---
name: hybrid-workloads-hybrid-access-tutorial
title: Customizing access for managing hybrid workloads
description: In this tutorial, you customize how a Power Virtual Server administrator can view and access an account with on-premises and off-premises environments. In this scenario, a retail company wants to run their core business logic on IBM Power Virtual Server on-premises and run front-end services on IBM Cloud.
last-updated: 2024-09-19
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hybrid-workloads?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Customizing access for managing hybrid workloads
{: #access-tutorial-hybrid}
{: toc-content-type="tutorial"}
{: toc-completion-time="60m"}

In this tutorial, you customize how a Power Virtual Server administrator can view and access an account with on-premises and off-premises environments. In this scenario, a retail company wants to run their core business logic on IBM Power Virtual Server on-premises and run front-end services on IBM Cloud.
{: shortdesc}

Create a trusted profile for the Power Virtual Server administrator to grant them consistent access across on-premises and cloud environments and tailor their platform experience to their job role.

## Before you begin
{: #before-hybrid}

Make sure that you are logged in as the account owner or a user with the Administrator role on all account management services or Administrator role on the IAM Identity Service. For more information, see [IAM Identity service](https://cloud.ibm.com/docs/account?topic=account-account-services&format=markdown#identity-service-account-management).

## Create a trusted profile
{: #it-tp}
{: step}

The primary focus of the Power Virtual Server administrator is helping ensure that the underlying infrastructure, both cloud and on-premises, runs smoothly, is secure, scalable, and available for other teams.

Complete the following steps:
1. In the IBM Cloud console, click **Manage** > **Access (IAM) > Trusted profiles** and click **Create**.
1. Enter the profile name `PowerVS Admin` and the initials `PA`.
1. Enter a description for the profile, like "Full access to deploy, configure, and manage virtual servers, storage, and networking components in both on-premises and cloud environments."
1. Select a color to represent this trusted profile and click **Continue**. Your users might have access to multiple trusted profiles in multiple accounts.
1. Select **Individual users** and select the Power Virtual Server administrators that need access. Then, click **Add to profile**.
1. Click **Continue** and select **Access policy**.

## Assign access
{: #it-access}
{: step}

To set up IBM Power Virtual Server Private Cloud and [manage Power Virtual Server instances](https://cloud.ibm.com/docs/power-iaas?topic=power-iaas-modifying-instance&format=markdown) across on-premises and cloud environments, the Power Virtual Server administrator needs the following roles and services:

1. Select the following role and service:
   - Service: Workspace for Power Virtual Server
   - Resources: All resources
   - Roles and actions: Administrator
1. Click **Add**.
1. To optimize and monitor resources after the infrastructure is in place, the Power Virtual Server administrator needs the following access:
   - Service: IBM Cloud Monitoring
   - Resources: All resources
   - Roles and actions: Editor
1. Click **Add**.
1. Click **Create**.

You might also create a trusted profile for an AIX administrator. This job role needs to Viewer access to Power Virtual Server to get SSH ports to connect to instances, see whether a resource is up, but doesn't need to create VSIs.
{: tip}

## Customize the console
{: #it-experience}
{: step}

After you click create, you can customize the console experience for the trusted profile.

1. Click **Console experience**.
1. Select the URL for the landing page and input the Power Virtual Server dashboard URL: https://cloud.ibm.com/power/overview.
1. Deselect the Manage navigation items. The Power Virtual Server administrator in this example doesn't need to manage account settings, access, or billing. Removing these menu items helps users complete tasks specific to their job role.
1. Select the private catalog that you created in [Setting up catalogs and locations for hybrid workloads](https://cloud.ibm.com/docs/hybrid-workloads?topic=hybrid-workloads-tutorial-hybrid&format=markdown). This way, the Power Virtual Server administrator can provision only resources that they have access to from the curated list of services that you created.
1. Click **Save**.

## Next steps
{: #next-step-order}

Now that access is set up for the Power Virtual Server administrator, prepare your data center and order IBM Power Virtual Server Private Cloud. For more information, see [Ordering on-premises infrastructure for your hybrid cloud](https://cloud.ibm.com/docs/hybrid-workloads?topic=hybrid-workloads-tutorial-services-hybrid&format=markdown).