Skip to content

Commit 407d213

Browse files
Merge pull request #10481 from mendix/kk-pmp-role-management
PMP role management
2 parents 872ea2e + 6cfba95 commit 407d213

File tree

9 files changed

+151
-0
lines changed

9 files changed

+151
-0
lines changed
Lines changed: 149 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,149 @@
1+
---
2+
title: "Dynamic Role Management in Private Mendix Platform"
3+
linktitle: "Dynamic Role Management"
4+
url: /private-mendix-platform/dynamic-role-management/
5+
description: "Documents the dynamic role management functionality of the Private Mendix Platform."
6+
weight: 50
7+
---
8+
9+
## Introduction
10+
11+
Starting from version 2.0, Private Mendix Platform offers dynamic role management to strengthen governance, improve flexibility, and streamline access control. This feature ensures that organizations can manage roles and permissions dynamically, aligning with evolving business and compliance requirements.
12+
13+
To access the **Role Management** page, go to the **Admin > Manage** section of the Mendix Private Platform. This page centralizes all role-related governance and permissions.
14+
15+
{{< figure src="/attachments/private-platform/pmp-roles1.png" class="no-border" >}}
16+
17+
Private Mendix Platform 2.0 ships with a set of predefined roles to cover common responsibilities:
18+
19+
* **Developer** - Full access to application development features.
20+
* **Contributor** - Limited access, typically for business users or domain experts contributing to projects.
21+
* **Operator** - Focused on operational tasks such as deployments, monitoring, and cluster management.
22+
* **Administrator** - Highest level of access, with full governance and configuration rights.
23+
24+
Admins can create new custom roles tailored to organizational needs.
25+
26+
## Role Editing
27+
28+
Admins can edit any default or custom role to adjust the following permissions dynamically:
29+
30+
* Project permissions
31+
* Cluster permissions
32+
* CI/CD permissions
33+
34+
## Group Management
35+
36+
To access the **Group Management** page, go to the **Admin > Manage** section of the Mendix Private Platform. It provides a hierarchical structure for managing user roles and resource access across applications, clusters, and namespaces.
37+
38+
{{< figure src="/attachments/private-platform/pmp-roles2.png" class="no-border" >}}
39+
40+
Groups are organized in a hierarchical tree. The root group is created by Private Mendix Platform automatically and serves as the foundation for all user-created groups.
41+
42+
Admins can customize root group information to align with organizational needs. The hierarchy depth is theoretically unlimited, supporting complex organizational structures.
43+
44+
Every new group must be assigned a parent group. This ensures proper inheritance of governance and permissions.
45+
46+
{{< figure src="/attachments/private-platform/pmp-roles3.png" class="no-border" >}}
47+
48+
### Group Ownership and Resources
49+
50+
Each group can own or associate resources, and permissions are applied to its members through assigned roles.
51+
52+
The following resources are currently supported:
53+
54+
* Apps - Application-level access control.
55+
* Namespace purposes - Permissions tied to namespaces for deployment or operational segregation.
56+
57+
#### Ownership and Association Rules
58+
59+
* Apps - An app can only be owned by one group. Ownership is exclusive to ensure clear accountability.
60+
* Namespaces - A namespace can be associated with multiple groups non-exclusively, allowing flexible sharing of operational responsibilities across teams.
61+
62+
### Role Assignment Model
63+
64+
Roles are assigned to group members, not to the group itself. If a group has a subgroup, then members of the main group are automatically inherited into the subgroup with the same roles they hold in the main group. This ensures consistency of permissions across hierarchical structures and reduces duplication of role assignments.
65+
66+
{{< figure src="/attachments/private-platform/pmp-roles5.png" class="no-border" >}}
67+
68+
### Group Creation
69+
70+
When creating a new group, admins must provide the following information:
71+
72+
* **Description** - A clear explanation of the group's purpose.
73+
* **Group Admins** - One or more administrators responsible for managing the group.
74+
* **Parent Group** - Defines the group's place in the hierarchy.
75+
76+
### Statistics Dashboard
77+
78+
The Group Management page also provides real-time statistics to help administrators monitor governance:
79+
80+
* **Number of Groups** - Total number of groups created under the hierarchy.
81+
* **Number of Resources Owned** - Count of Apps and namespace purposes associated with groups.
82+
* **Namespaces Assigned to Groups** - Total namespaces linked to groups for operational control.
83+
* **Average Number of Members per Group** - Helps track group size and distribution of users.
84+
85+
{{< figure src="/attachments/private-platform/pmp-roles6.png" class="no-border" >}}
86+
87+
## Permission Synchronization
88+
89+
### Overview
90+
91+
Permission synchronization ensures that role changes in groups (admin mode) are automatically reflected in user mode, impacting the resources owned or associated with those groups. This mechanism guarantees consistency between governance configurations and actual user access.
92+
93+
### Role Change Propagation
94+
95+
When a member's role changes in a specific group through admin mode, the update is immediately synchronized to user mode. The change affects all resources owned by or associated with that group (for example, apps, or namespaces). This synchronization eliminates manual updates and ensures governance policies are enforced consistently.
96+
97+
### Combined Permission Calculation
98+
99+
When multiple roles apply to a member, Private Mendix Platform calculates a combined permission set.
100+
101+
The calculation is performed as a scope union of all roles assigned and inherited.
102+
103+
This ensures that the member's effective permissions cover all capabilities granted by any of the roles.
104+
105+
## User Mode
106+
107+
### Login and Portal Creation
108+
109+
When a user logs in, they can create a new app in Private Mendix Platform.
110+
111+
The **Teams** page provides visibility into all members associated with the app, along with their roles.
112+
113+
### Teams Page Overview
114+
115+
The Teams page displays two categories of members:
116+
117+
* Direct members
118+
* Owner
119+
120+
The user who created the app automatically becomes the owner. Owners have full control over the app, including inviting new members and assigning roles.
121+
122+
#### Invited Members
123+
124+
Owners can invite additional users into the App. These members are assigned specific roles such as:
125+
126+
* Operator
127+
* Contributor
128+
* Developer
129+
130+
#### Inherited Members
131+
132+
Inherited memberships are derived from group memberships defined in the **Group Management** page.
133+
134+
The folowing inheritance paths are available:
135+
136+
* Owner's group - Members of the group to which the owner belongs are automatically inherited into the app.
137+
* Parent group - Members of the parent group in the hierarchy are also inherited.
138+
139+
Roles for inherited members are determined by the **Group Management** page and applied automatically.
140+
141+
{{< figure src="/attachments/private-platform/pmp-roles7.png" class="no-border" >}}
142+
143+
### Role Assignment in User Mode
144+
145+
Direct members receive roles explicitly assigned by the app owner.
146+
147+
Inherited members retain the roles defined in their group context.
148+
149+
This approach ensures consistency. Direct roles can be managed with app-specific assignments, while inherited roles can have governance-driven assignments from group hierarchy.

content/en/docs/private-platform/reference/admin/pmp-ref-admin-manage.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -233,6 +233,8 @@ In the **Actions** tab, you can also log out all users currently logged in to yo
233233

234234
In the **Group Management** tab, you can create and edit user groups. These groups typically reflect your organization's structure. You can also use the **Automation Settings** option to automatically assign users to groups based on their profile attributes.
235235

236+
For more information about group management in Private Mendix Platform version 2.0 and newer, see [Dynamic Role Management in Private Mendix Platform](/private-mendix-platform/dynamic-role-management/).
237+
236238
### Platform
237239

238240
In the **Deployment** section, administrators can view and manage statistics, activity logs, webhooks, and licenses.
140 KB
Loading
323 KB
Loading
207 KB
Loading
186 KB
Loading
109 KB
Loading
128 KB
Loading
122 KB
Loading

0 commit comments

Comments
 (0)