Managing Event Data Access

Applications may be designed to publish and subscribe to events that contain sensitive information such as customer data. By managing event data access you can:

  • Govern the ability of applications to publish and consume events by requiring applications to get approval to publish or consume specific events.
  • Manage who has permissions to review event access requests at the application domain level.

If an application is designed to publish or consume a shared event that it does not have approval for, it must get approval to access the event when all of these conditions are true:

  • The event's Access Approval option is set to Requires Approval.
  • The application and the event that requires approval are located in different application domains.
  • The application publishes the event that requires approval or the application attracts the event through a consumer with an appropriate subscription.

This section includes the following tasks:

You can also create an approval process for users with the Event Portal User role who promote applications to environments in Event Portal. For more information, see Promoting Applications to Environments.

Event Access Approval Workflow

The following steps describe the workflow for managing event access, from creating an event that requires approval to approving or declining event data access requests.

  1. A user creates an event that includes sensitive information and specifies that access to the event data requires approval. For more information, see Creating an Event.
  2. When another user adding or editing an application in a different application domain publishes or adds a subscription to a consumer for an event that requires approval, a banner appears in the application to inform them of the access requirement. For more information, see Creating Applications.
  3. The user creating or updating the application sends access requests for the referenced events that require approval. For more information, see Requesting Event Access.
  4. The access request is added to the Event Access Requests page in the event's application domain where users with permission to approve event access requests in the event's application domain can review it. All Event Portal Users with Event Access Approver access for the application domain receive a notification by default. For more information, see Enabling Users to Approve Event Access Requests.
  5. The reviewer approves or declines the requests. For more information, see Reviewing Event Access Requests.
  6. The user who sent the requests receives notification of the decision.
  7. If access to all the referenced events is approved, the application can be added to an environment.

Watch this demo video of the workflow:

Video illustrating the features described in the preceding text.

Enabling Users to Approve Event Access Requests

Administrators, Event Portal Managers, and Event Portal Users with Application Domain Manager access to an application domain can give users with the Event Portal User role permission to approve and decline event access requests in an application domain.

Only users with Event Access Approver access in an application domain receive notifications about new access requests. Administrators and Event Portal Managers do not receive notifications.

Users with Application Domain Manager and Application Domain Editor access do not have permissions to view or approve event access requests; however, Application Domain Managers and Editors can also be given Event Access Approver access. Application Domain Managers can give Event Access Approver access to themselves.

To give a user permission to approve and decline event access requests, perform these steps:

  1. Log in to the Solace Cloud Console if you have not done so yet. The URL to access the Cloud Console differs based on your authentication scheme. For more information, see Logging In to the Solace Cloud Console.
  2. On the navigation bar, select Designer .
  3. On the Application Domain page, click More Actions for the application domain you want to give the user access to and then select Set User Access.
  4. In the User Access dialog select the Approval Access tab.
  5. Perform one of the following actions:
    • If your organization doesn't have user groups enabled, click Add User.
    • If your organization has user groups enabled, click Add and select either Add User Group or Add User.
    Screenshot showing the elements described in the surrounding text.
  6. In the Name list, type or select the name of the user or user group you want to give Event Access Approver access to. Only users and user groups with the Event Portal User role who do not already have Event Access Approver access to the application domain appear in the list.
  7. To remove access, click Remove in the row for the user or user group.
  8. Click Save.
  9. Repeat steps 3-8 to give event access approver role to another user or user group.

The user or user group now has the event access approver role and can Reviewing Event Access Requests.

For more information about Event Portal user access in application domains, see Managing User Access to Event Portal.

Requesting Event Access

If an application publishes or consumes an event in another application domain that requires approval, a request to access the event must be sent from the application, and be approved by an Event Access Approver before the application can be added to an environment.

An event access request banner shows above the application details when the application needs approval to use one or more events. Event Portal displays the banner after you declare that you want to publish an event or you set a topic subscription in a consumer that attracts an event that requires approval.

To request event access in an application, perform these steps:

  1. In Designer, on the Application Domains page, click the application domain containing the application that references the event requiring approval.
  2. To open the application details page, do one of the following:
    • Click Components to switch to the component view, and select the application you want to request event access for from the list.
    • Click the icon for the application you want to request event access for in the graph view. In the panel that opens click Open Application.
  3. In the Request Event Access banner click Manage Requests.
  4. (Optional) Click an event to expand the section and write a comment to be included with the request for that event.
  5. Click Send Requests to send the access requests for all the listed events to appropriate application domains.
  6. After the requests have been sent, click the Pending Requests tab at the top of the page to view the pending requests.

When an Event Access Approver makes a decision for an event, declined requests return to the Action Required tab with any message the Event Access Approver has added. Approved requests are counted in the Pending Requests tab.

Reviewing Event Access Requests

If you have the Administrator or Event Portal Manager role, or Event Access Approver access for an application domain, you can approve, decline, or revoke previously approved event access requests from the Event Access Requests page. Revoking access changes the request from approved to declined but does not make any changes to operational event brokers that the application has already been deployed to.

To manage event access requests, perform these steps:

  1. In Designer, on the Application Domains page, click More Actions in the top right corner of the page and select Event Access Requests. This option does not appear to users without an appropriate role.
  2. Click the Awaiting Review tab.
  3. Select the request that you want to review and then click Review in the information panel. If you need to filter the list to find a request, you can:
    • Start typing the name of the event in the Filter by Event Name field.
    • Click Filter to narrow your search results to the name of the user who made the request.
  4. In the Review Event Access Request dialog select Approve or Decline.
  5. (Optional) If you decline the request, add a message for the requestor.
  6. Click Send Review.
  7. If you want to view the event access requests that you have made a decision on, select the Closed Requests tab and then select the request you want to view.
  8. If you want to approve a previously declined event access request, click Approve in the dialog that opens. Likewise, if you want to revoke the access of a previously approved event access request, click Revoke Access.

Event Access Notifications

By default users requesting event access for an application are notified in both the Cloud Console and by email when the approval status of a request changes.

Users with Event Access Approver access in an application domain receive notifications in both the Cloud Console and by email when a new event access request is created in the application domain.

For information about managing your notification settings, see System Notifications.