6.5.1

Table Of Contents
You can set permissions on common tag operations to manage the operations over the inventory objects.
You must have vSphere administrator credentials to set and manage permissions for tags and organize
user's activities. When you create a tag, you can specify which users and groups can operate with that tag.
For example, you can grant administrative rights only to administrators and set read-only permissions for
all other users or groups.
Prerequisites
Grant the privilege.InventoryService.Tagging.label privilege to users that administer tags and tag
categories
Procedure
1 Log in to vSphere Web Client with administrator credentials.
2 From the vSphere Web Client Home, click Tags & Custom .
3 Click the Tags tab.
4 Select a tag from the list, right-click the tag, and select Add Permission.
You see a list with all default permissions for the selected tag.
5
Click the icon to add a permission to the existing list.
The Add permission dialog box appears.
6 In the Users and Groups pane, click Add, select all the users and groups you want to add, and click OK.
7 (Optional) Select a user or a group from the list and select a role from the Assigned Role list.
8 (Optional) Select Propagate to children to propagate the privileges to the children of the assigned
inventory object.
9 Click OK to save the new tag permission.
Tagging Best Practices
Incorrect tagging can lead to replication errors. To avoid these errors, diligently follow best practices when
tagging objects.
When working with tags in multiple node situations, expect replication delays between the nodes (generally
30 seconds to 2 minutes depending on your setup). Follow these best practices to avoid replication errors:
n
After creating a tag, if you immediately assign that tag to a local object, assign it from the management
node where you created the tag.
n
After creating a tag, if you immediately assign that tag to a remote object, assign it from the
management node to which the object is local. Depending on your environment setup, allow for
replication time to propagate the new tag before you use the tag.
n
Avoid simultaneously creating categories and tags from dierent management nodes before categories
and tags across nodes can nish the replication process. If duplicate categories or tags are created from
dierent nodes at the same time, the duplicates might not be detected and will appear. If you see these
results, manually delete duplicates from one management node.
Chapter 6 Tagging Objects
VMware, Inc. 77