Skip to main content
NetApp Console setup and administration

Set up role-based access for Cloud Volumes ONTAP in NetApp Console

Contributors netapp-tonias

Set up access to Cloud Volumes ONTAP so existing Console users retain the access they need and new subscribers can add users with appropriate permissions.

Use one of the following sections:

  • New to NetApp Console and Cloud Volumes ONTAP: Set up role-based access for new users and Cloud Volumes ONTAP systems.

  • Upgrading to a Console agent version that supports roles: Review the roles automatically assigned to existing users and adjust them as needed.

Set up access for users after initial configuration of Cloud Volumes ONTAP

New subscribers start by creating a Console organization. The first subscriber is given the role of Organization admin. Learn about identity and access management.

Plan Cloud Volumes ONTAP role assignments

Assign a Cloud Volumes ONTAP role at the organization, folder, or project level that contains the system. Platform roles enable users to administer NetApp Console resources, such as organizations, folders, projects, members, and resource access. Cloud Volumes ONTAP roles enable users to manage Cloud Volumes ONTAP systems.

Assign only the roles each user needs. Assign both a platform role and a Cloud Volumes ONTAP role when a user administers Console resources and manages Cloud Volumes ONTAP systems. A platform role does not replace a Cloud Volumes ONTAP role for Cloud Volumes ONTAP operations.

  • For example, assign the Folder or project admin and Cloud Volumes ONTAP admin roles to a user who manages access to a project and manages Cloud Volumes ONTAP systems in that project.

  • Assign the Organization admin and Cloud Volumes ONTAP operator roles to a user who manages Console agent settings and Cloud Volumes ONTAP systems throughout the organization.

  • If a user does not need to administer Console resources, assign only a Cloud Volumes ONTAP role that matches the level of access they require for managing Cloud Volumes ONTAP systems.

Use these role assignments when a user needs to administer Console resources and manage Cloud Volumes ONTAP systems in an organization that uses NetApp Console only for Cloud Volumes ONTAP.

Scope Platform role Cloud Volumes ONTAP role Recommendation

Organization

Organization admin

Cloud Volumes ONTAP operator

When a user must administer Console resources (including Console agent settings) and manage Cloud Volumes ONTAP systems

Folder or project

Folder or project admin

Cloud Volumes ONTAP admin

When a user must administer Console resources in a particular folder or project and administer Cloud Volumes ONTAP systems

Folder or project

Folder or project admin

Cloud Volumes ONTAP operator

When a user must administer Console resources in a particular folder or project and manage Cloud Volumes ONTAP systems

Folder or project

Folder or project admin

Cloud Volumes ONTAP viewer

When a user must administer Console resources in a particular folder or project and only needs read-only access to Cloud Volumes ONTAP systems

Note A known issue currently prevents the Organization viewer and Cloud Volumes ONTAP viewer role combination from working at the organization scope. Use the Organization admin or Folder or project admin role as a temporary workaround.
Steps
  1. Sign up for the NetApp Console and create your organization.

  2. Use the default project or create folders and projects that match how you want to organize your Cloud Volumes ONTAP systems.

  3. Configure or associate the Cloud Volumes ONTAP subscription.

  4. Add users, service accounts, or federated groups to the organization. Learn how to add members to a NetApp Console organization.

  5. Assign a Cloud Volumes ONTAP role to a user at the organization, folder, or project level where the system will be managed. If a member also needs to administer Console resources and assign access to others, assign the appropriate platform role.

  6. Add or discover the Cloud Volumes ONTAP system in the project where it will be managed. Learn about Cloud Volumes ONTAP.

  7. If the system or its Console agent must be available in other projects, associate the resources with those projects. Learn how to associate resources to folders and projects.

Review roles after upgrading the Console agent

After you upgrade a Console agent to version 4.9.0 or later, the Console automatically assigns Cloud Volumes ONTAP roles to existing users based on their platform roles. This one-time assignment helps users retain appropriate Cloud Volumes ONTAP access without requiring an administrator to assign each role manually. Users are assigned Cloud Volumes ONTAP roles automatically based on the user's existing platform role. The mappings apply only during migration; a platform role does not replace an explicit Cloud Volumes ONTAP role for new assignments. Review the new roles to confirm that users retain only the access they need.

Steps
  1. Identify the organization, folder, or project that contains each Cloud Volumes ONTAP system.

  2. Review the Cloud Volumes ONTAP role assigned to each user and confirm that it is assigned at the organization, folder, or project level containing the system. Learn about the Cloud Volumes ONTAP roles that are assigned automatically after upgrading.

  3. Assign or change the Cloud Volumes ONTAP role when the seeded role does not match the user's responsibilities. The seeding process assigns the Cloud Volumes ONTAP admin or viewer role based on the user's existing platform role. If a user needs operator-level permissions, assign the Cloud Volumes ONTAP operator role explicitly after seeding.

  4. Wait up to one hour for new or updated role assignments to take effect. Cloud Volumes ONTAP refreshes role assignments every hour.

  5. Have the user access the Cloud Volumes ONTAP system and confirm that the available operations match the assigned role.

If a user cannot access a system, verify that the user has a Cloud Volumes ONTAP role at the organization, folder, or project level.