Managing operational data in complex IT environments requires a delicate balance between accessibility and security. Today, we're excited to introduce enhanced permission controls in IBM Concert Operate that give administrators the flexibility they need in defining user roles and access levels for alert and incident management.
Why Granular Permissions Matter
In enterprise environments, different team members have different responsibilities. A junior operator might need to view alerts and run predefined actions, while a senior incident manager requires full control over incident resolution. Previously, organizations had to choose between broad permissions that granted too much access or restrictive settings that hindered productivity.
Our new granular permission system solves this challenge by introducing role-based access controls that align with real-world operational workflows.
Understanding the Permission Tiers
We've organized permissions into three logical tiers that map to common organizational roles:
Tier 1: Read-Only Access
Perfect for stakeholders, auditors, and team members who need visibility without modification rights.
View operational data provides complete read-only access to alerts, incidents, filters, and views
- Ideal for dashboards, reporting, and monitoring roles
- Ensures data visibility without risk of accidental changes
Tier 2: Operational Access
Designed for frontline operators and incident responders who need to take action but within controlled boundaries.
Manage personal filters - Create and manage your own alert filters without affecting team configurations
Manage personal views - Customize your workspace with personal view layouts
Use actions - Run predefined actions on alerts and add timeline comments
Update incidents - Update incident status, resolve incidents, and document investigation activities
These permissions empower your team to work efficiently while maintaining organizational standards.
Tier 3: Administrative Access
For administrators and team leads who need comprehensive control over operational data management.
Manage operational data - The most comprehensive permission, providing full control over alerts, incidents, filters, views, and actions
Manage filters - Create and manage shared filters visible to other users
Manage views - Configure shared view layouts for teams
Real-World Use Cases
Scenario 1: The Monitoring Team
Your NOC team monitors alerts 24/7 but shouldn't modify incident configurations.
Solution: Assign View operational data + Use actions
This combination allows them to view all operational data and execute predefined actions when alerts require immediate attention, without the ability to modify system configurations.
Scenario 2: The Incident Responder
Your on-call engineers need to manage incidents and customize their workspace.
Solution: Assign View operational data + Update incidents + Manage personal filters + Manage personal views
They can view all data, update incidents, and create personalized filters and views that optimize their workflow—all without affecting team-wide configurations.
Scenario 3: The Administrator
Your administrator need to configure shared resources for their teams.
Solution: Assign Manage operational data or the combination of Manage filters + Manage views
This provides administrative control over shared configurations while maintaining the flexibility to delegate specific responsibilities.
The Power of Personal vs. Shared Resources
One of the most powerful aspects of our new permission system is the distinction between personal and shared resources:
Personal Resources:
- Always private to the creator
- Can be created by users with "personal" permissions
- Cannot be shared with other users
- Perfect for individual workflow optimization
Shared Resources:
- Visible to other users (subject to ACL configuration)
- Require administrative permissions to create
- Can be managed by administrators across the team
- Ideal for standardizing team workflows
Access Control Lists (ACLs): An Additional Layer
Beyond permissions, our system supports Access Control Lists that provide fine-grained control over individual resources. Even with administrative permissions, users can only manage resources they have ACL access to. This dual-layer approach ensures maximum security and flexibility.
Migration Path for Existing Deployments
If you're currently using the broad Manage operational data permission, don't worry—nothing changes for you. This permission continues to provide comprehensive access to all features.
The new granular permissions are additive, allowing you to:
- Continue using existing broad permissions for power users
- Create new roles with restricted permissions for specific team members
- Gradually migrate to a more granular permission model at your own pace
Getting Started
To implement these new permissions:
- Audit your current roles - Identify which team members need which capabilities
- Design your permission strategy - Map organizational roles to permission tiers
- Create custom roles - Combine permissions to match your operational workflows
- Test and refine - Start with a pilot group before rolling out organization-wide
Looking Forward
These enhanced permissions represent our commitment to providing enterprise-grade security and flexibility in IBM Concert Operate. By aligning technical capabilities with organizational structures, we're helping you build more secure, efficient, and scalable operational workflows.
Whether you're managing a small team or a large enterprise operation, our granular permission system adapts to your needs—giving everyone the right level of access to do their job effectively.