The Open Telekom Cloud Marketplace is expanding its features with the introduction of a new Role Management system for both customers and sellers. This feature enables Tenant Owners to assign specific permissions to different IAM users within their organization, providing more granular control over Marketplace activities and improving security.
The Tenant Owner, the primary account for the tenant, can now delegate tasks without granting full administrative privileges. This is managed through a new “Manage Role” dashboard, which is accessible to the Tenant Owner upon logging into the Marketplace. From this central dashboard, the Tenant Owner can easily assign, update, or revoke roles for any IAM user in the tenant.
For Customers, the following roles can be assigned:
- Reports: This mandatory base role grants read-only access to view reports such as Workloads and Subscriptions, ideal for users who need to monitor activity without making changes.
- Profile Management: Includes all permissions of the Reports role and additionally allows users to update the customer profile information.
- Deployment/Subscription: Includes all permissions of the Reports role and grants users the ability to subscribe to and deploy product offerings from the Marketplace.
For Sellers, the following dedicated roles are available:
- Reports: This mandatory base role provides read-only access to sales history and product offering data for analysis and reporting purposes.
- Profile Management: Includes all permissions of the Reports role and allows for the management and updating of the seller profile.
- Product Offering: The most comprehensive seller role, which includes all permissions of the Reports role plus full control over managing product offerings, including on-boarding, updating, and off-boarding.
Please note: During a transitional period, users with the “Tenant Administrator” permission will retain their access to the Marketplace. This access will be revoked in a future step, after which only users with an assigned Marketplace role will be able to log in.
You can find more information in the technical documentation for sellers.