Skip to main content

Zuora OneID unified permission management for Zuora Billing

Zuora

Zuora OneID unified permission management for Zuora Billing

Introduces the centralized management of user roles, permissions, and access controls across Zuora Billing tenants from Zuora OneID.

Unified Permission Management in OneID provides a centralized and streamlined approach to managing user roles, permissions, and access controls across Zuora Billing tenants from Zuora OneID. This capability ensures a consistent and secure framework for defining and enforcing permissions, reducing complexity and improving compliance.

Unified Permission Management in OneID supports Zuora Billing tenants only. 

Unified Permission management helps you create global roles and manage permissions from within OneID for various tenants and modules including Zuora Platform, Billing, Payment, Finance, Commerce and Reporting. 

Unified Permission management offers the following benefits:

  • Centralized Interface: Manage permissions for Zuora Billing tenants from a single, intuitive UI within OneID. 
  • Create and Manage Global Roles: You no longer need to manually recreate the same role and permission configurations across multiple tenants. With this module, you can create a global role once, and it will automatically be available across all your Billing tenants—including Production, Sandbox, and Central Sandbox.
  • Granular Controls: Define and customize user roles with precise access rights tailored to specific business needs, clone and copy the permissions easily
  • Audit Trail Integration: Track and monitor permission changes with a detailed, time-stamped log for compliance and audit purposes.
  • Scalable Design: Support for dynamic business environments, enabling seamless updates to roles and permissions as organizational needs evolve.

Activate Unified Permission management

Before your organization can use this feature, you must reach out to Zuora Global Support for activation. Our support team will help enable Unified Permission management feature for your organization. Once our team enables this feature, you will find the User roles and permissions menu option in the left hand navigation of the OneID dashboard. 

While your organization is still using the current roles mapped to your users either directly or via user groups, will still continue to work along with this new unified permission management module. You can also import the roles to this new permission management module to create the Global roles.

Create a new role under unified permission management

When a user role is created, it is available across all tenants.

To create a new role:

  1. Navigate to OneID > Admin Console > User roles and permissions.
  2. Click the Add New Role button on the top right.
  3. In the New Role dialog, enter the Role Name and select the Product Type for which the role is applicable. 
  4. Click Next
    You can configure the permissions for each module in your Billing tenants, and it is not required to create modular roles anymore within Billing.
  5. After configuring the permissions for the new role, click Save.

Import tenant roles

To seamlessly transition the existing user roles into global roles, you can use the Import Tenant Roles feature. You can import all the existing roles created in various tenants along with the permission settings. 

To avoid role duplication, the import roles feature will not import roles with a similar set of permissions. 

To import tenant roles:

  1. Navigate to OneID > Admin Console > User roles and permissions.
  2. Click the Import Tenant Roles button on the top right.
  3. Using the dropdown, select a tenant to import all the existing roles created in that tenant. 
  4. Click Convert.

Clone a role

Cloning a role creates a copy of an existing role, including its associated permissions, but does not copy users assigned to the original role. You can make additional customizations to create a new role. 

To clone a role:

  1. Navigate to OneID > Admin Console > User roles and permissions.
  2. Click the ellipsis icon next to the role you want to clone.
  3. In the role information page, make the customizations required and click Save.

Working of Unified Permission Management

Within this permission management module, you can create global user roles by either setting up a new role with custom permissions, importing roles from an existing tenant-level setup, or cloning an existing global role and modifying its permissions as needed.

Once global roles are created, they become automatically available across all tenants. You can assign them directly to users using Direct Tenant Access provisioning or through user groups using Group Provisioning mode.

Currently, if a feature isn’t enabled in a Billing tenant, assigning a role associated with that feature will have no effect—the user’s experience will remain unchanged upon login.