2.7

Table Of Contents
User Management Overview
System and organization administrators use a combination of user logins, privileges, permissions, and roles
(role-based access control) to manage Data Director users. Role-based access control provides management of
users and the tasks that they can perform on objects. You can grant and revoke roles and permissions at the
system level, on organizations, and on database groups, databases, and templates within organizations.
Roles are sets of permissions required to perform particular jobs. Jobs are sets of tasks that a user with a
particular role is responsible for performing, such as the set of tasks that are the responsibility of a database
administrator. System and organization administrators define roles as part of defining security policies, and
grant the roles to users. To change the permissions and tasks associated with a particular job, the system or
organization administrator updates the role settings. The updated settings take effect for all users associated
with the role.
n
To add a user to a job, the system or organization administrator grants the role to the user.
n
To remove a user from a job, the system or organization administrator revokes the role from the user.
Changes are effective immediately.
Roles apply only to the organization in which they are created. For example, an organization administrator
creates a database administrator role that includes permission to add and remove database users, start and
stop databases, and perform backups for a specific database in that organization. Users that are granted the
database administrator role in that organization can perform database administrator tasks only within that
organization.
Organization administrators usually manage role and permission assignments for their organizations.
However, any user that has the permission to grant and revoke permissions on an object can grant all
permissions on that object to any user or any role. Organization administrators can also grant permissions
directly to users.
Each user's login account is unique in the system. Managing access, roles, and permissions for each user is
based on their user login account. The organization administrator can grant users access to one or more
organizations. Within those organizations, each user can be granted multiple roles and permissions.
Users who cannot view or access certain objects or cannot perform certain operations were not granted the
permissions to do so.
The following figure illustrates the scope of users and roles in Data Director.
Figure 3-1. Scope of users and roles in Data Director
User Namespace
Bob
role domain
System
(user) Alliance
DBG DBGDBGDBG
role domain role domain
(user) Benefits
DBAdmin
SysAdmin
DBAdmin
Organization
Organization
VMware vFabric Data Director Administrator and User Guide
34 VMware, Inc.