OSS ยท IM System Service Fulfillment โ€“ Inventory Management

Permission Tiers

IM implements three distinct levels of access control. All permissions are assigned to roles, and roles are assigned to users.

1. Menu Permission

Controls which menus an operator can see in the navigation. Permissions exist at both parent-menu and child-menu levels independently.

Resource Management menu (parent)ONT sub-menu (child)Log Management menuSystem Management menu
2. Button Permission

Controls which action buttons are visible and usable within a module.

Create / Add buttonModify buttonDelete buttonImport buttonExport buttonClone buttonRole AuthorizationBatch User Authorization
3. Input Parameter Permission

Fine-grained control over which query/filter fields an operator can use. Each input field can be independently permitted or restricted.

Zone Name filter in WO MgmtSector filter in Resource MgmtIP Address filterCustomer email query

Decryption Permissions

Three fields are always stored encrypted. To view their real values, operators need a specific per-field decryption permission:

Mobile Number

Email Address

IPTV Password

Permission Matrix by Module

Module Menu Buttons Input Fields Decrypt
โœ“ User Management Create, Modify, Delete โ€“ โœ“
โœ“ Organization Management Create, Modify, Delete โ€“ โœ“
โœ“ Role Management Create, Modify, Delete, Role Auth, Batch User Auth โ€“ โœ“
โœ“ Resource Management Create, Modify, Delete โ€“ โœ“
โœ“ WO Management (query only) โ€“ โœ“
โœ“ Customer (Service Mgmt) Create, Modify, Delete โœ“ โœ“
โœ“ Customer Service (Service Mgmt) Create, Modify, Delete โœ“ โœ“
โœ“ Log Management (query only) โ€“ โœ“

Role Design Guidelines

๐Ÿ’ก

Design roles by job function

  • IT Administrator: Full access including Add/Modify/Delete on all resources
  • NOC Operator (Level 1): Query-only access to WO and Service Mgmt, no resource modification
  • NOC Operator (Level 2): Query + export, limited modification, no delete
  • Supervisor: Full query + decrypt permissions, view-only on system mgmt
  • System Admin: Full access to User/Role/Org management only