---
title: "Setting up access control for different Scheduler users"
slug: "setting-up-access-control-for-different-scheduler-users"
updated: 2024-10-17T14:02:30Z
published: 2024-10-17T14:02:30Z
canonical: "support.lusid.com/setting-up-access-control-for-different-scheduler-users"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.lusid.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up access control for different Scheduler users

In this tutorial we'll see how to set up access control for different LUSID users so they can [operate Scheduler](/v1/docs/automatically-upserting-transactions-into-lusid-from-a-csv-file).

The goal is to give them exactly the permissions they need to perform their professional responsibilities, and no more.

> [!NOTE]
> Note
> 
> To complete this tutorial, you must yourself have suitable permissions. This can most easily be achieved by assigning your LUSID user the built-in `lusid-administrator` role. This should already be the case if you are the domain owner.

The users are:

- An *Administrator* who needs to upload images, create jobs and schedule them to run automatically at regular times.
- An *Operator* who just needs to run existing jobs on an *ad hoc* basis and see the results.

This tutorial assumes these users already exist in LUSID. [See how to onboard users](/v1/docs/onboarding-users-into-lusid).

> [!NOTE]
> Note
> 
> Once permissioned, users can interact with Scheduler either via the LUSID web app or by calling the API directly; the access control system makes no distinction between these two workflows.

## Step 1: Understanding access control in LUSID

LUSID's powerful role-based access management system consists of [users](/v1/docs/what-are-a-personal-user-and-a-service-user), [roles](/v1/docs/what-is-a-role), [policies](/v1/docs/what-are-a-policy-and-a-policy-collection) and [policy collections](/v1/docs/how-do-i-create-a-policy-collection). In summary:

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/6ef6dc97-7a44-4462-b70a-9ad7464fee62.png)

Note that an individual policy manages access to *features* and/or *data*:

- A feature policy controls access to [Scheduler API](https://www.lusid.com/docs/api/scheduler/intro) endpoints. This is irrespective of whether a user ultimately interacts with Scheduler via the LUSID web app or by calling the API directly (since the web app itself calls the API).
- A data policy controls access to information about jobs, images and schedules.

To perform any real-world operation in Scheduler, a user must be assigned both types of policy. This is because a data policy without an equivalent feature policy cannot perform operations, and a feature policy without an equivalent data policy yields no data.

For much more on identity and access management (IAM) in the LUSID platform, see our [IAM documentation](/v1/docs/identity-management-and-access-control-iam).

## Step 2: Defining the roles and policies we want to create

For our users, we need the following:

| **User** | **Role** | **Policies** |
| --- | --- | --- |
| Administrator | `scheduler-admin` | `scheduler-features-data-all` |
| Operator | `scheduler-operator` | `scheduler-features-data-jobs-run` |

## Step 3: Creating a policy for the Operator

Let's start with the Operator and the `scheduler-features-data-jobs-run` feature policy.

> [!NOTE]
> Note
> 
> We'll create this policy using the LUSID web app, but it could equally be created by calling the [Access API](https://www.lusid.com/docs/api/access/intro).

The Operator requires access to Scheduler API endpoints that list jobs and run them (features), as well as read-only access to information about jobs (data). They don't need access to API endpoints that create or update jobs, nor upload images, nor manage automation schedules:

1. Sign in to the [LUSID web app](https://www.lusid.com/app/home) using the credentials of a LUSID administrator.
2. From the left-hand menu, select **Identity and access > Policies**: ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(226).png)
3. On the **Policies** dashboard, click the **Create policy** button. ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(227).png)
4. Specify a unique **Code** for the policy:

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(228).png)
5. On the **Features** tab, select the appropriate API endpoints:

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(229).png)

Selecting precisely which API endpoints is subjective, but to enable the Operator to list jobs, run them, and see the results, you might choose: `GetJobConsoleOutput`, `ListJobs`, `RunJob`, `GetHistory`, `GetRunHistory`

> [!NOTE]
> Note
> 
> For the Administrator, it would be reasonable to select *all* API endpoints.

API endpoints are identified in the left-hand column by their *operation ID*. Examine the API reference for more information on the API itself, for example the [GetJobConsoleOutput](https://www.lusid.com/docs/api/scheduler/endpoints/jobs/GetJobConsoleOutput/) API. ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(230).png)
6. Click **Next** to reach the **Data Resources** tab. For the API endpoints, or features, in the policy, you must select appropriate [corresponding data resources in the data policy](/v1/docs/access-control-for-scheduler-resources). In this case, we want just the **Job** resource to prevent the Operator from managing schedules, and the **Read**, **Run** and **GetAllJobHistory** actions to prevent the Operator creating, editing or deleting jobs: ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(231).png)

> [!NOTE]
> Note
> 
> For the Administrator, it would be reasonable to select both **Job** and **Schedule**, and the **Any** action for each.
7. Choose **Identifier** as the **Selector** and specify a **Scope** and **Code** value of `*` to grant access to every job in all LUSID scopes and codes within those scopes. If you wanted, you could restrict access to just the job(s) defined in a particular scope or code:

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(232).png)
8. Create the policy.

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(233).png)

The Operator now has a feature and data policy, ready to assign to their role.

> [!TIP]
> Exercise
> 
> Can you create the policy for the Administrator?

## Step 4: Creating a role for the Operator

Now we need to create a suitable role, since policies are assigned to roles rather than directly to users. A role should represent an aspect of that user's professional responsibilities; you can divide these responsibilities into one or many roles, depending on your needs.

We'll create a single `scheduler-operator` role for this user, encompassing their entire responsibilities:

1. Navigate to the **Roles** dashboard. ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(234).png)
2. Click the **Create role** button (top right).
3. Specify a unique **Code** for the role, and then assign the appropriate policies from the **Policies > Choose** dropdown: ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(235).png)
4. Create the role.

Note that roles have a precedence, so if you do assign two roles to a person and those roles contain conflicting policies, the role with the highest precedence takes effect.

> [!TIP]
> Exercise
> 
> Can you create a role for the Administrator?

## Step 5: Assigning the role to the Operator user

The last step is to assign the `scheduler-operator` role to the LUSID user representing this person. To do this:

1. Navigate to the **Users** dashboard, find the appropriate user row, and click the **Edit** icon: ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(236).png)
2. Click the **Add roles** button to assign the appropriate role to the user: ![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(237).png)

## Helping users get started

The Operator can now interact with the LUSID web app straight away. Tell this person to navigate to your LUSID domain (for example `https://acme.lusid.com/app`) and sign in using their own account credentials.

The Operator should be able to navigate to the **Jobs & Scheduling > Jobs** dashboard, see a list of jobs, and run them. Other operations will not be available:

![](https://cdn.document360.io/d575ad81-c0ed-4980-bbd1-d59ac5c3de82/Images/Documentation/image(238).png)

To interact with Scheduler programmatically:

- Using the [Scheduler REST API](https://www.lusid.com/docs/api/scheduler/intro), tell the Operator to first [follow these instructions](/v1/docs/how-do-i-obtain-and-use-a-short-lived-api-access-token-from-okta) to obtain an API access token. Note the API reference hosts a pre-authenticated sandbox where they can [try out any FINBOURNE API](/v1/docs/getting-started-with-the-lusid-rest-api-and-sdks).
- Using an appropriate version of the [Scheduler SDK](/v1/docs/understanding-all-the-applications-in-the-finbourne-platform), tell the Operator to first [follow these instructions](/v1/docs/how-do-i-use-an-api-access-token-with-the-lusid-sdk) to assemble credentials and authenticate securely.
