Airlock as a Service Knowledge Base

Roles and permissions

In Airlock as a Service, users that interact with the Airlock Console are called actors. Actors hold certain roles with corresponding permissions. These permissions allow performing the tasks associated with the role. By assigning a role to a user, the corresponding permissions are granted.

For an overview of the SaaS actors, see the table below. For a detailed overview of available roles and permissions, download this spreadsheet: Roles and permissions.xlsx. It covers permissions for working in the Airlock Console — e.g., creating tenants, inviting administrators, and activating IAM configurations — as well as permissions for the tenant IAM Adminapp, where administrators manage the end users of your application

SaaS Administrator

In Airlock as a Service, a SaaS Administrator is responsible for managing and operating the Airlock SaaS service. A SaaS Admin with the role SaaS Administrator has full access to the organization, including all its tenants and its administrators. This role also allows managing generic secrets and key pairs used in the IAM configurations. Additionally, a SaaS Admin with the role role SaaS Administrator can view and manage OAuth 2.0 clients used for system to system communication via Airlock APIs.

The first SaaS Administrator of an organization, automatically receives the SaaS Administrator role. This is the person who creates the Airlock as a Service account through the self-registration process. After completing the self-registration successfully, they can access the Airlock Console (see also Setup Airlock).

The first SaaS Administrator can set up the SaaS organization that represents the customer and create the required tenants. They can also invite additional administrators and assign them to tenants.

Invited administrators can by default only perform tasks on end-users, such as search for and manage end-users, view end-user logs, -profiles and authentication tokens. It is possible to assign additional roles to the invited administrator, such as the SaaS Administrator role or individual roles, depending on their task. For a detailed overview or roles, permissions, and related actors, see .

End-user

End-users are the persons that access your company's applications. They do this via the tenant Loginapp, according to the authentication and authorizations flows defined in the corresponding active tenant IAM configuration.

Notice
The roles shown below do not apply to end-users. End-users have their own roles, which are configured as part of the tenant configuration. For more information, see Working with end-users.

Airlock Partner

The Airlock Partner actor is responsible for creating/altering a tenant IAM configuration according to the requirements of your company, and uploading these new/altered IAM configurations into the Airlock Console. Currently, only employees of Airlock or Airlock partners can hold the corresponding role.