Access & Entitlement
One login, one console
Onam DRM runs at /drm inside the same console as the rest of the Onam platform, behind the same login. There is no second credential and no separate set of cloud connections — DRM reads the platform's cloud inventory, so your accounts are connected once.
Entitlement
DRM is a separate product, granted per organisation as its own add-on. Organisations without the grant do not get access to DRM's pages or its API.
Who can do what
Seeing DRM, approving what it proposes and authoring records in it are separate permissions. Reaching a page does not let you approve anything on it.
| Permission | What it allows |
|---|---|
| View | Read applications, dependencies, protection, plans, readiness, drift and drills |
| Approve | Accept or reject proposals in the Approval Center — the act that lets an item into a plan or a baseline |
| Author | Create and edit what people write in DRM, such as drill records |
| Modify rules | Change the rules DRM's engines use |
Permissions come from the roles and grants your platform administrator already manages — DRM does not keep its own user list. A grant carries the scope it was made at: a permission granted for one cloud account allows nothing across the whole organisation.
What DRM changes in your cloud
Nothing. DRM reads configuration and inventory. Approvals, baselines, required targets and drill records are records inside DRM, not changes to your cloud accounts. It does not execute a recovery, run a DR test or connect to a backup product.
"Why can't I see DRM?" Either your organisation has not been granted it, or your role does not include it. Ask your platform administrator, or talk to us.