7.0

Table Of Contents
Best Practices When Entitling Users to Actions
Blueprints are complex and entitling actions to run on provisioned blueprints can result in unexpected
behavior. Use the following best practices when entitling service catalog users to run actions on their
provisioned items.
n
When you entitle users to the Destroy Machine action, entitle them to Destroy Deployment. A
provisioned blueprint is a deployment.
A deployment can contain a machine. If the service catalog user is entitled to run the Destroy
Machine action and is not entitled to run the Destroy Deployment, when the user runs the Destroy
Machine action on the last or only machine in a deployment, a message appears indicating that they
do not have permission to run the action. Entitling both actions ensures that the deployment is
removed from your environment. To manage governance on the Destroy Deployment action, you can
create a pre approval policy and apply it to the action. This policy will allow the designated approver
to validate the Destroy Deployment request before it runs.
n
When you entitle service catalog users to the Change Lease, Change Owner, Expire, Reconfigure
and other actions that can apply to machines and to deployments, entitle them to both actions.
Entitle Users to Services, Catalog Items, and Actions
When you add a service, catalog item, or action to an entitlement, you allow the users and groups
identified in the entitlement to request the provisionable items in the service catalog. Actions are
associated with items and appear on the Items tab for the requesting user.
There are several user roles with permission to create entitlements for business groups.
n
Tenant administrators can create entitlements for any business group in their tenant.
n
Business group managers can create entitlements for the groups that they manage.
n
Catalog administrators can create entitlements for any business group in their tenant.
When you create an entitlement, you must select a business group and specify individual users and
groups in the business group for the entitlement.
To understand how to create an entitlement so that you can use the interactions of services, catalog
items, and actions with approvals to provide the correct items in the service catalog, see Creating an
Entitlement.
Prerequisites
n
Log in to the vRealize Automation console as a tenant administrator or catalog administrator.
n
Verify that the catalog items to which you are entitling users are associated with a service. See Add
Catalog Items to a Service.
n
Verify that the business group for which you are defining the entitlement exists and that the member
users and user groups are defined. See Create a Business Group.
Configuring vRealize Automation
VMware, Inc. 394