Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Introduction

From Permissions tab, the admin

Introduction

In CXO Designer, from under Permissions tab, a user with the Security Admin permission can set the permissions that the User or User Group a user or user group will have. Image RemovedTo set the permissions:

  1. Click Users
  2. Click User Groups or Users
  3. Click Edit
  4. Click Permissions
  5. Select the access for the user(s) and click Save

Image Added


CONTENT

Table of Contents

General Permissions

The "Access Mobile Version" Access Menu and Full POV permission indicates whether the user or users belonging to a specific group will be able to login in through the CXO-Mobile App.

Comments

This access the reports in the menu with the appurtenant POV. Giving this permission bypasses the Light User. Only Regular Users can access the menu and full POV.

Designer Permissions

The Designer Permission indicates whether the user or users belonging to a specific group will be able access the CXO-Designer or Source System manager. Refer Admin for more details.

Draft Data

These set of permissions indicates whether the user or users belonging to a specific group will be able to view Draft Data. Refer How to use - Draft period data.

  • View Draft Period Data - Ability to view, and select in the report's Point of View, data from the period marked as Draft
  • View Data Beyond Draft Period - Ability to view, and select in the report's Point of View, data from periods after the Draft Period

Comments

These set of permissions indicates whether the user or users belonging to a specific group will be able to Edit, Lock, Unlock Comments and View Comments History.

  • View Comments History - Ability to read comments & narratives (Applies to everyone who is allowed to view the data)
  • Edit Comments - Ability to edit comments & narratives
  • Lock Comments - Ability to lock comments & narratives (No more editing allowed)
  • Unlock Comments - Ability to unlock comments & narratives (Usually only the Administrator or the process owner is allowed to unlock)

Data Warehouse Adapter

These set of permissions indicates whether the user or users belonging to a specific group will be able to Edit Data Warehouse Data and Metadata.

  • Edit Data Warehouse Data - Ability to edit data, save them and process it towards the OLAP cube
  • Edit Data Warehouse Metadata - Ability to maintain and create Metadata and process it towards the OLAP cube

Workflows

These following set of permissions decide whether the user or users belonging to a specific group will be able to:

  • Access workflows: Only if a user has this permission enabled will they be able access workflow tab
  • Create workflows: When this option is enabled for a user, the +New tab to create a new workflow becomes available for the user
  • Edit workflows: When this option is enabled, the user can edit the template or the instance of the workflow. Edit workflow permission allows the user to make changes to the owner and/or due date for a step of the workflow.
  • Full control over all instances: Admin with this option enabled has full control over the workflow functionality. It also allows the user to mark a step as done even if the step is not assigned to them.

Other Permissions

The Access Mobile Version permission indicates whether the user or users belonging to a specific group will be able to login in through the CXO mobile app.

The Edit MDX permission indicates whether the user having Report Builder rights will be able to write MDX statements via linked cube calcs or linked MDX lists.

Permissions inheritance

Each user or user group can be member of one or more user groups. This can be set through the Main Tab inside Create New User / New User Group or Edit User / Edit User Group popup.

  • When a user or user group is member of a user group, he they will inherit all permissions from it (i.e. Permissions, Point  Point of View Security Filters or Report Filters or Report Permissions).
  • When a user or user group is member of more user group, he they will get the sum of all permissions from all the user groups he is are a member of.
  • In addition to the permissions inherited from the user group a user or user group is are a member of, additional permissions can be set for the specific user / user group. 
  • The inheritance hierarchy can be an as deep as needed, i.e. that is, it is possible to create basic user groups with permissions to be applied to most users (e.g. 'basic group') and then have additional user groups with more advanced permissions (e.g. 'group 1') who are member of the 'basic group', and then more complex user groups (e.g. 'group 2') who are member of 'group 1' and so on. Users member User members of 'group 2' will inherit permission both set for 'basic group' and for 'group 1'.

Permissions inheritance allows to optimize the maintenance of users and user groups..

Inherited permissions can't cannot be removed. When creating or editing a user or user group, inherited permissions will appear in the popup as selected and disabled, while permission set for the single user or user group will appear selected but enabled.
Unselecting the  option 'option Show inherited permissions, only permissions set for the specific user or user group will appear.

Image RemovedImage Added

Duplicated Permission

When a permission is both inherited and set for the current user or user group a symbol Image Removed  will appear close to the permission. It is suggested to remove duplicated permission to avoid potential problems .
e.g.for a scenario like:

  • A user is given 'Report Admin' permission
  • In a second timefuture, when more admin Admin users are needed, a user group ' Report Admin ' is created (with ' Report Admin ' permission) and the user is set as member of the group.
  • After a period for any reason, the admin Admin wants to take out remove the ' Report Admin ' permission from the user. He will remove the user from the 'Report Admin' group and think this is enough, while as the user had the 'Report Admin' permission set previously on himself, even if he is no more member of 'Report Admin' user group, he will still maintain the capabilities associated to 'Report Admin' permission.
Image Removed
  • The user loses the permissions that were part of that group but retains the permissions assigned directly to the user.
    Image Added  

To remove duplicated permissions:

  1. Unselect 'Show inherited permissions' flag option to view permission set for the current user or user group
  2. Unselect the duplicated permission permission
  3. Select again  'Show inherited permissions' flag option, the duplicated symbol will not appear any moreanymore
  4. Save

Draft Data

This set of permissions indicates whether the user or users belonging to a specific group will be able to view Draft Data.

  • View Draft Period Data - Ability to view, and select in the report's Point of View, data from the period marked as 'Draft'
  • View Data Beyond Draft Period - Ability to view, and select in the report's Point of View, data from periods after the 'Draft Period'

Admin

Action in CXO CockpitReport BuilderReport AdminReports Security AdminIntegration AdminSecurity AdminStoryboard AdminCreate report xxView any reportxView own reports depending on own menu-item permissionsxxModify or delete any reportxModify or delete own reports not yet placed in menu xxPlace reports in the menuxGive permissions to view reportsx

Create and modify shared objects like variables, formats, cube calculations and lists  

xCreate new private objects from scratch or based on a copy of a public objectxxSetup users and user groupsxConnect CXO-Cockpit to a source systemxGive users access to a storyboard in the CXO - Designer (via Tools)x

View Report Builder for more details on this role and on the differences between it and the Report Admin role.

Data Warehouse Adapter

This set of permissions indicates whether the user or users belonging to a specific group will be able to Edit Data Wharehouse Data and Metadata.

  • Edit Data Warehouse Data - Ability to edit data, save them and process it towards the OLAP cube
  • Edit Data Warehouse Metadata - Ability to maintain and create Metadata and process it towards the OLAP cube.
    1. Click Save