Configuring User Access to Agent Mesh

Solace Agent Mesh manages access to Agent Mesh instances using role-based access control (RBAC). For general information about RBAC for Agent Mesh, see Enabling Role-Based Access Control (RBAC).

Solace Cloud also has its own user roles that control access to tools and resources, including a user role for Solace Agent Mesh Manager that provides permissions to use Agent Mesh Manager features and view the Agent Mesh details and settings available in Solace Cloud. For more information, see Agent Mesh Manager Roles and Permissions.

When you create an Agent Mesh instance in Solace Cloud, Agent Mesh Manager also creates an RBAC role for the Agent Mesh itself. The Agent Mesh Manager user role in Solace Cloud and the RBAC role for the Agent Mesh instance do not synchronize. Changes made to the RBAC roles in Agent Mesh have no impact on the Agent Mesh Manager user role in Solace Cloud.

If your organization uses single sign-on (SSO) for Solace Cloud, Solace recommends using SSO for your Agent Mesh to enable users with administrator access to Agent Mesh to log in with their existing organizational credentials. If you don't enable SSO for Agent Mesh, users log in to an Agent Mesh instance using the role-based credentials set when the instance was created. For more information, see Enabling SSO for an Agent Mesh Instance.

Agent Mesh Manager Roles and Permissions

The level of access you have to Agent Mesh Manager depends on the role you're assigned in Solace Cloud and the permissions granted to that role. Roles can be assigned directly to users or, if your organization has SSO enabled, to user groups. For more information about assigning user roles, see Managing Users, Groups, Roles, and Permissions.

These roles are specific to the features available in Agent Mesh Manager in Solace Cloud. Permissions to use an Agent Mesh instance, for example to create components and chat with agents, are managed separately for each Agent Mesh instance. For more information, see Enabling Role-Based Access Control (RBAC).

Administrator
Solace Cloud users with the Administrator role have full access to all Solace Cloud capabilities. Administrators can assign users any role in Solace Cloud. In Agent Mesh Manager, Administrators have the same access as users with the Agent Mesh Manager role.
Agent Mesh Manager
Solace Cloud users with the Agent Mesh Manager role have full access to all Agent Mesh instances in Solace Cloud and Agent Mesh Manager capabilities. They can create, edit, delete, and view the configuration of an Agent Mesh instance. They can also enable SSO for Agent Mesh instances.

When you create a new Agent Mesh instance in Agent Mesh Manager, the instance is provisioned with a user role that corresponds to the Solace Cloud Agent Mesh Manager role. You can add more roles or change role permissions for individual Agent Mesh instances; however, these changes have no impact on the roles and permissions in Solace Cloud.

Enabling SSO for an Agent Mesh Instance

If SSO is enabled for Solace Cloud, Solace recommends also using SSO for Agent Mesh so Agent Mesh Managers and other users with administrator access to Agent Mesh can log in with their existing organizational credentials. If you do not enable SSO for Agent Mesh, every user logs in to Agent Mesh with the username and password provided by Solace Cloud. All work and chats are shared between all users sharing the same credentials.

When you enable or disable SSO, the Agent Mesh instance must restart.

To configure SSO for Agent Mesh instances, you must meet these prerequisites:

For more information about using SSO with Agent Mesh, see Enabling Single Sign-On (SSO).

You can also manage SSO settings for all Agent Mesh instances from the Account Details. For more information, see Viewing and Managing SSO Settings for All Agent Mesh Instances.

To enable SSO for an Agent Mesh instance, perform these steps:

  1. Log in to the Solace Cloud Console if you have not done so yet. The URL to access the Cloud Console differs based on your authentication scheme. For more information, see Logging In to the Solace Cloud Console.
  2. On the navigation bar, select Agent Mesh Manager .
  3. At the top-left, select the environment containing the Agent Mesh instance.
  4. Click the name of the Agent Mesh instance you want to view.
  5. Select the Manage tab.
  6. In the Single Sign-On Configuration panel, click Enable.
  7. Click Enable SSO.
  8. Click Copy to copy the Agent Mesh URI to your clipboard so you can add it to your IdP.
  9. Update your IdP settings as required.

The Agent Mesh instance restarts for the change to take effect. Requests to the Agent Mesh instance may be interrupted during restart.

Disabling SSO for an Agent Mesh Instance

Disabling SSO for an Agent Mesh instance in Solace Cloud stops users from logging in to an Agent Mesh instance using SSO. When SSO is disabled, users log in to the Agent Mesh UI using the credentials provided on the Details tab for the Agent Mesh instance. The credentials are visible only when SSO is disabled. For more information, see Viewing Agent Mesh Details.

To disable SSO for an Agent Mesh instance, perform these steps:

  1. On the navigation bar, select Agent Mesh Manager .
  2. At the top-left, select the environment containing the Agent Mesh instance.
  3. Click the name of the Agent Mesh you want to view.
  4. Select the Manage tab.
  5. In the Single Sign-On Configuration panel, click Disable.

The Agent Mesh instance restarts for the change to take effect. Requests to the Agent Mesh instance may be interrupted during restart.

Viewing and Managing SSO Settings for All Agent Mesh Instances

You can view the SSO status for all of your Agent Mesh instances on the Infrastructure SSO Settings tab in your Account Details. To view and manage SSO status for multiple Agent Mesh instances, perform these steps:

  1. On the navigation bar, select User & Account < Account Details.
  2. On the Account Details page, select the Infrastructure SSO Settings tab.
  3. Click Manage Agent Meshes to view SSO details for your Agent Mesh instances.
  4. (Optional) To enable or disable SSO, in the Manage Agent Meshes dialog, select an Agent Mesh instance from the list and click Actions.
    • Select Enable SSO to enable SSO for the selected Agent Mesh instance.
    • Select Disable SSO to disable SSO for the selected Agent Mesh instance.

The list of Agent Mesh instances contains the following information:

Agent Mesh Name
The name of the Agent Mesh.
Agent Mesh SSO Status
The status of SSO configuration for the Agent Mesh instance. The statuses are as follows:
  • Disabled—No SSO configuration is available and SSO has been disabled.
  • Enabled— The SSO configuration was successfully updated and SSO has been enabled. If the URI has been updated on your identity provider, you can use SSO credentials to access the Agent Mesh instance.
  • In Progress—An operation to enable, update, or remove the SSO configuration is in progress.
  • Failed—Enabling, disabling, or updating the SSO configuration failed. A recommendation for an action appears.
Datacenter
The location where the Agent Mesh instance resides, which corresponds to the region name selected when you created the instance.
Callback URI
The URI used by your identity provider (IdP) as a redirect URI. You can copy the redirect URIs to your IdP.