Skip to content
Last updated

Compute Ops Management Permissions - IAM

This page lists the IAM permissions associated with Compute Ops Management, along with which built-in roles contain the permission and whether or not the permission is affected by granular scoping. To read more about granular scoping see Compute Ops Management Scope Based Access Control (SBAC) - IAM.

Built-in roles

There are three built-in roles for Compute Ops Management: Observer, operator, and administrator. Each role has a pre-defined set of permissions.

PermissionObserverOperatorAdministratorSupports granular scoping
Compute appliance deleteX
Compute appliance readXXX
Compute appliance editXX
Compute appliance createX
Compute appliance useXX
Compute approval policy createX
Compute approval policy readXXX
Compute approval policy editX
Compute approval policy deleteX
Compute approval request readXXX
Compute approval request approveXX
Compute async operation readXXX
Compute authorization editX
Compute filter editXX
Compute filter readXXX
Compute filter createX
Compute filter deleteX
Compute group readXXX
Compute group useXX
Compute group deleteX
Compute group createX
Compute group editX
Compute schedule createX
Compute schedule readXXX
Compute schedule editXX
Compute schedule deleteX
Compute server readXXX
Compute server editXXX
Compute setting readXXX
Compute setting useXX
Compute setting deleteX
Compute setting createX
Compute setting editX
Compute webhook readXXX
Compute webhook createX
Compute webhook editX
Compute webhook deleteX

Using Compute Ops Management permissions

If one of the built-in roles does not provide the set of permissions needed, a custom role can be created and assigned any set of permissions.

To create a custom role, or view the permissions associated with built-in roles, use the HPE GreenLake Roles & permissions page. Read more about this process in the HPE GreenLake user role documentation.

To assign a role, use the HPE GreenLake Workspace identity & access page. Read more about this process in the HPE GreenLake assign roles documentation.