Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

AUTHORIZATION AND POLICY · LAB

Build roles, assign them, and work out effective permissions

Give Cora two roles, predict her effective permissions as a union, confirm the server's answer, and see that groups and roles stay separate here.

Partly readyUses your lab tenant

The lesson

Builds on: Checking access to each object.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. Create the temporary group

    Recorded as tenant.groups.create succeeded.

  2. Give Cora a second role

    Recorded as tenant.users.management_roles.assign succeeded about [email protected].

  3. Take Help desk away from Cora again

    Recorded as tenant.users.management_roles.assign succeeded about [email protected].

  4. Cora's directory read is refused after the removal

    Recorded as tenant.users.read rejected.

Setup

  1. Complete Object and field checks in the tenant's own APIs first. Cora holds Auditor; Ben holds Help desk.

  2. In Groups, create lab-tmp-support-desk and add Ben and Cora.

  3. Open a private window for Cora and sign in at $ISSUER/manage. Because she holds a management role, she needs a second step: if she has no authenticator app or passkey yet, the tenant asks her to set one up now.

Walkthrough

  1. Assign Cora Help desk as well, so she holds Auditor and Help desk. Before looking anything up, write down her effective permissions: the union of both roles.

Why it matters: assignments only ever add. Nothing in one role can take away what the other grants, as the lesson's effective-permissions table shows for Omar.

  1. In Cora's window, reload $ISSUER/manage and ask for her current grants in the DevTools console:

(await (await fetch('/api/auth/tenant/roles')).json()).permissions

Compare the list with your prediction.

Why it matters: effective permissions are what the server computes from current assignments, on this request. Your union and its answer should match exactly.

  1. Read an assignment as a record. In Audit, open the tenant.users.management_roles.assign event for Cora. Identify the principal (Cora, a tenant user, by stable ID), the role, the actor (you) and the time. Then note what the lesson's record has that this one does not: a scope and an expiry.

Why it matters: in this tenant, every management assignment covers the whole tenant. The scope is real, the tenant itself, but it is chosen by where you create the assignment, not written into it.

  1. The scope boundary that does exist. Cora is a user of Lab Photos only. Optional: open $ISSUER2/manage in her window. Lab Mail has no account for her, and her roles mean nothing there.

Why it matters: a scope keeps "Help desk" from becoming "help desk of everything". Another tenant is outside every assignment you can make here.

  1. Groups against roles. Open Users or Groups and look for a way to give lab-tmp-support-desk a management role. There is none.

Why it matters: here a group says who belongs together and a role says what work needs, and the two are not connected. Adding someone to a group never grants management access, so the group's managers are not quietly granting roles.

  1. Remove Help desk from Cora. In her window, run the console call from step 2 again. The list is smaller at once.

Why it matters: assignments are evaluated on each request. No session or cached copy kept the removed permissions.

Break it

  1. Cora now holds only Auditor, which has no tenant.users.read. In her window open the Users page. The server refuses it, and Audit records the refused read.

Why it matters: no role that applies grants the permission, so default deny refuses the request. Whether the page also hides its menu item is a convenience, not the protection.

Check your work

Press Check my progress. The checks follow the group, Cora's second role, its removal and her refused directory read.

Also confirm by hand:

  • Your predicted union matched the permissions list in step 2.

Cleanup

  • Delete the group lab-tmp-support-desk.

  • Cora keeps Auditor only; Ben keeps Help desk.

Missing infrastructure

  • G45, scoped and group-based management assignments. A management role assigned to a group, and scoped to part of the tenant, such as "users in group lab-tmp-support-desk" or "clients tagged lab", would let the full lab reproduce Omar's two assignments, the nested-group surprise and the effective-permissions table exactly. The photo library API (G3 and G22) would add library and album scopes to the same exercise.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab