RBAC & Access Controls
This section explains how to configure and govern Cloudaware access controls, including baseline access, additive permissions, data visibility, SSO/MFA, and audit-ready access reviews.
Core Access Layers
Use three layers together to control what users can do and what data they can see:
- Profiles: minimal baseline access (login/session/UI + object/field permissions).
- Permission sets: add module-specific privileges (Compliance admin, CMDB editor, cost actions).
- Scoping & sharing: restrict what data users can see (prod vs non-prod, owner/team, account/subscription/project).
Use role‑based access controls (RBAC) and field‑level security to align CMDB visibility with organizational responsibilities:
- Grant read access broadly for inventory and relationships where appropriate, but restrict sensitive fields (for example, data classification or regulatory scope).
- Use groups or roles that mirror team structure (operations, SecOps, FinOps, application teams) so access updates track organizational changes.
Coordinate CMDB permissions with your identity provider and Change Management policies to ensure that changes are auditable.
Use these guides to design, configure, and review Cloudaware access controls consistently.
Least-Privilege Patterns
Explore practical access patterns by persona, least-privilege design principles, and the recommended operating model.
Profiles
Learn how profiles define baseline Cloudaware access on the Salesforce platform, including object permissions, field-level security, app access, and login policy settings.
Permission Sets
Use permission sets to add role- or task-specific privileges on top of baseline profiles without creating extra profiles for every team, module, or temporary access need.
Scoping & Sharing
Learn how to restrict CMDB record visibility by environment, account, project, ownership, application, or other operational boundaries.
SSO & MFA Patterns
Plan identity-provider group mapping, MFA requirements, session controls, break-glass access, and validation workflows before configuring provider-specific SSO.
SSO Configuration
Configure provider-specific SAML SSO settings for Cloudaware access through Microsoft Entra ID or Okta.
Audit & Access Reviews
Explore how to review access, audit RBAC and SSO changes, and collect evidence that supports least-privilege governance.