7.3

Table Of Contents
Table 25. Tenant Roles and Responsibilities (Continued)
Role Responsibilities How Assigned
Shared access user Interact with items that other business
group members deploy, including
running actions against them. By default,
shared access users cannot request
items.
The tenant administrator designates the
shared access users when creating or
editing business groups.
Approval administrator
n
Create and manage approval
policies.
Tenant administrators can assign this role
to users in their tenant at any time from
the Administration tab.
Approver
n
Approve service catalog requests,
including provisioning requests or
any resource actions.
The tenant administrator or approval
administrator creates approval policies
and designates the approvers for each
policy.
Support user
n
Request and manage items on
behalf of other users in their
business group.
n
Change machine owner.
The tenant administrator designates the
support user when creating or editing
business groups.
Business user
n
Request catalog items from the
service catalog.
n
Manage their provisioned resources.
The tenant administrator designates the
business users who can consume IT
services when creating or editing business
groups.
Health Consumer
n
Can view test results.
n
Cannot configure, edit, or delete a
test.
The IaaS administrator designates
privilege to any role..
Containers User Roles and Access Privileges
You can use container-specific roles to control who can create and configure containers by using options
in the vRealize Automation Containers tab and who can add and configure container components in
blueprints by using options in the Design tab.
When you enable Containers, two container-specific roles appear in the list of roles that a
vRealize Automation tenant administrator can assign to users and groups.
User Role Description
Container
Administrator
Users and groups with this role can see the Containers tab in vRealize Automation. They can use all
theContainers options, such as configuring hosts, placements, and registries. They can also create
templates and provision containers and applications for configuration and validation purposes.
Container Architect Users and groups with this role can use containers as components when creating and editing blueprints in
vRealize Automation. They have permission to see the Design tab in vRealize Automation and to work with
blueprints.
For information about vRealize Automation administrator and user roles, see User Roles Overview in the
vRealize Automation Information Center.
Tenant administrators can assign one or both of these roles to users or groups in their tenant at any time
by using options on the vRealize Automation Administration tab.
Foundations and Concepts
VMware, Inc. 27