Depending on your organizational needs, create multiple roles, each of which comprises a unique set of permissions.
A role can also be based on the permissions set of another role, eliminating the need to define each permission set separately. This enables you to conveniently create a specialized group of users with the combined permissions of one or more groups or specific permissions.
On the Permissions page, select the Roles tab, then click Create New Role.
In the Name field, enter a name for the role.
In the Description field, enter a brief description of the new role.
(Optional) To use an existing system of defined users, select the LDAP checkbox. The LDAP server must be configured first on the System page. A drop-down list is displayed, listing all LDAP roles detected in the system. Select an LDAP role that matches an existing security group in the Active Directory and configure the permissions this LDAP role should have in the Database Security system.
To use more than one LDAP role, create separate roles for each LDAP security group.
Note
Allow 60 seconds between the first configuration of the LDAP server and the definition of the LDAP roles.
Select the required permissions for the new role from the All Permissions list, then click right arrow icon
to move it to the Selected permissions list.Note
To remove a permission from the Selected permissions list, select the permission, then click the left side arrow icon
.To include the permission set of an existing role in the new role, select the role in the All roles list, then click right arrow icon
to move it to the Selected roles list.Note
To remove a role from the Selected roles list, select the role, then click
.In the View Alert permissions by Rules area, select the rules for which the role is authorized to view alerts.
Click Save.