User Groups and Roles

This overview describes the groups and roles that are relevant to Oracle Blockchain Platform. Anyone who uses or administers Oracle Blockchain Platform must be added to the authentication server and granted the correct group.

Groups

Global role groups are used with both OpenLDAP and OIDC.

For OpenLDAP, Blockchain Platform Manager creates the global groups. Their names are fixed constants and are the same for all instances.

For OIDC, you must create and configure the global groups in the external identity provider. The group names do not need to follow a fixed naming pattern.

For instance-specific access, you must explicitly create the instance access group in OpenLDAP and OIDC if you do not use the default access group, Instance Admin.

Below are the group roles that are available for Oracle Blockchain Platform.

User Group Group Name in OpenLDAP Description
BPM Admin OBP_CP_ADMIN

Platform-level administrator users with membership to this group can login in to Blockchain Platform Manager and set/reset/configure IdP providers, rich history, KeyStore, add users, assign roles in OpenLDAP. They cannot create/delete/update/view instances.

Instance Admin

OBP_INSTANCE_ADMIN

Main administrative group for Besu instance operations: create, delete, update, start, stop, scale, certificate updates. This group can create/delete/scale/stop/start or perform any other life cycle operation on the instances. They can also access service console and perform all the operations on it via UI or console REST APIs (if present).

These users have read/write access to both the Blockchain Platform Manager and Blockchain Platform console.

Instance Operator OBP_INSTANCE_OPERATOR

Read/view access: instance details, operation status, console/API viewing paths, but not lifecycle operations. This group can also access Blockchain Platform Manager and can view instance details (provided the user is part of the access group of the instance as well). The permissions will be read-only and they will not be able to perform any other operations.

Instance API Client OBP_INSTANCE_API_CLIENT

Proxy client group. Intended for users/clients that interact through RPC proxy APIs.

Not able to log in to the Blockchain Platform Manager or data plane. Only REST API access allowed.

Fabric CA Admin OBP_FABRIC_CA_ADMIN

A Fabric-specific role used to manage Fabric CA identities, such as registering and enrolling users in CA. It does not provide Blockchain Platform Manager administration, instance management, console access, or Besu/RPC access.

Not able to log in to Blockchain Platform Manager or Blockchain Platform Console. Specific to Fabric CA.

Wallet Super Admin OBP_WALLET_SUPER_ADMIN

Allows creation of organization administrators and organization users. Has full access for configuring wallets and policies across multiple orgs.

Can log in to Blockchain Platform Manager.

Wallet Org Admin OBP_WALLET_ORG_ADMIN

Allows creation of org admins and org users in their own org. Has full access for configuring wallets and policies only in their org.

Can login to Blockchain Platform Manager.

Wallet Org User OBP_WALLET_ORG_USER

Has read access for all wallets and policies in their own organization.

Cannot login to Blockchain Platform Manager.

Digital Assets Super Admin OBP_DA_SUPER_ADMIN

Creates a new asset, assigns one or more deployer for the asset, assigns approver based on the GOV policy.

Cannot login to Blockchain Platform Manager.

Digital Assets Token Admin OBP_DA_TOKEN_ADMIN

Manages the lifecycle of the asset

Cannot login to Blockchain Platform Manager.

Digital Assets Deployer OBP_DA_DEPLOYER

Develop and initiate approval for for initial deployment or upgrades.

Cannot login to Blockchain Platform Manager.

Digital Assets Approver OBP_DA_APPROVER

Approves asset deployment.

Cannot login to Blockchain Platform Manager.

Global Groups with Optional Instance-specific Overrides

Configuring global groups once at the identity-provider level would define role aspect for the user for any instance.

Additionally, an instance specific access group defining user entitled for operation on that instance needs to be defined. The users added to the group would have permissions to act or operate on that instance with the role defined by the global groups. If a user is not in the access group for the instance, he cannot perform any operation on the instance irrespective of roles defined by the global group for him.

During instance creation, the administrator will additionally provide a group name to be used as access group for the instance which defines the set of users who can operate on the instance (in different roles defined by the users association to the global roles group). This input is taken as a field during instance creation rather than using a group name with a predefined naming template (including the instance name), for the following reasons:

  • Organizations may have their own naming conventions to define groups in their IDP and if the product pre-decided a name template to be used, then it may not be acceptable to you. Instead this approach gives you the control to define the group name for the instance access group.
  • If you want the same set of users to be able to operate on multiple instances, you can create a group and re-use it for multiple instances.

This combines the unified global group's simplicity with the permissioning flexibility specific for instances.

Important points to consider:

  • The access group field will be optional with a default value of instance admin's group, named OBP_INSTANCE_ADMIN.
  • If no explicit access group is given and the default OBP_INSTANCE_ADMIN is used, then instance will lose any exclusive access pattern specific for this instance, because OBP_INSTANCE_ADMIN is a global group and any instance admin users from the IdP environment will get access to the instance.
  • Access group chosen once, can't be modified later.
  • Creating the access group and adding the required user, is user's responsibility both in OpenLDAP and OIDC. Blockchain Platform Manager will not create any groups automatically.
  • Once a user is added in a group, a fresh login needs to be done in Blockchain Platform Manager. Blockchain Platform Manager will not recognise the user's access in an existing session created before group enrollment.

Besu Role Based Access Control

Table 4-1 Besu Role Based Access Control

Role Name Log in to Blockchain Platform Manager Create Instance Act on an Instance View Instance Details Configure Authentication View Wallet Tab Perform Actions in the Wallet Tab Call UWaas APIs Access Service Console Execute RPC Proxy APIs
BPM Administrator Yes No No No Yes No No No No No
Instance Administrator Yes Yes Yes

Only for organizations where they're a member of the access group

Yes

Only for organizations where they're a member of the access group

No No No No Yes

Only for organizations where they're a member of the access group

Yes

Only for organizations where they're a member of the access group

Instance API Client No No No No No No No No No Yes

Only for organizations where they're a member of the access group

Instance Operator No No No Yes

Only for organizations where they're a member of the access group

No No No No Yes

Read-only access for only the organizations where they're a member of the access group

No
Wallet Super Administrator Yes No No No No Yes Yes Yes Yes No
Wallet Organization Administrator Yes No No No No Yes

Only for their own organization

Yes

Only for their own organization

Yes Yes No
Wallet Organization User No No No No No No No Yes

Only GET calls

Yes No

Service Console Views

RBAC group Dashboard Nodes Explorer Contracts Digital Assets Developer Tools Accounts Logs
BpmAdminGroup No: Console access alone No: Console access alone No: Console access alone No: Console access alone No: Console access alone No: Console access alone No: Console access alone No: Console access alone
InstanceAdminGroup Visible: all dashboard summaries Visible: node inventory and details; administrative node actions Visible: blocks, transactions, and search Visible: registry data, contract details, and contract operations Visible: all Digital Assets views Visible Visible: current user's accounts, balances, and activity Visible
InstanceOperatorGroup Visible: read-only summaries Visible: node inventory and details; no administrative node actions Visible: blocks, transactions, and search Visible: read-only Visible: read-only Visible Not shown Visible
InstanceApiClientGroup No: Console access alone No: Console access alone No: Console access alone; enables Explorer when combined with DaTokenAdminGroup No: Console access alone No: Console access alone No: Console access alone No: Console access alone No: Console access alone
DaTokenAdminGroup Not shown Not shown Shown only when combined with InstanceApiClientGroup Visible: registry data, contract details, and permitted contract operations Visible: Digital Assets views and permitted token-administration workflows Not shown Visible: current user's accounts, balances, and activity Not shown
WalletOrgAdminGroup Not shown Not shown Not shown Not shown Not shown Not shown Visible: current user's accounts, balances, and activity Not shown
WalletOrgUserGroup Not shown Not shown Not shown Not shown Not shown Not shown Visible: current user's accounts, balances, and activity Not shown
WalletSuperAdminGroup Not shown Not shown Not shown Not shown Not shown Not shown Visible: current user's accounts, balances, and activity Not shown
Combined-role behavior
  • InstanceOperatorGroup plus any wallet group receives the Operator tabs plus Accounts. The wallet role does not grant contract operations or administrative node actions.
  • DaTokenAdminGroup plus InstanceApiClientGroup receives Contracts, Digital Assets, Explorer, and Accounts.
  • InstanceAdminGroup receives every current Console tab. Additional groups may grant access to downstream services but do not add Console tabs.
  • BpmAdminGroup and InstanceApiClientGroup are not standalone Console login roles.
  • Wallet organization and super-administrator group names do not currently grant cross-user wallet inventory or wallet mutation in the Console. The Accounts tab remains scoped to the authenticated user's wallets.