Skip to content
Last updated

Compute Ops Management Permissions - Enhanced IAM

This page lists the enhanced IAM permissions associated with Compute Ops Management, along with which built-in roles contain the permission and whether or not the permission is affected by granular scoping. To read more about granular scoping see Compute Ops Management Scope Based Access Control (SBAC) - Enhanced IAM.

Built-in roles

There are three built-in roles for Compute Ops Management: Viewer, operator, and administrator. Each role has a pre-defined set of permissions.

PermissionDescriptionViewerOperatorAdministratorSupports granular scoping
compute-ops-mgmt.appliance.createCreate an appliance.X
compute-ops-mgmt.appliance.deleteDelete an appliance.X
compute-ops-mgmt.appliance.readView appliance information.XXX
compute-ops-mgmt.appliance.updatePerform actions that affect appliances.XX
compute-ops-mgmt.appliance.useUse an appliance.XX
compute-ops-mgmt.approval.policy.createCreate an approval policy.X
compute-ops-mgmt.approval.policy.deleteDelete an approval policy.X
compute-ops-mgmt.approval.policy.readView approval policy information.XXX
compute-ops-mgmt.approval.policy.updateUpdate an approval policy.X
compute-ops-mgmt.approval.request.approveApprove or decline an approval request.XX
compute-ops-mgmt.approval.request.readView approval request information.XXX
compute-ops-mgmt.async-operation.readView async operation information.XXX
compute-ops-mgmt.filter.createCreate a filter.X
compute-ops-mgmt.filter.deleteDelete a filter.X
compute-ops-mgmt.filter.manage-scopeConfigure scope based access control enabled saved filters.X
compute-ops-mgmt.filter.readView filter information.XXX
compute-ops-mgmt.filter.updateUpdate a filter.XX
compute-ops-mgmt.group.createCreate a group.X
compute-ops-mgmt.group.deleteDelete a group.X
compute-ops-mgmt.group.readView group information.XXX
compute-ops-mgmt.group.updateUpdate a group.X
compute-ops-mgmt.group.useChange devices associated with a group.XX
compute-ops-mgmt.schedule.createCreate a schedule.X
compute-ops-mgmt.schedule.deleteDelete a schedule.X
compute-ops-mgmt.schedule.readView schedule information.XXX
compute-ops-mgmt.schedule.updateUpdate a schedule.XX
compute-ops-mgmt.server.readView server and general application information.XXX
compute-ops-mgmt.server.updatePerform actions that affect servers.XXX
compute-ops-mgmt.setting.createCreate a setting.X
compute-ops-mgmt.setting.deleteDelete a setting.X
compute-ops-mgmt.setting.readView setting information.XXX
compute-ops-mgmt.setting.updateUpdate a setting.X
compute-ops-mgmt.setting.useChange settings associated with a group.XX
compute-ops-mgmt.webhook.createCreate a webhook.X
compute-ops-mgmt.webhook.deleteDelete a webhook.X
compute-ops-mgmt.webhook.readView webhook information.XXX
compute-ops-mgmt.webhook.updateUpdate a webhook.X

Using Compute Ops Management permissions

If none of the built-in roles provide the set of permissions needed, a custom role can be created and assigned any set of permissions.

To create a custom role, or view the permissions associated with built-in roles, use the HPE GreenLake Roles & permissions page. Read more about this process in the HPE GreenLake user role documentation.

To assign a role, use the HPE GreenLake Workspace identity & access page. Read more about this process in the HPE GreenLake assign roles documentation.