In this lesson, you will configure Adobe Experience Platform user permissions using Adobe’s Admin Console and the Permissions screen in the Platform interface.
Access control is a key privacy capability in Experience Platform and we recommend limiting permissions to the minimum required for people to perform their job functions. See the Access Control documentation for more information.
Data Architects and Data Engineers are power users of Adobe Experience Platform and you will need many permissions in order to complete this tutorial and later in your day-to-day work. Data Architects are likely be involved in the administration of other Platform users at their company such as marketers, analysts, and data scientists. As you complete this lesson, think about how you might use these features to manage other users at your company.
Data Architects often configure permissions for other users outside of this tutorial.
A System Administrator of Adobe Experience Cloud products must complete some of the steps in this lesson, which is called out in the section headings. If you are not System Administrator, please reach out to one at your company and ask them complete these tasks. There is also a task they need to complete during the Set up Developer Console and Postman lesson.
The Admin Console is the interface used to administer user access to all Adobe Experience Cloud products. For access to Platform, a user or must be added in the Admin Console and then all of their granular permission items are managed in the Permissions screen of Adobe Experience Platform.
Here is a quick summary of the roles that exist for Platform:
AEP-Default-All-Users
product profile (requires a system administrator or product admin)In this exercise, you or a System Administrator or Product Admin will add you as a User and Developer in the Adobe Experience Platform product of the Adobe Admin Console.
If you are a System Administrator assisting a colleague taking this tutorial, consider adding your colleague as a Product Administrator for Adobe Experience Platform. As a Product Administrator, they would be able to complete these steps on their own and administrate other Experience Platform users in the future.
To add the tutorial participant as a User and Developer:
Log into the Adobe Admin Console
Select Products on the top navigation
Select Adobe Experience Platform
You may have several profiles in your Experience Platform instance already. Select the AEP-Default-All-Users
profile
Go to the Users tab
Select the Add User button
Complete the workflow to add the tutorial participant as a user to the product profile
Go to the Developers tab
Select the Add Developer button
Complete the workflow to add the tutorial participant as a developer to the product profile
Granular permissions to Experience Platform are managed in the Permissions screen of the Platform interface. Only System and Product Admins have access to this screen, so if you do not have Admin privileges, you will need assistance from someone who does.
Permissions are managed in Roles. Create a Role for the tutorial:
Log into Adobe Experience Platform
Select Permissions in the left navigation which will take you to the Roles screen
Select Create role
Name the role Luma Tutorial Platform
(add the tutorial participant’s name to the end, if multiple people from your company are taking this tutorial) and select Confirm
Add all of the permission items for the following resources using + and Add all:
Data Modeling
Data Management
Profile Management
Identity Management
Sandbox Administration
Query Service
Data Collection
Data Governance
Dashboards
Alerts
Under Data Ingestion, add the Manage Sources and View Sources permission items.
After adding all of the permission items, be sure to select the Save button
You will make a few small updates to this role after the Create a sandbox and Set up Developer Console and Postman lessons.
In this exercise, you or a System Administrator at your company will create a product profile for Data Collection (formerly known as Adobe Experience Platform Launch) and add you as a product profile admin.
If you are a System Administrator assisting a colleague with this tutorial, consider adding them as a Product Administrator for Data Collection. As a Product Administrator, they will be able to complete these steps on their own and administrate other users of Data Collection in the future.
To create the product profile:
Luma Tutorial Data Collection
(add the tutorial participant’s name to the end, if multiple people from your company are taking this tutorial)After completing these steps, you should see that the Luma Tutorial Data Collection
profile is set up with one admin.
Now that you are an admin of the Luma Tutorial Data Collection
product profile you can configure the permissions and roles you will need to complete the tutorial.
Now you will add the individual permission items to the profile:
Luma Tutorial Data Collection
profileNow add yourself as a user to the Data Collection profile:
You do not need to add yourself as a Developer for Data Collection.
Now you have almost all the permissions required to complete the tutorial! There will be just two more tweaks that you will make inside the Adobe Admin Console, including one after you create a sandbox!