User States and Actions



Platform Administrator (Root)

Represents the enterprise or organization that hosts CloudCenter and has special administrative permissions and access to all CloudCenter functions, and is responsible for setting up clouds, initial cloud accounts, creating users, and adding tenants.

Platform administrators can:

  • Configure and register clouds and cloud accounts in CloudCenter
  • Create tenants and sub-tenants  
  • Promote to Sub-Tenant Owner or a Co-Administrator
  • Manage user, cloud, and tenant permissions

Tenant Administrator

CloudCenter's multi-tenancy model refers to tenant-level isolation of functions that are accessible to a specific set of Users and Groups .

A separate administrator, called the tenant administrator, governs each tenant. At the tenant level, the tenant administrator can create tenant users and user groups. Tenants get complete independence in managing users and user groups within the tenant. An example of organizations with tenants is a business unit that requires isolation from its parent to customize workflows, clouds, UIs, applications, governance models, and so forth.

If permitted by the platform admin, tenant administrators can perform the following tasks:

  • Install CCOs for private clouds
  • Create sub-tenants
  • Enable a subset of Public Clouds regions for a tenant user or sub‐tenant
  • Setup Cloud Accounts and cloud authentication credentials to provision resources on enabled clouds
  • Configure enabled accounts to be shared with tenant users or and sub‐tenants
  • Manage tenant-level application profiles   
  • Promote to Sub-Tenant Owner or a Co-Administrator


People who use the CloudCenter platform to create application profiles, deploy applications, or manage applications using the UI, API, or CLI. Users are also referred to as standard users (see Standard Users).

Resource Owner
End UsersPeople who use the application after it is onboarded and deployed.

System Administrator

The CloudCenter platform's infrastructure system administrator (SysAdmin) is responsible for installing and managing the CloudCenter platform. This user is independent of other CloudCenter users and accounts.

A CloudCenter SysAdmin has separate credentials (Log in as a System Admin) and performs the following tasks:

  • Configure a tenant to use SSO

To obtain the initial credentials for your CloudCenter SysAdmin account, contact CloudCenter Support.

GroupsEach user can be assigned to none, one, or more than one group. 


A role is a collection of global permissions that specifically relate to CloudCenter functions. Roles control user privileges and permissions to CloudCenter functions (for example, the ability to create Application Profiles, add a cloud account, and so forth).

Roles only apply to users and groups  within one tenant. They do not apply to sub-tenant and sub-tenant users.

PermissionsCloudCenter provides additional granularity in user objects and resource sharing permissions within CloudCenter (for example, the ability to view a specific Deployment Environments, the ability to share a specific Application Profile with other users or user groups, and so forth). See Permission Control.

User Administration

The Users page (CCM UI > Admin > Users) lists the available Actions for each user.

CloudCenter Users

You can see three types of users in the Users page:

See the Permission Control page for assigning resource permissions to users.

Possible User States

You an see three possible states for each user in the Users page:

  • New:

    • Must be activated and enabled to be considered Standard Users

    • Tenant owners can never be in this state.

  • Enabled:

    • Depending on the Permission, this user can perform numerous tasks.

    • Enabled users can perform Standard User or Admin User tasks based on the configured user actions

  • Disabled:

Possible User Actions for Each State

A user's current state and profile determine the options listed in the Actions dropdown. The following table describes the user types and actions.


User Type and Actions

User Is
Not Activated

User Is Activated

Standard (User)

Admin (Promoted)

Owner (Tenant)


Activate User

Delete User

Enable User

Delete User

Not applicable


Not Applicable

Possible Actions

Add Cloud

Manage API Key

Reset Password

User Key Operations

Assign Bundles

Import from Marketplace

Additional User Actions

 Promote to Admin

Promote to Sub-Tenant Owner 

Disable User

Assign Bundles 

Assign Usage Plan

Additional Admin Actions

 Convert to Standard User  

Assign Usage Plan

Not applicable


Enable User

Delete User

Not applicable
  • No labels
Terms & Conditions Privacy Statement Cookies Trademarks