- Introduction
- Access control and administration
- Account management
- Accessing capabilities
- Role-based access control (RBAC)
- Access control for group-based project roles (Automation Cloud)
- Managing projects
- Governance
- Quotas
- Licensing
- Frequently asked questions
Access control considerations for group-based project roles in IXP on Automation Cloud, including data visibility implications for large or regulated groups.
When you assign project roles to groups, the users part of those groups can access any projects the groups are added to. This means the users can view the data within those projects, which might not be appropriate for a large group of users, especially in regulated industries. For more details, check Understanding the data structure and permissions.
Access control for single sign-on (SSO)
As a best practice, when you use single sign-on (SSO), segregate groups at relevant and appropriate access levels. For example, if only a limited set of users should have access to a specific project, create a per-project group to provision access to that project. Otherwise, unauthorized people might access the data.
If strict segregation is required and data must not be shared across teams, consider using a separate Automation Cloud tenant.
Access control for Automation Cloud groups
When using Automation Cloud groups, determine if everyone in the group should have access to the project data. This ensures that you only grant access to the right people and maintain proper data security.
Default Project access and group mappings
IXP does not automatically grant access to all users to the Communications Mining Default Project folder in Manage Access. The access depends on whether the user is part of an Automation Cloud group. Each default Automation Cloud group is mapped to a corresponding permission set in the Default Project, as described in the following table:
| Automation Cloud group | Default Project role |
|---|---|
| Automation Users | IXP Viewer |
| Automation Developers | IXP Developer |
| Administrators | IXP Project Admin |
Administrators can remove or edit these default role assignments in the IXP Administration page, from the Manage Access tab. For the Administrators group, admins can change which IXP roles are assigned, but cannot remove the assignment entirely or leave it with no roles.
Default access for new projects
The Administrators group is automatically added to every new IXP project, both Communications Mining and Unstructured and Complex Documents, and is granted project admin permissions by default.
Consider the following when you plan access for new projects:
- Project admins can remove the Administrators group from a project when the group should not have default access. Members of the group then have to be added to the project individually.
- Existing projects keep their existing role assignments. Add the Administrators group manually to any earlier project that should match the new behavior.
- To disable this default behavior for your organization, submit a UiPath Support ticket.
The default assignment can take up to 2 minutes to propagate. A new project appears on the home page of a group member only after a page refresh.