Your event program involves many kinds of people: planners and admins on your team, field colleagues who request meetings, and agency staff who execute. Audiences only ever see the app. Onomi separates what each of them can see and do. It uses layered roles, enterprise single sign-on, and audience-based visibility rules. Each person works with the access their job needs and nothing more.
Roles and access control in Onomi follows the role-based access control (RBAC) model. Access follows the role a person holds at each layer. Single sign-on (SSO) sits behind the sign-in, so people sign in with their corporate identity. The guides in this series document the role model and the steps for granting and removing access. They also cover enterprise sign-in with just-in-time provisioning, and how agencies and audience segments fit into the model.
Before you start
- Backstage is the planner-facing admin console of Onomi. You manage organization, workspace, and content hub roles there. You also manage audience targeting for the app, the attendee-facing surface. See Agency access and strategic meetings management scope for that targeting. Strategic meetings management roles are granted in Onomi 360 instead, in Users and roles, and the same guide describes them.
- Access is layered. Every Backstage user belongs to one or more organizations and holds a role in each. Within an organization, the same user is added to individual workspaces (events) and content hubs, and holds a separate role in each of those.
- To manage access you need the right role at the right layer. Only organization admins can add members to an organization or change organization roles. Only workspace managers can manage a workspace's team. Only content hub managers can manage a content hub's team.
- Email is the unique identifier for users across the platform.
- Enterprise single sign-on is configured together with your SpotMe Account Manager. Have your identity provider (IdP) team available for that setup.
The guides in this series
This article is the overview of the series. The three guides below carry the documentation. Read them in order for the full model, or go straight to the guide your task needs.
- The role model and role registry:
- the platform role model: organization, workspace, content hub, and tailored task roles.
- the role registry at a glance, whose last column states per role what an assignment may write on an event in its scope. That column includes the writes the platform makes on a grant holder's action, such as an award writing the event budget.
- Assigning roles, enterprise sign-in, and provisioning:
- adding people to an organization, a workspace, or a content hub, and changing and removing roles.
- the offboarding order to verify when someone leaves, including the identity-provider layer that closes the meeting request portal for a leaver.
- single sign-on protocols and setup, and what just-in-time provisioning does at first sign-in.
- Agency access and strategic meetings management scope:
- granting an agency scoped access, and targeting content by audience.
- the strategic meetings management roles, and scoped visibility with the scope dimensions.
- how scope and workspace membership meet, with a worked example and the scope verification step at the end.
One rule holds across the series: reaching a record and changing it are separate grants. Which surfaces open at all, and what each assignment may write once a record is open, are both role questions. Every role and grant in this documentation is named in one place: the role registry in The role model and role registry. Where other documentation references a section of this article by name, the guide named above carries that section.
* Onomi 360 MeetingsEQ exclusive capabilities.
Comments
0 comments
Please sign in to leave a comment.