Services

Explore Kyndryl Bridge Services

Subscription Access FAQ
Published On Jun 02, 2026 - 1:54 PM

Subscription Access FAQ

Understand how CCMM manages access groups and roles during subscription
What is
CCMM Subscription Access Group Automation
?
CCMM Subscription Access Group Automation creates customer access groups during CCMM subscription (via CCMM Broker or subscription flow) and assigns predefined IAM roles to those groups.
What is the purpose of this feature
?
This feature standardizes role-based access control for CCMM workflows during subscription and ensures CCMM personas receive appropriate permissions without manual IAM configuration.
What happens when a customer subscribes to CCMM?
When a customer subscribes to CCMM, the system automatically:
  • Creates required customer access groups
  • Maps each access group to the correct CCMM IAM role
  • Enables the groups for use by Workflow Service (workflowsvc)
Which personas and roles are supported?
Supported personas and roles are as follows:
CCMM Persona
IAM Role
Access Group
Owner
CCMMEvidenceControlOwner
Ccmm_Evidence_Control_Owner
Approver
CCMMEvidenceApprover
Ccmm_Evidence_Approver
Reviewer
CCMMEvidenceReviewer
Ccmm_Evidence_Reviewer
Support Admin
CCMMSupportAdmin
Ccmm_Support_Admin
Administrator
CCMMAdmin
Ccmm_Administrator
Viewer
CCMMViewer
Ccmm_Viewer
Are access groups created automatically?
Yes. Access groups are automatically created during the CCMM subscription process and mapped to the corresponding IAM roles.
Can existing CCMM subscriptions use this feature?
Existing subscriptions are not automatically updated. If new access groups are required, users must unsubscribe and resubscribe to CCMM for the updated configuration to reflect.
Who is responsible for IAM role creation?
The application team is responsible for creating IAM roles and defining associated permissions.
How are roles used in CCMM workflows?
Once assigned, IAM roles are inherited by users added to the respective access groups. The Workflow Service (workflowsvc) uses these roles to execute CCMM workflows based on assigned permissions.
Does this change require any manual configuration from customers?
No manual configuration is required for new subscriptions. Access group creation and role assignments are handled automatically during the subscription process.
Do you have two minutes for a quick survey?
Take Survey