在此页面上:熟悉Journey Optimizer中的核心访问控制概念,包括角色、权限、沙盒以及基于对象和属性的访问控制,因此您可以规划如何授予用户正确的访问权限。
Journey Optimizer允许您定义和管理分配给不同用户的权限。 权限是授权或拒绝访问产品内特性和功能的一组权限和限制。
Journey Optimizer的访问控制是通过Adobe CX Enterprise中的 权限 提供的。 此功能利用角色和策略,将用户与权限和沙盒关联起来。
要配置Journey Optimizer的访问控制,您必须拥有组织的系统或产品管理员权限。 可以授予或撤销权限的最低角色是产品管理员。 可以管理权限的其他管理员角色是系统管理员(无限制)。 有关详细信息,请参阅有关管理角色的Adobe帮助中心文章。
Journey Optimizer中的用户管理基于以下关键概念:
-
角色:角色是指共享相同权限和沙盒的用户集合。 利用这些角色,可轻松管理组织中不同用户组的访问和权限。 角色附带一组统一权限(权限),允许用户访问界面中的特定功能或对象。
通过Journey Optimizer,您可以从预先存在的 角色 范围中进行选择,每个角色都具有各种级别的权限,以便分配给您的用户。 详细了解此页面上可用的内置角色。 -
权限:权限是单一权限,允许您定义分配给 角色 的授权。 每个权限都集中在资源(例如历程或优惠)下,代表Journey Optimizer中的不同功能或对象。 在权限级别部分了解详情。
-
沙盒:虚拟沙盒将实例分区为单独的独立虚拟环境。 沙盒通过权限中的角色进行分配。 了解有关使用沙盒的更多信息。
-
基于对象的访问控制:用于限制对象访问权限的标签。 这种方法可以保护敏感数字资产免受未经授权用户的访问,确保进一步保护个人数据。 了解有关基于对象的访问管理的详细信息。
-
基于属性的访问控制:管理特定团队或用户组的数据访问权限的授权。 基于属性的访问控制使管理员能够根据属性控制对特定对象和/或权能的访问。 属性可以是添加到对象的元数据,例如添加到架构字段或区段的标签。 管理员定义包括管理用户访问权限的属性的访问策略。 了解有关基于属性的访问管理的详细信息。
让我们深入探究
现在,您已了解 Journey Optimizer 中的访问控制概念,接下来该深入了解这些文档部分以开始配置权限。
This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.
For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.
- TL;DR: Access control in Journey Optimizer is built on roles, permissions, and sandboxes managed through Adobe CX Enterprise Permissions, with additional layers of object-based access control (OLAC) and attribute-based access control (ABAC) for fine-grained data protection.
Intents:
- Understand the five core access control concepts: roles, permissions, sandboxes, object-based access control, and attribute-based access control
- Know who can configure access control (system or product administrator)
- Navigate to the right documentation section for each access control topic
- Plan an access control strategy for the organization
Glossary:
- Roles: Collections of users sharing the same permissions and sandboxes; pre-existing built-in roles are available, and custom roles can be created (product-specific)
- Permissions: Unitary rights defining the authorizations assigned to Roles, grouped under resources such as Journey or Offers (product-specific)
- Sandboxes: Virtual environments partitioning the Journey Optimizer instance into separate, isolated virtual workspaces; assigned through roles in Permissions (product-specific)
- Object-based access control: Labels applied to specific Journey Optimizer objects (journeys, campaigns, offers) to restrict access to authorized users (product-specific)
- Attribute-based access control: Policies controlling access to objects or capabilities based on attributes such as labels added to schema fields or segments (product-specific)
Guardrails:
- Configuring access control requires system or product administrator privileges (prerequisite)
- The minimum role that can grant or withdraw permissions is a product administrator (as stated on the page)
Terminology:
- Canonical name: Attribute-based access control — Acronym: ABAC — variants: attribute-based access management
- Canonical name: Object-based access control — Acronym: OLAC — variants: object-level access control, object-based access management
- Do not confuse: “Object-based access control” (restricts access to specific AJO objects like journeys, campaigns, and offers using labels) ≠ “Attribute-based access control” (restricts access to data attributes like schema fields and segments based on label policies)
- Do not confuse: “Roles” (a collection of users with shared permissions and sandboxes) ≠ “Permissions” (the unitary rights grouped under resources that are assigned to roles)
FAQ:
- Q: Who can configure access control in Journey Optimizer? — Users with system administrator or product administrator privileges.
- Q: What is the minimum administrator level required to grant or withdraw permissions? — Product administrator.
- Q: Are sandboxes managed independently of roles? — No; sandboxes are assigned through roles in the Permissions product.
- Q: Where is access control for Journey Optimizer managed? — Through Permissions in Adobe CX Enterprise, which links users with permissions and sandboxes via roles and policies.