defining user entitled for operation on that instance needs to be defined. The users added to the group would have permissions to act or operate on that instance with the role defined by the global groups. If a user is not in the access group for the instance, he cannot perform any operation on the instance irrespective of roles defined by the global group for him.
During instance creation, the administrator will additionally provide a group name to be used as access group for the instance which defines the set of users who can operate on the instance (in different roles defined by the users association to the global roles group). This input is taken as a field during instance creation rather than using a group name with a predefined naming template (including the instance name), for the following reasons:
- Organizations may have their own naming conventions to define groups in their IDP and if the product pre-decided a name template to be used, then it may not be acceptable to you. Instead this approach gives you the control to define the group name for the instance access group.
- If you want the same set of users to be able to operate on multiple instances, you can create a group and re-use it for multiple instances.
This combines the unified global group's simplicity with the permissioning flexibility specific for instances.
Important points to consider:
- The access group field will be optional with a default value of instance admin's group, named OBP_INSTANCE_ADMIN.
- If no explicit access group is given and the default OBP_INSTANCE_ADMIN is used, then instance will lose any exclusive access pattern specific for this instance, because OBP_INSTANCE_ADMIN is a global group and any instance admin users from the IdP environment will get access to the instance.
- Access group chosen once, can't be modified later.
- Creating the access group and adding the required user, is user's responsibility both in OpenLDAP and OIDC. Blockchain Platform Manager will not create any groups automatically.
- Once a user is added in a group, a fresh login needs to be done in Blockchain Platform Manager. Blockchain Platform Manager will not recognise the user's access in an existing session created before group enrollment.
Besu Role Based Access Control
Table 4-1 Besu Role Based Access Control
| Role Name | Log in to Blockchain Platform Manager | Create Instance | Act on an Instance | View Instance Details | Configure Authentication | View Wallet Tab | Perform Actions in the Wallet Tab | Call UWaas APIs | Access Service Console | Execute RPC Proxy APIs |
|---|---|---|---|---|---|---|---|---|---|---|
| BPM Administrator | Yes | No | No | No | Yes | No | No | No | No | No |
| Instance Administrator | Yes | Yes | Yes
Only for organizations where they're a member of the access group |
Yes
Only for organizations where they're a member of the access group |
No | No | No | No | Yes
Only for organizations where they're a member of the access group |
Yes
Only for organizations where they're a member of the access group |
| Instance API Client | No | No | No | No | No | No | No | No | No | Yes
Only for organizations where they're a member of the access group |
| Instance Operator | No | No | No | Yes
Only for organizations where they're a member of the access group |
No | No | No | No | Yes
Read-only access for only the organizations where they're a member of the access group |
No |
| Wallet Super Administrator | Yes | No | No | No | No | Yes | Yes | Yes | Yes | No |
| Wallet Organization Administrator | Yes | No | No | No | No | Yes
Only for their own organization |
Yes
Only for their own organization |
Yes | Yes | No |
| Wallet Organization User | No | No | No | No | No | No | No | Yes
Only GET calls |
Yes | No |
Service Console Views
| RBAC group | Dashboard | Nodes | Explorer | Contracts | Digital Assets | Developer Tools | Accounts | Logs |
|---|---|---|---|---|---|---|---|---|
BpmAdminGroup |
No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone |
InstanceAdminGroup |
Visible: all dashboard summaries | Visible: node inventory and details; administrative node actions | Visible: blocks, transactions, and search | Visible: registry data, contract details, and contract operations | Visible: all Digital Assets views | Visible | Visible: current user's accounts, balances, and activity | Visible |
InstanceOperatorGroup |
Visible: read-only summaries | Visible: node inventory and details; no administrative node actions | Visible: blocks, transactions, and search | Visible: read-only | Visible: read-only | Visible | Not shown | Visible |
InstanceApiClientGroup |
No: Console access alone | No: Console access alone | No: Console access alone; enables Explorer when combined with DaTokenAdminGroup |
No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone | No: Console access alone |
DaTokenAdminGroup |
Not shown | Not shown | Shown only when combined with InstanceApiClientGroup |
Visible: registry data, contract details, and permitted contract operations | Visible: Digital Assets views and permitted token-administration workflows | Not shown | Visible: current user's accounts, balances, and activity | Not shown |
WalletOrgAdminGroup |
Not shown | Not shown | Not shown | Not shown | Not shown | Not shown | Visible: current user's accounts, balances, and activity | Not shown |
WalletOrgUserGroup |
Not shown | Not shown | Not shown | Not shown | Not shown | Not shown | Visible: current user's accounts, balances, and activity | Not shown |
WalletSuperAdminGroup |
Not shown | Not shown | Not shown | Not shown | Not shown | Not shown | Visible: current user's accounts, balances, and activity | Not shown |
InstanceOperatorGroupplus any wallet group receives the Operator tabs plus Accounts. The wallet role does not grant contract operations or administrative node actions.DaTokenAdminGroupplusInstanceApiClientGroupreceives Contracts, Digital Assets, Explorer, and Accounts.InstanceAdminGroupreceives every current Console tab. Additional groups may grant access to downstream services but do not add Console tabs.BpmAdminGroupandInstanceApiClientGroupare not standalone Console login roles.- Wallet organization and super-administrator group names do not currently grant cross-user wallet inventory or wallet mutation in the Console. The Accounts tab remains scoped to the authenticated user's wallets.