Users, Groups & Roles
STRATUM separates authentication from authorization. Use Users, Groups, and Roles to control what an authenticated identity is allowed to do.
Authorization model
Groups collect users that need the same access. STRATUM roles are built in and define the actions those users are allowed to perform; operators assign the available roles rather than creating or editing role definitions.
External authentication does not replace STRATUM authorization. When Active Directory or another external identity provider is used, STRATUM still requires a local authorization record for the identities that are allowed to use the platform.
Interface tour
Authorization Groups
Create or edit groups that collect users for STRATUM authorization. Use groups to assign access consistently instead of repeating permissions user by user.
Authorization Roles
STRATUM roles are built in. The roles shown here are: Platform administration (platform-admin), which grants platform-administration access; Can edit mission topology (mission-planner), which allows Mission Planner topology changes; and Can operate systems (operator), which allows system operations. Assign the built-in role that matches the user or group’s operational responsibility.
User Authorization
Create the STRATUM user authorization record and associate the required groups or roles. This step is still required when authentication is provided by Active Directory.
The outcome you should see
Authenticated users are represented in STRATUM authorization and receive access through the intended groups and built-in roles.
