- 概要
- はじめに
- 概念
- UiPath CLI を使用する
- 使用ガイド
- CI/CD レシピ
- コマンド リファレンス
- 概要
- 終了コード
- グローバル オプション
- uip codedagent
- UIP コーダー
- UIP のコンテキスト グラウンディング
- uip docsai
- uip 関数
- UIP ガードレール
- uip llm - 構成
- uip llm-gateway
- uip model-hub
- add-test-data-entity
- テスト データのキューを追加
- 追加-テスト-データ-バリエーション
- 分析
- 開発
- プロジェクトを作成
- 差分
- アクティビティを検索
- GET-ANALYZER-RULES
- get-default-activity-xaml
- エラーを取得
- 手動テスト用のテスト ケースを取得
- 手動テストステップを取得
- get-library-object-repository
- オブジェクト リポジトリを取得
- get-versions
- Get-workflow-example
- indicate-application
- 要素を示す
- inspect-package
- install-data-fabric-entities
- パッケージのインストールまたは更新
- list-data-fabric-entities
- リスト - インスタンス
- list-workflow-examples
- パッケージ化
- パブリッシュ
- リモート
- 元に戻す
- 実行、デバッグ、実行
- ファイル名を実行
- 検索テンプレート
- スタートスタジオ
- 実行を停止
- TM
- UIA
- UIP タスク
- uip traces
- UIP トレースのフィードバック
- 移行
- 参照とサポート
uip or roles
「uip or roles」の構文とオプション - Orchestrator RBAC ロール、権限、フォルダー レベルの割り当てを管理します。
uip or roles は Orchestrator の役割と権限 (RBAC) を管理します。ロールは権限をバンドルし、ユーザー、グループ、ロボット、マシン、または外部アプリケーションにテナント レベル (グローバル) レベルまたはフォルダー レベル (スコープあり) で割り当てられます。このページの動詞は、ロールとその権限、ロールとユーザーのメンバーシップ、プリンシパル レベルのロール/権限の検査、フォルダー レベルの割り当てに対応しています。ユーザーごとのテナント レベルのロールの割り当てについては、「uip or usersのusers assign-roles」をご覧ください。
概要
uip or roles permissions list [options]
uip or roles list [options]
uip or roles get <role-key>
uip or roles create --name <name> --type <Tenant|Folder>
uip or roles update <role-key> [--add-permissions <names>] [--remove-permissions <names>]
uip or roles delete <role-key> -y
uip or roles users list <role-key> [options]
uip or roles users set <role-key> [--add-user-keys <keys>] [--remove-user-keys <keys>]
uip or roles user-roles list <principal-name> [--type <type>] [options]
uip or roles user-permissions list <username> [--folder-path <path> | --folder-key <key>]
uip or roles assign --user-key <key> --role-keys <keys> [--folder-path <path> | --folder-key <key>]
uip or roles permissions list [options]
uip or roles list [options]
uip or roles get <role-key>
uip or roles create --name <name> --type <Tenant|Folder>
uip or roles update <role-key> [--add-permissions <names>] [--remove-permissions <names>]
uip or roles delete <role-key> -y
uip or roles users list <role-key> [options]
uip or roles users set <role-key> [--add-user-keys <keys>] [--remove-user-keys <keys>]
uip or roles user-roles list <principal-name> [--type <type>] [options]
uip or roles user-permissions list <username> [--folder-path <path> | --folder-key <key>]
uip or roles assign --user-key <key> --role-keys <keys> [--folder-path <path> | --folder-key <key>]
動詞
| 動詞 | 目的 |
|---|---|
permissions list | 付与可能な権限の名前を一覧表示します。 |
list | テナント内のロールを一覧表示します。 |
get | 付与された権限を持つロールを 1 つ取得します。 |
create | TenantまたはFolderの範囲でロール (権限なし) を作成します。 |
update (エイリアス edit) | ロールの権限を追加または削除します。 |
delete | ユーザーが作成したロールを削除します。 |
users list | ロールに割り当てられたユーザーのリストを取得します。 |
users set | ロールのユーザーを追加または削除します (一括)。 |
user-roles list | テナントおよびすべてのフォルダーにわたってプリンシパル (ユーザー、グループ、ロボット、マシン、または外部アプリ) の完全なロールの割り当てのリストを取得します。 |
user-permissions list | ユーザーの有効な権限 (テナント全体または 1 つのフォルダーへのスコープ) を一覧表示します。 |
assign | 特定のフォルダー内のユーザーにフォルダー レベルのロールを割り当てます。 |
UI またはロールのアクセス許可リスト
付与可能なすべての権限名を一覧表示します。これらの名前は 、 roles update --add-permissionsと一緒に使用してください 。
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
-l | --limit | Number | 50 | ページ サイズ |
| — | --offset | Number | 0 | カウントをスキップします。 |
| — | --sort-by | フィールド | Name asc | OData の並べ替え。 |
例
uip or roles permissions list --limit 200
uip or roles permissions list --output-filter 'Data[].Name'
uip or roles permissions list --output table
uip or roles permissions list --limit 200
uip or roles permissions list --output-filter 'Data[].Name'
uip or roles permissions list --output table
データシェイプ(--output json)
{
"Code": "PermissionList",
"Data": [{ "Name": "Assets.Create" }, { "Name": "Assets.Delete" }]
}
{
"Code": "PermissionList",
"Data": [{ "Name": "Assets.Create" }, { "Name": "Assets.Delete" }]
}
UI またはロールのリスト
ロールのリストを表示します。キー (GUID)、ID、名前、表示名、種類、およびロールが編集可能かどうかを返します。ロール キーを roles get、 roles update、または roles users setとともに使用します。
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
-l | --limit | Number | 50 | ページ サイズ |
| — | --offset | Number | 0 | カウントをスキップします。 |
| — | --sort-by | フィールド | Id desc | OData の並べ替え。 |
例
uip or roles list --limit 50
uip or roles list --output-filter "Data[?Type=='Tenant'].Name"
uip or roles list --output table
uip or roles list --limit 50
uip or roles list --output-filter "Data[?Type=='Tenant'].Name"
uip or roles list --output table
データシェイプ(--output json)
{
"Code": "RoleList",
"Data": [
{
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsEditable": false
}
]
}
{
"Code": "RoleList",
"Data": [
{
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsEditable": false
}
]
}
UIP またはロールは Get
付与された権限を持つロールを取得します。
引数
| 名前 | Required | 目的 |
|---|---|---|
<role-key> | ○ | ロール キー (GUID)。roles listを使用して検索します。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|
例
uip or roles get a1b2c3d4-0000-0000-0000-000000000001
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data.Permissions'
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 --output table
uip or roles get a1b2c3d4-0000-0000-0000-000000000001
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data.Permissions'
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 --output table
データシェイプ(--output json)
{
"Code": "Role",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsStatic": true,
"IsEditable": false,
"Permissions": "Assets.View, Assets.Create, Jobs.View"
}
}
{
"Code": "Role",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsStatic": true,
"IsEditable": false,
"Permissions": "Assets.View, Assets.Create, Jobs.View"
}
}
UIP またはロールで作成する
権限のないロールを作成します。作成後、 roles update --add-permissionsで権限を付与します。
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --name | text | 必須 | ロール名。 |
| — | --type | Tenant | Folder | 必須 | Tenant テナント全体に適用されます。 Folder フォルダー内に適用されます。 |
例
uip or roles create --name "Read Only" --type Tenant
uip or roles create --name "Folder Viewer" --type Folder
uip or roles create --name "Read Only" --type Tenant \
--output-filter 'Data.Key'
uip or roles create --name "Read Only" --type Tenant
uip or roles create --name "Folder Viewer" --type Folder
uip or roles create --name "Read Only" --type Tenant \
--output-filter 'Data.Key'
データシェイプ(--output json)
{
"Code": "RoleCreated",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000010",
"ID": 10,
"Name": "Read Only",
"Type": "Tenant",
"Status": "Created successfully"
}
}
{
"Code": "RoleCreated",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000010",
"ID": 10,
"Name": "Read Only",
"Type": "Tenant",
"Status": "Created successfully"
}
}
UI またはロールの更新
ロールの権限を追加または削除します。現在の権限を読み取り、--add-permissions/--remove-permissions内の名前のisGranted切り替えて保存します。新しい名前 (まだロールに含まれていない名前) は、テナントの完全な権限カタログで検索されて追加されます。
edit はこの動詞の登録済みエイリアスです。 uip or roles edit と同じように機能します uip or roles updateです。
引数
| 名前 | Required | 目的 |
|---|---|---|
<role-key> | ○ | ロール キー (GUID)。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --add-permissions | 名前の CSV | — | 付与する権限。 |
| — | --remove-permissions | 名前の CSV | — | 取り消す権限。 |
--add-permissionsまたは--remove-permissionsのうち少なくとも 1 つが必要です。
例
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View,Jobs.View
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--remove-permissions Jobs.Edit
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View --output-filter 'Data.Status'
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View,Jobs.View
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--remove-permissions Jobs.Edit
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View --output-filter 'Data.Status'
データシェイプ(--output json)
{
"Code": "RoleUpdated",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Updated successfully" }
}
{
"Code": "RoleUpdated",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Updated successfully" }
}
UIP またはロールの削除
ユーザーが作成したロールを削除します。組み込みロール ( IsStatic=true) は削除できません。
引数
| 名前 | Required | 目的 |
|---|---|---|
<role-key> | ○ | ロール キー (GUID)。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
-y | --yes | フラグ | — | 必須。この元に戻せない操作を確認します。CLI はプロンプトを表示しません。 |
例
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes \
--output-filter 'Data.Status'
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes \
--output-filter 'Data.Status'
データシェイプ(--output json)
{
"Code": "RoleDeleted",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Deleted successfully" }
}
{
"Code": "RoleDeleted",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Deleted successfully" }
}
UI またはロールのユーザー リスト
ロールに割り当てられたユーザーのリストを取得します。
引数
| 名前 | Required | 目的 |
|---|---|---|
<role-key> | ○ | ロール キー (GUID)。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
-l | --limit | Number | 50 | ページ サイズ |
| — | --offset | Number | 0 | カウントをスキップします。 |
例
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 --limit 200
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data[].UserName'
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 --limit 200
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data[].UserName'
データシェイプ(--output json)
{
"Code": "RoleUserList",
"Data": [
{
"Key": "d4e5f6a7-0000-0000-0000-000000000001",
"ID": 101,
"UserName": "admin@example.com",
"FullName": "Admin User",
"Type": "User"
}
]
}
{
"Code": "RoleUserList",
"Data": [
{
"Key": "d4e5f6a7-0000-0000-0000-000000000001",
"ID": 101,
"UserName": "admin@example.com",
"FullName": "Admin User",
"Type": "User"
}
]
}
ユーザーが設定する UIP またはロール
ロールのユーザーの追加または削除 (一括)。--add-user-keys、--remove-user-keys、またはその両方を指定します。少なくとも 1 つは必須です。加算/減算のみ — どちらのフラグにも名前が付けられていない既存のメンバーシップはそのまま残ります (完全なリストを置き換える users assign-rolesとは異なります)。
引数
| 名前 | Required | 目的 |
|---|---|---|
<role-key> | ○ | ロール キー (GUID)。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --add-user-keys | GUID の CSV | — | 追加するユーザー。 |
| — | --remove-user-keys | GUID の CSV | — | 削除するユーザー。 |
例
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-0000-0000-0000-000000000001
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001,d4e5f6a7-…-002 \
--remove-user-keys d4e5f6a7-…-099
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001 --output-filter 'Data.Added'
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-0000-0000-0000-000000000001
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001,d4e5f6a7-…-002 \
--remove-user-keys d4e5f6a7-…-099
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001 --output-filter 'Data.Added'
データシェイプ(--output json)
{
"Code": "RoleUsersUpdated",
"Data": {
"RoleKey": "a1b2c3d4-0000-0000-0000-000000000010",
"Added": 1,
"Removed": 0,
"Status": "Updated successfully"
}
}
{
"Code": "RoleUsersUpdated",
"Data": {
"RoleKey": "a1b2c3d4-0000-0000-0000-000000000010",
"Added": 1,
"Removed": 0,
"Status": "Updated successfully"
}
}
UI またはロール user-roles list
テナントおよびすべてのフォルダーにわたって、プリンシパル (ユーザー、ディレクトリ グループ、ディレクトリ ロボット、マシン、外部アプリケーション) に割り当てられたすべてのロールを一覧表示します。プリンシパルのフル アクセス プロファイルを監査するのに役立ちます。
引数
| 名前 | Required | 目的 |
|---|---|---|
<principal-name> | ○ | 検索するユーザー名、グループ名、ロボット名、マシン名、または外部アプリ名。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --type | User | Group | Robot | Machine | ExternalApplication | User | プリンシパルの種類。DirectoryUser/DirectoryGroup/DirectoryRobot/DirectoryExternalApplication のスペルもエイリアスとして受け入れられます。 |
-l | --limit | Number | 50 | ページ サイズ |
| — | --offset | Number | 0 | カウントをスキップします。 |
例
uip or roles user-roles list admin@example.com
uip or roles user-roles list "MRS Developers" --type Group
uip or roles user-roles list admin@example.com \
--output-filter "Data[?Scope=='Folder']"
uip or roles user-roles list admin@example.com
uip or roles user-roles list "MRS Developers" --type Group
uip or roles user-roles list admin@example.com \
--output-filter "Data[?Scope=='Folder']"
データシェイプ(--output json)
{
"Code": "UserRoleList",
"Data": [
{ "Scope": "Tenant", "FolderPath": "", "Role": "Administrator" },
{ "Scope": "Folder", "FolderPath": "Shared", "Role": "Folder Administrator" }
]
}
{
"Code": "UserRoleList",
"Data": [
{ "Scope": "Tenant", "FolderPath": "", "Role": "Administrator" },
{ "Scope": "Folder", "FolderPath": "Shared", "Role": "Folder Administrator" }
]
}
UIP またはロール user-permissions list
ユーザーの有効な権限のリストを表示します。フォルダー オプションなし: テナント レベルのロールと権限が表示されます。 --folder-path/--folder-keyを使用すると、代わりにその特定のフォルダーで付与されているロールと権限が表示されます。一致するすべてのロールによって付与された権限の重複排除済みの和集合を返します。
引数
| 名前 | Required | 目的 |
|---|---|---|
<username> | ○ | 検索するユーザー名です。 |
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --folder-path | パス | — | このフォルダーに対する権限を、テナント レベルではなくフォルダー レベルの権限を表示します。 |
| — | --folder-key | GUID | — | --folder-pathの代替フォルダーです。 |
例
uip or roles user-permissions list admin@example.com
uip or roles user-permissions list admin@example.com --folder-path "Shared"
uip or roles user-permissions list admin@example.com
uip or roles user-permissions list admin@example.com --folder-path "Shared"
データシェイプ(--output json)
テナント レベル
{
"Code": "UserPermissionList",
"Data": {
"Roles": ["Administrator"],
"Permissions": ["Jobs.View", "Assets.Create"]
}
}
{
"Code": "UserPermissionList",
"Data": {
"Roles": ["Administrator"],
"Permissions": ["Jobs.View", "Assets.Create"]
}
}
フォルダー範囲:
{
"Code": "UserPermissionList",
"Data": {
"FolderPath": "Shared",
"Roles": ["Folder User"],
"Permissions": ["Jobs.View", "Assets.View"]
}
}
{
"Code": "UserPermissionList",
"Data": {
"FolderPath": "Shared",
"Roles": ["Folder User"],
"Permissions": ["Jobs.View", "Assets.View"]
}
}
uip or roles assign
フォルダー レベルのロールをユーザーに割り当てる。フォルダーの種類のロールのみを使用します。--folder-path または --folder-keyが必要です。
注意 — 役割に破壊的です。サーバーは、ターゲット フォルダーのユーザーのフォルダー レベルのロール リスト 全体 を、 --role-keysを介して渡されたキーに置き換えます。ペイロードにないロールは通知なしに削除されます。既存のフォルダー ロールを保持するには、最初にフォルダー ロールを roles user-roles list <principal-name> --type <type> で読み取り、目的の完全な和集合を --role-keysに渡します。ロールに追加のテナント レベルのロール メンバーシップがある場合は、代わりに roles users set を使用します。
オプション
| Short | 長押し | 値 (Value) | 既定 (Default) | 説明 |
|---|---|---|---|---|
| — | --user-key | GUID | 必須 | ユーザー キー |
| — | --role-keys | GUID の CSV | 必須 | フォルダー内で割り当てるロール GUID。 |
| — | --folder-path | パス | — | ターゲット フォルダー。これまたは --folder-keyを指定します。 |
| — | --folder-key | GUID | — | ターゲット フォルダー。 |
例
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared"
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-…-002,a1b2c3d4-…-003 \
--folder-key b1c2d3e4-0000-0000-0000-000000000001
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared" --output-filter 'Data.Status'
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared"
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-…-002,a1b2c3d4-…-003 \
--folder-key b1c2d3e4-0000-0000-0000-000000000001
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared" --output-filter 'Data.Status'
データシェイプ(--output json)
{
"Code": "PermissionsAssigned",
"Data": {
"UserKey": "d4e5f6a7-0000-0000-0000-000000000001",
"FolderPath": "Shared",
"Status": "Assigned successfully"
}
}
{
"Code": "PermissionsAssigned",
"Data": {
"UserKey": "d4e5f6a7-0000-0000-0000-000000000001",
"FolderPath": "Shared",
"Status": "Assigned successfully"
}
}
終了コード
「終了コード」を参照してください。動詞固有の上書きはありません。
関連コマンド
uip or users— ユーザーキーの検索テナント レベルのロールの割り当ての場合はusers assign-roles。uip or folders—roles assignのフォルダー キーを見つけます。
参照
- 概要
- 動詞
- UI またはロールのアクセス許可リスト
- オプション
- 例
- データシェイプ(--output json)
- UI またはロールのリスト
- オプション
- 例
- データシェイプ(--output json)
- UIP またはロールは Get
- 引数
- オプション
- 例
- データシェイプ(--output json)
- UIP またはロールで作成する
- オプション
- 例
- データシェイプ(--output json)
- UI またはロールの更新
- 引数
- オプション
- 例
- データシェイプ(--output json)
- UIP またはロールの削除
- 引数
- オプション
- 例
- データシェイプ(--output json)
- UI またはロールのユーザー リスト
- 引数
- オプション
- 例
- データシェイプ(--output json)
- ユーザーが設定する UIP またはロール
- 引数
- オプション
- 例
- データシェイプ(--output json)
- UI またはロール user-roles list
- 引数
- オプション
- 例
- データシェイプ(--output json)
- UIP またはロール user-permissions list
- 引数
- オプション
- 例
- データシェイプ(--output json)
- uip or roles assign
- オプション
- 例
- データシェイプ(--output json)
- 終了コード
- 関連コマンド
- 参照