Identity and access problems generally occur at one of several layers:
Authentication
↓
Identity Federation
↓
K2cloud Orchestrator Authorization
or
Fabric Space Authorization
↓
Optional Application Authorization
Start by determining where access fails before changing roles, groups, or federation configuration.
If the user cannot complete sign-in, investigate authentication and federation before investigating Fabric roles.
For federated users, verify:
Changes to the customer IdP, SAML application, certificates, metadata, or identity claims can affect authentication.
For more information, see Identity Federation.
Successful authentication does not automatically provide access to K2cloud Orchestrator.
Verify that the user has the appropriate K2cloud authorization.
Project Manager access requires the cloud_user role.
Do not assign cloud_user simply to solve a Space-access problem. This is a highly privileged role that provides Project and Space lifecycle capabilities.
If the user only needs access to a Studio or Fabric Space, troubleshoot Space authorization instead.
If authentication succeeds but the Space cannot be accessed, verify the user's Space authorization.
For federated users, check the authorization chain:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
Space Access
Verify that:
If the user can enter the Space but cannot perform a specific operation, authentication and basic Space access are already working.
Review the permissions assigned to the user's Fabric role.
For example, determine whether the role provides the permissions required for the affected:
TDM introduces an additional authorization layer.
The complete mapping can be:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
TDM Permission Group
If the user can access Fabric but cannot perform the expected TDM operation, verify the mapping between the Fabric role and the appropriate TDM permission group.
Creating a Space does not automatically grant the Space creator runtime administrative access.
Also, the built-in space_user role is not automatically added to a newly created Space.
Verify that:
Git access is separate from K2cloud and Fabric authorization.
If a Studio user can access the Space but cannot commit or push changes, verify:
Do not attempt to solve a Git authorization problem by changing K2cloud or Fabric roles.
If access previously worked, identify what changed.
Common areas to review include:
Federation configuration is operational configuration. Changes to identity trust or group mappings can affect deployed Spaces and should be planned and validated carefully.
Use the following sequence to isolate the problem:
Can the user authenticate?
Can the user access the requested application?
Can the user enter the Space but not perform the required operation?
Is the problem specific to TDM?
Is the problem specific to Git?
This sequence helps avoid granting unnecessary privileges while troubleshooting an access problem.
Identity and access problems generally occur at one of several layers:
Authentication
↓
Identity Federation
↓
K2cloud Orchestrator Authorization
or
Fabric Space Authorization
↓
Optional Application Authorization
Start by determining where access fails before changing roles, groups, or federation configuration.
If the user cannot complete sign-in, investigate authentication and federation before investigating Fabric roles.
For federated users, verify:
Changes to the customer IdP, SAML application, certificates, metadata, or identity claims can affect authentication.
For more information, see Identity Federation.
Successful authentication does not automatically provide access to K2cloud Orchestrator.
Verify that the user has the appropriate K2cloud authorization.
Project Manager access requires the cloud_user role.
Do not assign cloud_user simply to solve a Space-access problem. This is a highly privileged role that provides Project and Space lifecycle capabilities.
If the user only needs access to a Studio or Fabric Space, troubleshoot Space authorization instead.
If authentication succeeds but the Space cannot be accessed, verify the user's Space authorization.
For federated users, check the authorization chain:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
Space Access
Verify that:
If the user can enter the Space but cannot perform a specific operation, authentication and basic Space access are already working.
Review the permissions assigned to the user's Fabric role.
For example, determine whether the role provides the permissions required for the affected:
TDM introduces an additional authorization layer.
The complete mapping can be:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
TDM Permission Group
If the user can access Fabric but cannot perform the expected TDM operation, verify the mapping between the Fabric role and the appropriate TDM permission group.
Creating a Space does not automatically grant the Space creator runtime administrative access.
Also, the built-in space_user role is not automatically added to a newly created Space.
Verify that:
Git access is separate from K2cloud and Fabric authorization.
If a Studio user can access the Space but cannot commit or push changes, verify:
Do not attempt to solve a Git authorization problem by changing K2cloud or Fabric roles.
If access previously worked, identify what changed.
Common areas to review include:
Federation configuration is operational configuration. Changes to identity trust or group mappings can affect deployed Spaces and should be planned and validated carefully.
Use the following sequence to isolate the problem:
Can the user authenticate?
Can the user access the requested application?
Can the user enter the Space but not perform the required operation?
Is the problem specific to TDM?
Is the problem specific to Git?
This sequence helps avoid granting unnecessary privileges while troubleshooting an access problem.