Skip to content

Commit

Permalink
udpate description of data admins
Browse files Browse the repository at this point in the history
  • Loading branch information
craddm committed Jan 23, 2024
1 parent 2668485 commit b6321cd
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions docs/source/roles/system_manager/manage_users.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,10 +17,10 @@ A helper script for doing this is already uploaded to the domain controller - yo

### {{lock}} SRE Security Groups

Each user should be assigned to one or more Active Directory "security groups", which give them access to a given SRE with appropriate privileges. The security groups are named like so:
Each user should be assigned to one or more Active Directory "security groups", which give them access to a given SRE with appropriate privileges:

- `SG <SRE ID> Research Users`: Default for most researchers. No special permissions.
- `SG <SRE ID> Data Administrators`: Researchers who can create/modify/delete database tables schemas. Given to a smaller number of researchers. Restricting this access to most users prevents them creating/deleting arbitrary schemas, which is important because some SREs have their input data in database form.
- `SG <SRE ID> Data Administrators`: Researchers who can create/modify/delete tables in the `data` schema on a `PostgreSQL` within `<SRE ID>``. Users outside this group can only read these tables. Restricting this access to most users prevents them creating/deleting arbitrary schemas, which is important because some SREs have their input data in database form.

(generate_user_csv)=

Expand Down

0 comments on commit b6321cd

Please sign in to comment.