TECHNICAL GUIDE
Administration · ADM-06

Users, Groups & Roles

STRATUM separates authentication from authorization. Use Users, Groups, and Roles to control what an authenticated identity is allowed to do.

AUTHORIZATION

Authorization model

Groups collect users that need the same access. STRATUM roles are built in and define the actions those users are allowed to perform; operators assign the available roles rather than creating or editing role definitions.

External authentication does not replace STRATUM authorization. When Active Directory or another external identity provider is used, STRATUM still requires a local authorization record for the identities that are allowed to use the platform.

INTERFACE

Interface tour

REFERENCE 01

Authorization Groups

Create or edit groups that collect users for STRATUM authorization. Use groups to assign access consistently instead of repeating permissions user by user.

FIGURE 01Authorization Groups
REFERENCE 02

Authorization Roles

STRATUM roles are built in. The roles shown here are: Platform administration (platform-admin), which grants platform-administration access; Can edit mission topology (mission-planner), which allows Mission Planner topology changes; and Can operate systems (operator), which allows system operations. Assign the built-in role that matches the user or group’s operational responsibility.

FIGURE 02Authorization Roles
REFERENCE 03

User Authorization

Create the STRATUM user authorization record and associate the required groups or roles. This step is still required when authentication is provided by Active Directory.

FIGURE 03User Authorization
RESULT

The outcome you should see

Authenticated users are represented in STRATUM authorization and receive access through the intended groups and built-in roles.