Cloud Pak for Business Automation

Cloud Pak for Business Automation

Come for answers. Stay for best practices. All we’re missing is you.

 View Only
  • 1.  Is ABAC (Attribute based access control) supported by CP4BA?

    Posted Mon September 23, 2024 09:46 AM

    Deal all,

    Does any knows an answer for the next question?

    I know RBAC is supported by CP4BA. Is ABAC (Attribute based access control) also supported by CP4BA?

    Thanks in advance.

    Ab.



    ------------------------------
    ABDERAHIM CHARKI
    ------------------------------


  • 2.  RE: Is ABAC (Attribute based access control) supported by CP4BA?

    Posted Tue September 24, 2024 03:32 AM

    Hi Ab,

    CP4BA has many "capabilities".

    In Workflow RBAC would mean: This user can administrate running process instances.
    Workflow is finer grained. We can set this role in various scopes, down to the process instance level. We call that "instance based authorization".


    Using the team services in Workflow you can implement a static attribute based authorization scheme: Tasks are assigned to teams. The team can be calculated by custom code. The custom code can query users by attributes (e.g. from LDAP) and return only those where the manager flag is true or the language is Spanish or whatever.

    See https://www.ibm.com/docs/en/baw/24.x?topic=team-using-services-define-dynamic-teams 

    This is static, though. That is, if you learned Spanish and have your attribute updated, the task assignment might not change.

    Workflow even allows you to maintain user attributes in the product database, independent of LDAP.

    https://www.ibm.com/docs/en/baw/24.x?topic=interface-creating-user-attribute-definition

    HTH

    Jens



    ------------------------------
    Jens Engelke
    ------------------------------



  • 3.  RE: Is ABAC (Attribute based access control) supported by CP4BA?

    Posted Tue September 24, 2024 12:02 PM

    And in FileNet, you're looking for Markings or Marking Sets. See this for an overview



    ------------------------------
    Scott Sumner-Moore
    ------------------------------