diff --git a/datacenter/ucp/2.2/guides/admin/manage-users/grant-permissions.md b/datacenter/ucp/2.2/guides/admin/manage-users/grant-permissions.md index 73b25ecc34..7c4ce85999 100644 --- a/datacenter/ucp/2.2/guides/admin/manage-users/grant-permissions.md +++ b/datacenter/ucp/2.2/guides/admin/manage-users/grant-permissions.md @@ -13,6 +13,8 @@ to a set of resources (collection). Each grant is a 1:1:1 mapping of subject, role, collection. For example, you can grant the "Prod Team" "Restricted Control" permissions for the "/Production" collection. +![](../../images/ucp-grant-model.png) + The usual workflow for creating grants has four steps. 1. Set up your users and teams. For example, you might want three teams, diff --git a/datacenter/ucp/2.2/guides/images/ucp-grant-model.png b/datacenter/ucp/2.2/guides/images/ucp-grant-model.png new file mode 100755 index 0000000000..7371c51c2a Binary files /dev/null and b/datacenter/ucp/2.2/guides/images/ucp-grant-model.png differ