Role-Based Access Control (RBAC), Directory Sync, and Single Sign-On (SAML SSO) are available as add-ons on the Axiom Cloud plan. For more information, see Manage add-ons.
Groups
Groups connect users with roles, making it easier to manage access control at scale. For example, you can create groups for areas of your business like Security, Infrastructure, or Business Analytics, with specific roles assigned to serve the unique needs of these domains. A user’s complete set of capabilities is derived from the additive union of their base role, plus any roles assigned through group membership.Create new group
- Click Settings > Groups
- Click New group.
- Enter the name and description of the group.
- Click Add users to add users to the group.
- Click Add roles to add roles to the group.
Roles
Roles are sets of capabilities that define which actions a user can perform at both the organization and dataset levels.Default roles
The default roles are the following:- Owner: Assigns all capabilities across the entire Axiom platform.
- Admin: Assigns administrative capabilities except for Billing capabilities, which are reserved for Owners.
- User: Assigns standard access for regular users.
- Read-only: Assigns read capabilities for datasets, plus read access on various resources like dashboards, monitors, notifiers, users, queries, saved queries, and virtual fields.
- None: Assigns zero capabilities, useful for adopting the principle of least privilege when inviting new users. You can build up specific capabilities for these users by assigning their role to a group.
Create custom role
- Ensure you have create permission for the access control capability. By default, this capability is assigned to the Owner and Admin roles.
- Click Settings > Roles.
- Click New role.
- Enter the name and description of the role.
- Assign permissions (create, read, update, and delete) across capabilities (access control, API tokens, dashboards, datasets, etc.).
Assign capabilities to roles
You can assign organization-level and dataset-level capabilities to roles. You can assign create, read, update, or delete (CRUD) permissions to most capabilities. Organization-level capabilities define access for various parts of your Axiom organization:- Access control: Full CRUD.
- Annotations: Full CRUD.
- API tokens: Full CRUD.
- Apps: Full CRUD.
- Audit log: Read only.
- Billing: Read and update only.
- Dashboards: Full CRUD.
- Datasets: Full CRUD.
- Endpoints: Full CRUD.
- Monitors: Full CRUD.
- Notifiers: Full CRUD.
- Shared access keys: Read and update only.
- Users: Full CRUD.
- Views: Full CRUD.
Dataset-level capabilities provide fine-grained control over access to datasets. You can assign the following capabilities for all datasets or individual datasets:
- Data: Delete only.
- Ingest: Create only.
- Query: Read only.
- Share: Create, read, and update only.
- Saved queries: Full CRUD.
- Trim: Update only.
- Vacuum: Update only.
- Virtual fields: Full CRUD.
Access to datasets
The datasets that individual users have access to determine the following:- The data they see in dashboards. If a user has access to a dashboard but only to some of the datasets referenced in the dashboard’s elements, the user only sees data from the datasets they have access to.
- The monitors they see. A user only sees the monitors that reference the datasets that the user has access to. If a user has access to the monitors of an organization but only to some of the datasets referenced in the monitors, the user only sees the monitors that reference the datasets they have access to. If a monitor joins several datasets, a user can only see the monitor if the user has access to all of the datasets.
Users
Users in Axiom are the individual accounts that have access to an Axiom organization. You assign a base role to users when you invite them to join your organization. For organizations with the role-based access control (RBAC) add-on, additional roles can be added through group membership.Assign roles to users
- Click Settings > Users.
- Find the user in the list, and then assign a role to them on the right.
Delete users
- Click Settings > Users.
- Find the user in the list, and then click Delete user on the right.
Directory Sync
Directory Sync automatically mirrors user account data between a central directory, such as Active Directory, and connected applications. When the status of an employee changes, all systems are automatically updated. For this feature, Axiom relies on WorkOS. For more information, see Directory Sync and Supported vendors in the WorkOS documentation.Single Sign-On (SAML SSO)
To simplify access management and enhance security, Security Assertion Markup Language-based Single Sign-On (SAML SSO) allows you to keep access grants up-to-date with support for the industry standard SCIM protocol. Axiom supports secure, centralized user authentication through both types of flow for SAML-based SSO:- IdP-initiated flow (identity-provider-initiated flow)
- SP-initiated flow (service-provider-initiated flow)
Two-factor authentication (2FA) is a security feature that requires users to provide two forms of identification before accessing their accounts. You can turn on 2FA for users logging in through SAML SSO and enforce it through your identity provider. Axiom doesn’t offer 2FA natively.
- Axiom provisions an organization for you in WorkOS, connects it to your Axiom organization, and turns on SSO.
- Axiom provides you with a setup link to your WorkOS organization.
-
You follow the instructions using the setup link. The setup requires the following attributes for your users:
idp_idfirst_namelast_nameemail