Definition of the Permissions of the Veritas Alta SaaS Protection Authorization / RBAC Model

Article: 100050019
Last Published: 2023-04-19
Ratings: 0 0
Product(s): Veritas Alta SaaS Protection

Description

Access All Items

This permission permits a user to retrieve any folder/item in the entire Veritas Alta SaaS Protection tenant, even when an item has the 'Prevent Retrieval' tag behavior associated to it. It is the only permission that is not granted as part of the 'Full Admin' permission. Users with 'Access All Items' granted will be able to choose 'Admin' mode in the Export Utility.

Full Admin

This permission grants all other permissions except for 'Access All Items'.

API

This permission is required by the Veritas Alta SaaS Protection Connector Service (HCS), and should only be granted to the account(s) configured for use by the HCS.

API Blobless Archive

This permission is required by the Veritas Alta SaaS Protection Connector Service (HCS) to work with the 'Blobless Archive' option on a connector. This should only be granted and used in a drive-shipping scenario.

End User Retrieval

This permission is required for any user to perform retrieval, whether the retrieval is performed via a stub file or the Veritas Alta SaaS Protection User Portal. In the default configuration, the 'Default' role has the permission enabled.

End User Portal

This permission is required for any user (internal or external) to sign in to the Veritas Alta SaaS Protection User Portal. In the default configuration, the 'Default' role has the permission enabled. Note: For the current  User Portal (redesigned for version 2.9.311), End User Retrieval permission is also required.
 
Within the Veritas Alta SaaS Protection User Portal are the following authorization controls (none of which are enabled in the 'Default' role by default):
 
Search
This permission determines if the user is able to execute searches in the Veritas Alta SaaS Protection User Portal.
Add/Remove Content
This permission determines if the user can add or delete content from the Veritas Alta SaaS Protection User Portal.
Internal Sharing
This permission determines if the user can share eligible items or folders they have access to within the Veritas Alta SaaS Protection User Portal with other users within the organization.
External Sharing
This permission determines if the user can share eligible items or folders they have access to within the Veritas Alta SaaS Protection User Portal with users that are external to the organization.
Export Utility
This permission permits a user to access the Export Utility. Specifically it controls two things:
  1. The visibility of the 'Export' action in the Veritas Alta SaaS Protection User Portal, and
  2. Whether 'End User' mode is available in the Export Utility.

Admin Portal

This permission is required for any user to sign in to the Veritas Alta SaaS Protection Admin Portal.  Within the Admin Portal are the following authorization controls:

 

Administration App
There are two sub-permissions for the Administration App:

 

This permission determines if the user can access the 'Administration' tab within the Veritas Alta SaaS Protection Admin Portal.

1. Manage Permissions 

This permission determines if the user can manage authorization settings within 'Users & Roles' within the 'Administration' tab.

2. View Auditing

This permission determines if the user can view 'Auditing' within the 'Administration' tab.

Analytics App

This permission determines if the user can access the dashboards within the 'Analytics' tab.

DLP App

This permission determines if the user can access functionality within the 'DLP' tab.

eDiscovery App
There is one sub-permission for the eDiscovery App:

 

This permission determines if the user can access functionality within the 'eDiscovery' tab. See also the section below on Securable Object Permissions for case-level authorization.

1. Create Cases

This permission determines if the user can create new eDiscovery cases.

Retention App

This permission determines if the user can access functionality within the 'Retention' tab.

Billing App

This permission determines if the user can access functionality within the 'Billing' tab.

System App

This permission determines if the user can access functionality within the 'System' tab.

Chargeback App

This permission determines if the user can access functionality within the 'Chargeback' tab.

Storage Tiering App

This permission determines if the user can access functionality within the 'Storage Tiering' tab.

 
For instructions on how to configure Users/Groups/Roles, see How to Use Veritas Alta SaaS Protection Role Based Access Control (RBAC) .

Securable Object Permissions

Discovery Cases

For users with access to the Veritas Alta SaaS Protection Admin Portal and authorization to access the 'eDiscovery App', Securable Object Permissions will determine what cases they are able to access. Within each case are the following authorization controls:
 
Read
Determines if the user has read access to the particular case. This is simply the ability to see that the case exists in the eDiscovery app, and be able to see its configuration details.
Modify
Determines if the user can modify the particular case. This includes the ability to add search results to the case.
Read Case Items
This permission allows a user to read items in the given case. Currently this will be required to export items for the case. In the future it will likely also control if a user can preview/review case items.
Export Utility
This permission permits a user to run the export utility in 'Case' mode. The user still requires access to the items to be exported (granted via organic permissions, 'Access All Items', or 'Read Case Items').
 
 
 

Was this content helpful?