Overview
provides the foundational framework to govern and control user access to services and resources it supports both kyndryl teams and customer organizations by offering scalable, secure and policy driven access management ensures users can access only what they need, when they need it, based on their role, identity and attributes, while adhering to enterprise security and compliance standards by implementing across the bridge platform, teams gain a centralized visibility and control over authentication, authorization, reducing risk and simplifying operations in complex hybrid environments defines who can do what on which resources roles are collections of permissions used as building blocks access policies grant one or more roles to a subject over all resources or a scoped set service ids are non human identities for applications, agents and automations api keys are scoped credentials used by users or service ids to authenticate system to system calls prerequisites and personas the prerequisites define the minimum requirements needed to access and manage the service, while the personas define the types of users who interact with and the permissions and responsibilities assigned to each role prerequisites the primary prerequisites are a bridge account with administrator role or equivalent permissions for management tasks bridge services registered to kyndryl platform central, so they appear in the main menu > services when creating roles and policies (platform appears by default) personas the following user personas have been defined administrators create custom roles, assign policies and manage service ids and api keys end to end operators and contributors view roles and policies, manage their own api keys, request policy changes viewers read only access, can manage their own api keys if allowed by the policy