RBAC

Configure who can access xDP and what they can do using role-based access control (RBAC) in Admin Central.

What is RBAC?

Role-based access control (RBAC) assigns permissions through roles rather than to individual users directly. In xDP:

  1. Users are added to groups (for example Admin, Contributor, Viewer).

  2. Each group is assigned one or more tenant roles.

  3. Each tenant role bundles permissions — the platform features a user can view, create, modify, or delete.

When a user signs in to xDP, the UI loads their effective permissions and shows only the menus and actions they are allowed to use.

Key concepts

Term

Description

User

A person who signs in to xDP with a tenant account

Group

A collection of users; roles are typically assigned to groups, not individuals

Tenant role

A named set of permissions scoped to the xDP product in Admin Central

Permission

Access to a platform feature at a given level (View, Modify, Delete, or Create)

Service user

A non-human account used for cluster creation and automation

Prerequisites

  • You hold the Tenant Admin role or User Management permissions (create/modify users, roles, and groups).

  • You can open Settings → Admin Central in xDP and sign in to the Admin Central portal.

Setup overview

Step

Page

Create groups, add users, configure the default service user for cluster creation

Users and Groups

Assign roles to groups and review permissions

Roles and Permissions

Recommended order:

  1. Users and Groups — Open Admin Central, create Admin, Contributor, and Viewer groups, add users, and configure dataplane-service-user with the required ADOC and xDP roles before creating clusters.

  2. Roles and Permissions — Assign Tenant Admin, Editor, and Viewer to each group and review the permission reference.