Skip to main content

The console: layout and roles

For every administrator of the Organisations console, and anyone deciding what access to give a colleague.

Before you start: the console lives at the hostname chosen at install; once single sign-on is connected, password sign-in is off for everyone (see Sign in with Entra ID).

Sign in​

While your session resolves the page reads "Signing you in…". A failure reads Could not sign you in with a Technical details disclosure; retrying reloads the page. If your single sign-on session runs out mid-work, the overlay Your session has expired offers Sign in again.

Find your way around​

The dock at the bottom of the screen has six entries:

Dock entryOpens
HomeYour fleet summary.
FleetEvery deployment (Fleet).
AccountsThe AWS accounts you deploy into (Accounts).
LibrariesShared resource stores (Libraries).
Identity & Access ManagementAdmins if you can manage administrators, otherwise Policies.
DocumentationThis site, in a new tab.

The sidebar groups every screen: Fleet Management (Fleet, Fleet Configurations, Update Manager), Account Management (Accounts), Identity & Access Management (Admins, Identity Providers, Roles, Policies, Users, Groups, Programmatic Access, Audit) and Library Management (Libraries). Its footer shows your email and Sign out.

An entry you may not open is disabled and its hover names what it requires: Admins, owner or operator; Roles, owner or operator or an AccessAdministrator grant; Users and Groups, the IdentityProviderManager role; Programmatic Access, a Programmatic Access role; Audit, an AdminManage-class grant.

Read Home​

Home shows a Total deployments tile and one tile per health state present: Provisioning, Awaiting input, Healthy, Degraded, Failed, Deleting, Disabled, Uninstalled. View all deployments → opens the Fleet. If you may view accounts and one is unverified or failed verification, Accounts needing verification lists it as "not yet verified" or "verification failed".

Reload when the console is updated​

When a newer console is published while you are signed in, a banner offers Reload; the console reloads itself only when you are not watching a deployment's progress. Navigating away from a running deployment shows the dialog Deployment in progress: the job keeps running in the background.

Understand the role model​

Access is granted two ways, both from Users, groups and roles:

  1. Three organisation-wide tiers. Owner and Operator: every administrative action in this guide, including granting or revoking Roles and tiers; the one difference the console enforces is that the last remaining Owner cannot be revoked. Viewer: read-only access across the organisation.
  2. Built-in Roles, granted organisation-wide or on one resource: LibraryViewer, LibraryContributor, LibraryManager, FleetViewer, FleetOperator, DeploymentOperator, AccountManager, AccountViewer, IdentityProviderManager, IdentityProviderViewer, AccessAdministrator, StudioUser, ProgrammaticAccessAdministrator and ProgrammaticAccessViewer. StudioUser is the one Role that is not about the console: it lets a person sign in to a Studio deployment.

Viewers can read the Fleet, deployment detail, Accounts, Identity Providers, Libraries, deployment drafts and API keys. Everything else needs the Owner or Operator tier or the matching Role: creating, pausing, resuming, upgrading, reconfiguring, rolling back or uninstalling a deployment and retrying, resuming or abandoning its jobs; registering, verifying, clearing or deleting an AWS account; connecting or deleting an identity provider, linking it to a deployment, assigning people and browsing the directory; creating Libraries, managing members and pushing items; Fleet Configurations and Update Manager rules; per-user token attribution; Admins, Roles, grants and the shared Entra credentials; API keys; Audit.

The server checks every action on each request. A disabled button carries the reason as hover text; a refused request, or a list you may not read, shows "You don't have permission to <do this>. An owner or operator can grant you access in Identity & Access Management."

What you should see​

A person who can sign in but holds no role sees Home as You have access to nothing yet: "Ask an administrator to grant you a role in Identity & Access Management." Only entries that need no permission, such as Policies, open for them.

Notes​

  • Signing in with no role is not refused; you get the zero-access Home until an Owner or Operator grants you a Role or a tier.
  • Old bookmarks to a Settings screen open the Fleet. The shared Entra application credentials moved to Identity Providers as Platform setup; release choice is the deployment wizard's Release version step.
  • Policies is readable by anyone who can sign in; what a Role does cannot be changed from the console.
  • Repeated sign-in failures: your identity administrator has not assigned you to the console's Enterprise Application in Microsoft Entra.
  • The console refuses to revoke the last remaining Owner; grant another Owner first.