Role based access control
8 min
what is role based access control? role based access control (rbac) is an essential security framework utilized by organizations to manage and restrict access to sensitive information and resources systematically this model operates on the principle of assigning users to specific roles that reflect their responsibilities and functions within the organization each role is associated with a predetermined set of permissions that define what actions a user can perform and what resources they can access key benefits by implementing rbac, organizations can ensure that individuals have access only to the information necessary for them to carry out their job responsibilities for instance, an admin must have access to set up ssids, while a help desk admin can only monitor the network for supporting end users this role centric approach not only simplifies access management but also reduces the risk of unauthorized access, thereby enhancing overall security furthermore, rbac enables organizations to streamline the process of onboarding and offboarding employees when a new employee joins the organization, assigning them to a role automatically grants them the relevant access permissions associated with that role conversely, when an employee leaves or changes roles, their access can be revoked or modified quickly and efficiently this scalability and flexibility make rbac a preferred choice for many organizations aiming to maintain robust security while promoting operational efficiency what groups does nile support? nile operates with three clearly defined groups administrator monitor, and help desk, each serving a distinct function within the system the administrator group is equipped with comprehensive capabilities which includes the ability to set up ssids, which are essential for establishing wireless networks furthermore, the admin role encompasses managing authentication to ensure secure access to the network; wired or wireless additionally, the admin can establish integrations with third party systems, such as servicenow and zscaler, facilitating streamlined operations and enhanced functionality on the other hand, the monitor group has a more restricted function as its name implies, the monitor role is limited to viewing data within the portal individuals in this role do not have the authority to modify or configure any settings within the portal, thereby ensuring that critical configurations remain securely managed by the admin role this role is assigned to employees who field end user calls and assist with troubleshooting lastly, the help desk admin group functions with capabilities akin to the monitor group, primarily focusing on data visibility however, this group holds additional responsibilities, including the approval of wired devices this involves a process where help desk admins can assess wired devices seeking access and then approve or deny them based on predefined criteria together, these roles contribute to a well structured and efficient operational framework, ensuring that admins can effectively setup up the network (ssid's, guest access etc ) and troubleshoot it while maintaining security and accessibility across the board nile also possesses a root admin role this individual is the initial registrant of the service the root admin holds the same privileges as the admin; however, the distinguishing factor is that the root admin has the authority to transfer the account to another admin comparison of group privelages feature root administrator administrator monitor help desk all settings \<font color="#48ae21">read/write\</font> \<font color="#48ae21">read/write\</font> read only read only wired device approval \<font color="#48ae21">read/write\</font> \<font color="#48ae21">read/write\</font> read only \<font color="#48ae21">read/write\</font> wireless deny \<font color="#48ae21">read/write\</font> \<font color="#48ae21">read/write\</font> read only \<font color="#48ae21">read/write\</font> all monitoring \<font color="#48ae21">read/write\</font> \<font color="#48ae21">read/write\</font> read only read only fedration with idp administrators can be created locally within the nile portal individuals with administrator privileges have the capability to create additional administrator accounts or manage help desk and monitor role administrators furthermore, nile can integrate with the customer's identity provider (idp) to facilitate access to the nile portal roles can be dynamically assigned through the idp, providing a streamlined approach to user management one significant advantage of this system is that when an employee leaves the company, their access to the nile portal is automatically revoked, ensuring enhanced security and compliance please review the azure ad https //docs nilesecure com/azure active directory integration#og8ch article to understand the configuration process the guest group is designated for granting employees access to the network via single sign on (sso) it is important to note that individuals within this group will not be granted access to the nile portal restricting access based on geoscope nile is pleased to introduce the concept of tags, which will be utilized to group sites effectively tags are free form, allowing multiple sites to be associated with the same tag this functionality empowers our customers to tag various site types, such as retail locations, stores, and carpeted offices, with their respective identifiers once a site or sites are tagged, these tags can be leveraged for role based access control (rbac), enabling the assignment of monitoring and settings privileges to users within the nile portal let us consider a scenario involving a customer acme inc who manages 100 retail sites alongside 15 enterprise sites following is the list of admins at acme inc name group access description jane smith adminstrator all jane is a global admin and should have access to all sites across acme inc john doe adminstrator retail only monitor global john is responsible for managing all the retail sites only but he should have monitoring capabilities for all sites karen mae adminstrator enterprise only karen should have read/write access to warehouse sites only sara kerr help desk enterprise only sara is an a help desk admin supporing all enterprising sites step 1 tag all the sites let's begin by tagging all retail sites with the appropriate retail tag and all enterprise sites with the corresponding enterprise tag step 2 create a new admin and map them to the appropriate tags
