Managing application access through Personas
2 Tasks
30 mins
Scenario
U+ Hotels needs to restrict access to sensitive complaint workflows within the Travel Management Customer Support (TMCS) application. The Complaint Resolution Case Type contains investigation and resolution data that should only be accessible to authorized service roles. Property Managers using the TMCS application should not be able to view, modify, or run reports on complaint Cases. U+ Hotels also wants users to collaborate within the application via Pulse messaging, so team members can communicate and share updates in the context of a Case.
To meet this requirement, U+ Hotels has decided to enforce security using Access Groups and role-based access control (RBAC).
As a Solution Builder, you are responsible for updating the appropriate Access Group and role configuration to restrict access to the Complaint Resolution Case Type. You also use Pulse to collaborate with other users within a Partner Onboarding Case.
The following table provides the credentials you may need to complete the challenge:
| Role | User name | Password |
|---|---|---|
| Solution Builder | [email protected] | pega123! |
| Property Manager | [email protected] | pega123! |
After completing this challenge, you should be able to:
- Use Access Groups to control user permissions in a Pega application.
- Update role permissions within an Access Group.
- Apply role-based access control (RBAC) to prevent users from accessing restricted Case Types.
- Use Pulse to collaborate with other users within the context of a Case.
Detailed Tasks
1 Restrict Complaint Resolution access by using Access Groups
Use the technical documentation linked in the doc journey above to complete the assigned tasks. The technical documentation might have more information than you need to complete the tasks.
Acceptance criteria
- The
TMCS:PropertyManagerAccess Group includes theTMCS:PropertyManagerManagedrole. - The
TMCS:PropertyManagerManagedrole does not have the following permissions on the Complaint Resolution Case Type: Read, Write, Delete, and Execute Reports. - Users assigned to the
TMCS:PropertyManagerAccess Group:- Cannot open Complaint Resolution Cases.
- Cannot create or update complaint Cases.
- Cannot run reports or view audit history for Complaint Resolution.
Directions
- Open the
TMCS:PropertyManagerAccess Group. - Verify that the
TMCS:PropertyManagerManagedrole is associated with this Access Group. - Open the
TMCS:PropertyManagerManagedrole. - Remove the Read, Write, Delete, and Execute Reports permissions for the Complaint Resolution Case Type.
- Save your changes.
2 Send a Pulse message in a Partner Onboarding Case
Use the technical documentation linked in the doc journey above to complete the assigned tasks. The technical documentation might have more information than you need to complete the tasks.
Acceptance criteria
- In a Partner Onboarding Case, a Pulse message is created successfully.
- The message tags @PropertyManager.
- The message is posted and visible in the Pulse feed.
- The tagged user is notified of the message.
Directions
- Open a Partner Onboarding Case in the TMCS application.
- Launch Work Portal in TCMS application and create a Partner Onboarding Case
- On the Pulse tab, enter @PropertyManager.
- Select the @PropertyManager account from the list.
- Enter a message and Post.
- Login with Property Manager credentials and Verify the Received Notification.
Available in the following mission:
Want to help us improve this content?