3.1.3 Managing Application Users

An application user can access the subscribed cloud services, based on the roles and groups assigned to them

An administrator can create application users using IAM. They can also batch import several users using a .CSV file.

After users are created, they are synced from IAM to the Cloud Service.

You can map the application users to existing groups based on the roles that they require and their access levels. The access level provided to an application user is based on the following:

  • Groups: Groups are seeded (available out-of-the-box) by your cloud service. Administrators can also create new groups in IAM. After groups are created, they are synced from IAM to the cloud service. You can map the groups to roles using the subscribed cloud service.
  • Roles: Roles are seeded by the cloud service. Administrators can also create new roles using the cloud service and assign existing functions to these new roles.
  • Functions: Functions are seeded by the cloud Service. Administrators cannot create new functions; however, they can use the existing functions.