Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Creating a User-Specific Role to Prevent or Allow Certain Actions on a Service

 

With Cross Provisioning Platform Release 15.1R1, you can create a user-specific role that prevents or allows the following actions on the Service page by the user to whom the role is assigned:

  • Decommissioning a service

  • Modifying a service

  • Bulk-decomissioning services on Service and Bulk Service Operations pages

  • Re-creating a service order after a failed deployment

  • Bulk-modifying services

Complete the following tasks to create a role and assign the role to a specific user account:

Creating a User-Specific Role

Note

Only an administrator can create a role.

To create a user-specific role:

  1. On the Junos Space Platform user interface, select Role Based Access Control > Roles.

    The Roles page appears.

  2. Click the Create Role icon on the menu bar.

    The Create Role page appears.

  3. In the Title text box, type a role name.

    The role name cannot exceed 32 characters. The name can contain letters, numbers, and the following special characters: hyphen (-), underscore (_), and period (.).

  4. In the Description text box, type a role description.

    The role description cannot exceed 256 characters. The description can contain letters, numbers, and the following special characters: hyphen (-), underscore (_), period (.), and comma (,).

  5. Select the CPP workspace from the application selection ribbon.

    Mouse over an application workspace icon to view the application workspace name. An expandable and collapsible tree of associated tasks appear below the selection ribbon for you to modify specific tasks that you want included on the Task Summary pane.

  6. On the CPP task pane, select or clear the following check boxes:
    • Modify PW-LDP—If you want to create a user-specific role to allow the user to modify an LDP-based point-to-point CPP service, select the Modify PW-LDP check box.

    • Modify PW-BGP—If you want to create a user-specific role to allow the user to modify a BGP-based point-to-point CPP service, select the Modify PW-BGP check box.

    • Modify L3VPN—If you want to create a user-specific role to allow the user to modify a Layer 3 VPN CPP service, select the Modify L3VPN check box.

    • Modify VPLS—If you want to create a user-specific role to allow the user to modify a VPLS CPP service, select the Modify VPLS check box.

    • Decommission PW-LDP—If you want to create a user-specific role to allow the user to decommission an LDP-based point-to-point CPP service, select the Decommission PW-LDP check box.

    • Decommission PW-BGP—If you want to create a user-specific role to allow the user to decommission a BGP-based point-to-point CPP service, select the Decommission PW-BGP check box.

    • Decommission L3VPN—If you want to create a user-specific role to allow the user to decommission a Layer 3 VPN CPP service, select the Decommission L3VPN check box.

    • Decommission VPLS—If you want to create a user-specific role to allow the user to decommission a VPLS CPP service, select the Decommission VPLS check box.

    • Bulk Service Operations—If you want to create a user-specific role to allow the user to perform bulk service operations, select the Bulk Service Operations check box.

    For example, if you move the newly created role with the Modify L3VPN check box selected, the user can modify the Layer 3 VPN service on the CPP > Services inventory page.

    If you move the newly created role with the Modify L3VPN check box cleared, the user cannot modify the Layer 3 VPN service on the CPP > Services inventory page.

  7. Click Create.

    The new user role is created. Apply the new role to a user account.

Applying the New Role to a User

Note

Only an administrator can assign a role to a user account.

To apply the new role to a user account:

  1. On the Junos Space Platform user interface, select Role Based Access Control > User Accounts.

    The User Accounts inventory page appears.

  2. From the inventory page, right-click the user account that you want to modify and select Modify User.

    The Modify User page appears. The Modify User page contains three areas—General, Role Assignment, and Domain Assignment

  3. To add or remove role assignments, click Role Assignment on the upper right of the Modify User page.
  4. Move the newly created role to the Selected list and click Finish.

    The new role is now applied to the selected user account.