Key Concepts
Scope Logic
The logic for determining access in user access management follows a union principle, ensuring flexibility when managing user access to resources.Key rules for scope
Attributes are assigned to users as part of their role or scope settings. Copilot administrators define attributes when configuring access levels. A user might receive attributes based on factors such as:- Their department or team. For example, region: North America.
- The brands they manage. For example, brand: Nike.
- Their role-specific permissions. For example, category: Electronics.
- Can access all resources, regardless of the resource’s attributes.
- New users start with full access until a scope is assigned.
- Can access a resource if any of their attributes match the resource’s attributes.
- Can access a resource if any of the user’s attributes is a partial match with the resource’s attributes.
- Can’t access a resource if none of the resource’s attributes match with user’s attributes.
Example Scenarios
Prerequisites
Ensure you have administrator privileges to edit or delete user access settings.Procedure
- In the left menu, click Settings > Account Settings. The Account Settings page is displayed.
- Click User Management. The User Management page is displayed.
- In the User column, click the Edit Roles icon. The user profile is displayed.
-
Do one of the following:
- If the user already has a role and you want to add more scope to their role, click Add Scope next to the role in the Scope column and skip to step 7.
The Add Scopes window is displayed. - If the user has no roles, click Add Roles & Scopes.
The Add Roles & Scopes window is displayed.
- If the user already has a role and you want to add more scope to their role, click Add Scope next to the role in the Scope column and skip to step 7.
- In the Role Set field, select the roles you want enabled for the user. Multiple roles can be selected.
- Click Add Scopes. The fields App and Resource are displayed.
- In the App field, select an app you want to use for the user’s scope.
- In the Resource field, select a resource of the app you want to use for the user’s scope. The fields Attribute key and Attribute value are displayed.
- In the Attribute key field, select the attribute type you want to use for the user’s scope. The selection of Attribute key varies across organizations. To discuss your attribute options, contact your customer success manager.
- In the Attribute value field, select the specific attribute you want to use for the user’s scope.
- (Optional) Click Add Another Scope as needed.
- (Optional) Click Add Another Role Set as needed.
- In the Add Roles & Scopes window, click Save
- In the user profile, click Save
