There are two types of permissions that work together to ensure the right level of access for all of your Ronin users:
Ronin obtains user access tokens and top level groups from Cognito.
Cognito can be connected to third party identity providers such as Google, Facebook, OpenID and SAML.
As a member of the Ronin Admin group, I can…
- Create projects and assign users to them.
- Monitor project budgets and pause projects if necessary.
- Configure the pre-configured software in the create machine workflow.
- Do everything a Ronin Lower Admin can do.
Ronin Lower Admin (previously Ronin Trial Admin)
As a member of the Ronin Lower Admin group, I can…
- Access the Budget Management screen
- Monitor project budgets and pause projects if necessary for the projects I administer (Project Admin in Ronin - see Ronin Project Groups below).
- Modify the project settings and information (budgets, timeframe, billing codes etc.)
- Do everything a Ronin User can do.
As a member of the Ronin User group, I can...
- Login to Ronin using my account sync'd from a connected Active directory or sent to me by Ronin.
- Be found in a Ronin user search.
- Access and/or administer projects that have been assigned to me
- Log out.
RONIN PROJECT GROUPS
As a Project Admin within a Ronin project, I can...
- Modify permissions for other users within my project, including adding additional Project Admins, Users, Viewer.
- Do everything a Project User can do.
As a Project User within a Ronin project, I can…
- Launch, start, stop and terminate instances within my project.
- Choose the size of the machine I want to launch.
- Attach additional storage to my project’s instances.
- Backup my project’s storage.
- Package my research infrastructure to reproduce or share my work within my project.
- Create, manage and delete object storage. (s3)
- Do everything a Project View can do.
As a Project Viewer within a Ronin project, I can...
- Search for projects I have access to.
- View the project dashboard.