Skip to main content

RBAC & Access Controls

This section explains how to configure and govern Cloudaware access controls, including baseline access, additive permissions, data visibility, SSO/MFA, and audit-ready access reviews.

Core Access Layers

Use three layers together to control what users can do and what data they can see:

  • Profiles: minimal baseline access (login/session/UI + object/field permissions).
  • Permission sets: add module-specific privileges (Compliance admin, CMDB editor, cost actions).
  • Scoping & sharing: restrict what data users can see (prod vs non-prod, owner/team, account/subscription/project).

Use role‑based access controls (RBAC) and field‑level security to align CMDB visibility with organizational responsibilities:

  • Grant read access broadly for inventory and relationships where appropriate, but restrict sensitive fields (for example, data classification or regulatory scope).
  • Use groups or roles that mirror team structure (operations, SecOps, FinOps, application teams) so access updates track organizational changes.
note

Coordinate CMDB permissions with your identity provider and Change Management policies to ensure that changes are auditable.

Use these guides to design, configure, and review Cloudaware access controls consistently.

Least-Privilege Patterns

Explore practical access patterns by persona, least-privilege design principles, and the recommended operating model.

Profiles

Learn how profiles define baseline Cloudaware access on the Salesforce platform, including object permissions, field-level security, app access, and login policy settings.

Permission Sets

Use permission sets to add role- or task-specific privileges on top of baseline profiles without creating extra profiles for every team, module, or temporary access need.

Scoping & Sharing

Learn how to restrict CMDB record visibility by environment, account, project, ownership, application, or other operational boundaries.

SSO & MFA Patterns

Plan identity-provider group mapping, MFA requirements, session controls, break-glass access, and validation workflows before configuring provider-specific SSO.

SSO Configuration

Configure provider-specific SAML SSO settings for Cloudaware access through Microsoft Entra ID or Okta.

Audit & Access Reviews

Explore how to review access, audit RBAC and SSO changes, and collect evidence that supports least-privilege governance.