Pre-migration
before migrating to bridge automation service (bas), complete the required setup and access configuration tasks described in this section prerequisites before using bas, ensure that the account is onboarded to the appropriate kyndryl bridge, and bas is enabled for more information, see onboarding and enablement home a user with the bridge platform administrator role completes the prerequisite configuration tasks verify that the required automation access groups are available in bridge iam the access groups typically begin with automation common access groups include automation admin or automation administrator automation editor automation operator automation viewer create dedicated cacf credentials to allow bas to access the cacf, create dedicated credentials for each organization or account follow the iam process to obtain a functional id for bas access to cacf this task is typically performed by the delivery program executive (dpe) for more information, see identity management at kyndryl https //kyndryl sharepoint com/sites/identityandaccessmanagement/sitepages/identity%20management aspx#how to create a functional or application id 1 sign in to ansible automation platform (aap) using the functional id this step creates the aap user profile associated with this id the tower account/organization administrator grants the required permissions to the aap user profile a tenant automation administrator (taa) can generate a token in aap bas uses this token as the fid token to connect to aap for a specific organization for assistance with creating a functional id or completing cacf related tasks, contact the cacf team for more information, go to, automation services onboarding and enablement https //kyndryl sharepoint com/sites/cto automation/sitepages/automation services enablement aspx?teamscid=745d84aa a321 42a6 8d5d 9ee941928136#aap communication with aiops automation services onboard a dedicated cacf connection as a bridge credential a user must have the bridge platform administrator role to create connections in bridge from the main menu , go to administration → connections management select tool connections , and then select add connection configure the connection set connection type to cacf under supported apps, select provisioning orchestration and automation enter a connection name using the following format \<gsma code>@cacf instance example ace\@devtest4 enter a description to identify the target environment (optional) click next enter the endpoint url and gsma organization information enter the endpoint url and gsma organization information click next enter the authorization token for more information, go to create dedicated credentials for cacf click next review the configuration details and click submit enable automation admin access group with admin role from the main menu , go to access management → access groups login as a user with the bridge platform administrator role edit the automation admin or automation administrator access group assign the orchestration administrator role save the changes