Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

User Access Management, Source Code permission

We centrally manage user access for compliance reasons. With that being said, team membership is managed by an RTC Administrator.

As an RTC Administrator without being part of the project area or anywhere in its hierarchy (I removed my id as a team member or Project Administrator)
I can still:
Read the Source Code.
Write to the Source Code.
Make any changes to the project area I choose.


However, one of the few actions that I would really need to do is generate a team invitation after a user is added, bu this cannot be performed because I am not part of the Project or Team Area.

I do not need to work with source code for some projects but I do need to add users the project or team area. From our perspective this is not as secure as requiring the RTC Admin to have explicit source code permissions just like anyone else. While at the same time permitting the admin to add users and generate follow up actions (e.g. Inivitations)

0 votes



One answer

Permanent link
This can actually be fixed by giving everyone the permission to send
invite email.

But I agree that the current situation is confusing ... why is there a
separate permission for sending out permission information? If you can
add members to a team/project area, I agree that you should always be
able to request that email be send out (I got bitten by the same problem
just last week ... I had permission to add people to my team area, but
didn't have permission to send out the invitations). I've submitted
work item 112429 to get this fixed.

Cheers,
Geoff

tdunnigan wrote:
We centrally manage user access for compliance reasons. With that
being said, team membership is managed by an RTC Administrator.

As an RTC Administrator without being part of the project area or
anywhere in its hierarchy (I removed my id as a team member or
Project Administrator)
I can still:
Read the Source Code.
Write to the Source Code.
Make any changes to the project area I choose.


However, one of the few actions that I would really need to do is
generate a team invitation after a user is added, bu this cannot be
performed because I am not part of the Project or Team Area.

I do not need to work with source code for some projects but I do need
to add users the project or team area. From our perspective this is
not as secure as requiring the RTC Admin to have explicit source code
permissions just like anyone else. While at the same time permitting
the admin to add users and generate follow up actions (e.g.
Inivitations)

0 votes

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Apr 16 '10, 10:16 a.m.

Question was seen: 5,018 times

Last updated: Apr 16 '10, 10:16 a.m.

Confirmation Cancel Confirm