Skip to main content

Access control and audit

Lesson 11 of 11 · 2 min 5 s. Episode 11 of the Jaah tutorial series: make sure everyone sees what they should, and answer the auditor. Give a group access to one more project, see everything one person reaches and through which group, check whether they may do one thing and why, find who made a change and when, and find the record of what an agent did in its session.

Before you start​

  • A group that needs access to a project. In the video, TimeSaver (a time-tracking app for small teams) gives its TimeSaver reviewers group access to the TimeSaver app.
  • A person under People whose access you want to read.

Steps​

  1. Open Directory and go to the Groups tab. Access in Jaah is given to groups, not to one person at a time. Each group says who belongs together and what they're for.
  2. Open the group and go to Bindings. Each line is where the group has access, and the role it has there. Press Add, choose Project as the type, pick the project, and set the role to Project Viewer, so they can see its work without starting any. Press Add once more, and the new line appears.
  3. To see access from one person's side, open them under People and go to Access. It lists every group they're in, then everything they can reach: the organization, each project and each model account. Each line shows the role they hold there and the group it comes through.
  4. For a single question, go to Check access. Choose Project, pick the project, choose the action, like Edit tasks, and press Check. The answer says whether they're allowed, and why: the group, the role, and where the role comes from.
  5. When the auditor asks who changed what, open Audit in the sidebar. It records everything done in the console. Press Write to keep only the changes. Each entry says what was done, by whom and when, and a task's entries say how its work moved along.
  6. For work done by agents, go to the Sessions tab. Each line is one agent session: the task it worked on, the machine, how long it ran, and its transcript, kept as the record of every step the agent took.

What you learned​

  • Access is given to groups. A group's Bindings say where it has access and with which role.
  • A person's Access tab lists everything they can reach and through which group; Check access answers one question and says why.
  • Audit records who did what and when; Write keeps only the changes.
  • Sessions holds every agent session, its task and machine, and its transcript.

Next​

This is the last lesson. Previous: Nodes and capacity. All tutorials.

Related: How team and access work · Check what someone can access · Audit