VCS privileges for users with multiple roles

Table: VCS privileges for users with multiple roles describes how VCS assigns privileges to users with multiple roles. The scenarios describe user Tom who is part of two OS user groups: OSUserGroup1 and OSUserGroup2.

Table: VCS privileges for users with multiple roles

Situation and rule

Roles assigned in the VCS configuration

Privileges that VCS grants Tom

Situation: Multiple roles at an individual level.

Rule: VCS grants highest privileges (or a union of all the privileges) to the user.

Tom: Cluster administrator

Tom: Group operator

Cluster administrator.

Situation: Roles at an individual and OS user group level (secure clusters only).

Rule: VCS gives precedence to the role granted at the individual level.

Tom: Group operator

OSUserGroup1: Cluster administrator

Group operator

Situation: Different roles for different OS user groups (secure clusters only).

Rule: VCS grants the highest privilege (or a union of all privileges of all user groups) to the user.

OSUserGroup1: Cluster administrators

OSUserGroup2: Cluster operators

Cluster administrator

Situation: Roles at an individual and OS user group level (secure clusters only).

Rule: VCS gives precedence to the role granted at the individual level.

You can use this behavior to exclude specific users from inheriting VCS privileges assigned to their OS user groups.

OSUserGroup1: Cluster administrators

OSUserGroup2: Cluster operators

Tom: Group operator

Group operator