Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Anchor
Agent Permissions
Agent Permissions
Agent Permissions

Image RemovedImage Added
 

Options

Description

Read

Grants permission to read an Agent definition. 

Note

The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.


Update

Grants permission to update an Agent definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent.

Execute

Grants permission to execute a task on an Agent.

Commands

  • ALL: Grants permission to suspend and resume Agents.
  • Resume Agent: Grants permission to resume the ability of a suspended Agent to run tasks.
  • Suspend Agent: Grants permission to suspend the ability of an Agent to run tasks.

...

(You also can assign Agent Cluster Permissions to a user by assigning the ops_agent_cluster_admin role to the user.)

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Agent Cluster.

Read

Grants permission to read an Agent Cluster definition.
 

Note

The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.


Update

Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent Cluster.

Commands

  • ALL: Grants permission to issue any command.
  • Resume Agent Cluster: Grants permission to resume the ability of a suspended Agent Cluster to run tasks.
  • Suspend Agent Cluster: Grants permission to suspend the ability of an Agent Cluster to run tasks.
  • Resume Agent Cluster Membership: Grants permission to resume the membership of an Agent in an Agent Cluster.
  • Suspend Agent Cluster Membership: Grants permission to suspend the membership of an Agent from an Agent Cluster.
  • Resolve Agent Cluster: Grants permission to resolve the Network Alias of an Agent Cluster with a Distribution type of Network Alias.

Anchor
Application Permissions
Application Permissions
Application Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Application.

Read

Grants permission to read an Application.

Update

Grants permission to update an Application.

Delete

Grants permission to delete an Application.

Commands

See Application Control Tasks for details. Options:

  • ALL: Grants permission to execute a Start, Stop, and Query from the Application resource screen.
  • Start: Grants permission to execute a Start from the Application resource screen.
  • Stop: Grants permission to execute a Stop from the Application resource screen.
  • Query: Grants permission to execute a Query from the Application resource screen.

...

(You also can assign Bundle Permissions to a user by assigning the ops_bundle_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a Bundle matching both the specified name wildcard and business service membership, including the use of the Create Bundle By Date and Create Bundle By Business Service commands.

Read

Grants permission to read a Bundle matching both the specified name wildcard and business service membership.

  • User can run a Bundle Report for a Bundle matching both the specified name wildcard and business service membership.
  • User can Read a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership.

Update

Grants permission to update a Bundle matching both the specified name wildcard and business service membership, including the use of the Add To Bundle command.

Delete

Grants permission to delete a Bundle matching both the specified name wildcard and business service membership.

Commands

  • ALL: Grants permission to issue any command.
  • Promote Bundle: Grants permission to promote a Bundle.

For the ALL or Promote Bundle command:

  • User can promote a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.
  • User can Cancel, Reschedule, or Delete a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.

Anchor
Calendar Permissions
Calendar Permissions
Calendar Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Calendar.

Read

Grants permission to read a Calendar.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Calendar.

Delete

Grants permission to delete a Calendar.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Calendar: Grants permission to copy a Calendar.

Anchor
Credential Permissions
Credential Permissions
Credential Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Credential.

Read

Grants permission to read a Credential.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Credential.

Delete

Grants permission to delete a Credential.

Execute

Grants permission to execute a task that requires a Credential.

Commands

N/A

...

(You also can assign Database Connection Permissions to a user by assigning the ops_dba role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new Database Connection.

Read

Grants permission to read a Database Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Database Connection.

Delete

Grants permission to delete a Database Connection.

Execute

Grants permission to execute a task that requires a Database Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy Database Connection: Grants permissions to copy a Database Connection.
  • Test Connection: Grants permission to test a Database Connection.

...

(You also can assign Email Connection Permissions to a user by assigning the ops_email_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new Email Connection.

Read

Grants permission to read an Email Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Email Connection.

Delete

Grants permission to delete an Email Connection.

Execute

Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy Email Connection: Grants permissions to copy an Email Connection.
  • Test Connection: Grants permission to test an Email Connection.

Anchor
Email Template Permissions
Email Template Permissions
Email Template Permissions

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new Email Template.

Read

Grants permission to read an Email Template.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Email Template.

Delete

Grants permission to delete an Email Template.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Email Template: Grants permission to copy an Email Template.

OAuth Client Permissions

(You also can assign OAuth Client Permissions to a user by assigning the ops_oauth_admin role to the user.)

Image Added

Options

Description

Create

Grants permission to create a new OAuth Client.

Read

Grants permission to read an OAuth Client.

Update

Grants permission to update an OAuth Client.

Delete

Grants permission to delete an OAuth Client.

Commands

-- None --

Anchor
OMS Server Permissions
OMS Server Permissions
OMS Server Permissions

(You also can assign OMS Server Permissions to a user by assigning the ops_oms_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new OMS Server.

Read

Grants permission to read an OMS Server.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an OMS Server.

Delete

Grants permission to delete an OMS Server.

Commands

  • ALL: Grants permission to suspend and resume OMS Servers.
  • Resume: Grants permission to resume the connection of a suspended OMS Server.
  • Suspend: Grants permission to suspend the connection of an OMS Server.

...

(You also can assign PeopleSoft Connection Permissions to a user by assigning the ops_peoplesoft_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new PeopleSoft Connection.

Read

Grants permission to read a PeopleSoft Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a PeopleSoft Connection.

Delete

Grants permission to delete a PeopleSoft Connection.

Execute

Grants permission to execute a task that requires a PeopleSoft Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy PeopleSoft Connection: Grants permission to copy a PeopleSoft Connection.

...

(You also can assign Promotion Target Permissions to a user by assigning the ops_promotion_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a Promotion Target matching both the specified name wildcard and business service membership.

Read

Grants permission to read a Promotion Target matching both the specified name wildcard and business service membership.
 
User can View Target Server Info for Promotion Target matching both the specified name wildcard and business service membership.

Update

Grants permission to update a Promotion Target matching both the specified name wildcard and business service membership.

Delete

Grants permission to delete a Promotion Target matching both the specified name wildcard and business service membership

Execute

Grants permission to promote a Bundle using a Promotion Target matching both the specified name wildcard and business service membership, assuming the user has both Read permission and Promote Bundle command permission for the Bundle.

Commands

  • ALL: Grants permission to issue any command.
  • Refresh Target Agents: Grants permission to refresh Target Agents.

...

(You also can assign SAP Connection Permissions to a user by assigning the ops_sap_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new SAP Connection.

Read

Grants permission to read an SAP Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an SAP Connection.

Delete

Grants permission to delete an SAP Connection.

Execute

Grants permission to execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy SAP Connection: Grants permissions to copy an SAP Connection.

Anchor
Script Permissions
Script Permissions
Script Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Script.

Read

Grants permission to read a Script.

Update

Grants permission to update a Script.

Delete

Grants permission to delete a Script.

Execute

Grants permission to execute a Script contained by a task.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Script: Grants permission to copy a Script.

...

(You also can assign SNMP Manager Permissions to a user by assigning the ops_snmp_admin role to the user.)

Image RemovedImage Added


Options

Description

Create

Grants permission to create a new SNMP Manager.

Read

Grants permission to read an SNMP Manager.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an SNMP Manager.

Delete

Grants permission to delete an SNMP Manager.

Execute

Grants permission to execute a task that requires an SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy SNMP Manager: Grants permissions to copy an SNMP Manager.

Anchor
Task Permissions
Task Permissions
Task Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a new Task.

Read

Grants permission to read a Task.

Update

Grants permission to update a Task.

Delete

Grants permission to delete a Task.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Task: Grants permission to copy a Task.
  • Launch: Grants permission to launch a Task.
  • Recalculate Forecast: Grants permission to recalculate a forecast.
  • Reset Statistics: Grants permission to reset statistics, including statistics being tracked by each parent Workflow of a Task.
  • Reset z/OS Override Statistics: Grants permission to reset z/OS override statistics.
  • Set Execution Restriction: Grants permission to set an execution restriction for a task in a workflow.

Anchor
Task Instance Permissions
Task Instance Permissions
Task Instance Permissions

Image RemovedImage Added
 

Options

Description

Create

Task instances are created automatically when the task launches, so the Create permission does not appear.

Read

Grants permission to read a Task Instance

Update

Grants permission to update certain fields on a Task Instance.

Delete

Grants permission to delete a Task Instance.

Commands

For command descriptions, see Manually Running and Controlling Tasks.

  • ALL: Grants permission to issue any command.
  • Cancel: Grants permission to cancel a Task Instance.
  • Clear All Dependencies: Grants permission to clear all dependencies on a Task Instance.
  • Clear Predecessors: Grants permission to clear all predecessors on a Task Instance.
  • Clear Exclusive: Grants permission to clear all mutual exclusive dependencies from a Task Instance.
  • Clear Resources: Grants permission to clear all resource dependencies of a Task Instance.
  • Clear Time Wait/Delay: Grants permission to clear all Wait To Start and Delay On Start specifications for a Task Instance.
  • Force Finish: Grants permission to force finish a Task Instance.
  • Force Finish/Cancel: Grants permission to force finish/cancel a Task Instance.
  • Hold: Grants permission to put a Task Instance on hold.
  • Insert Task: Grants permission to insert a task on the workflow monitor of a workflow Task Instance.
  • Mark as Satisfied: Can mark a dependency as satisfied.
  • Re-run: Grants permission to re-run a Task Instance.
  • Release: Grants permission to release a Task Instance from hold.
  • Release Recursive: Grants permission to release a workflow and all its tasks from hold.
  • Retrieve Output: Grants permission to execute the Retrieve Output button.
  • Set Priority Low: Grants permission to change the priority of a task to Low.
  • Set Priority Medium: Grants permission to change the priority of a task to Medium.
  • Set Priority High: Grants permission to change the priority of a task to High.
  • Set Completed: Grants permission to set a Manual Task Instance status to completed.
  • Set Started: Grants permission to set a Manual Task Instance status to a new started time.
  • Skip: Grants permission to skip a Task Instance.
  • Unskip: Grants permission to unskip a Task Instance selected to be skipped.
Note
titleNote

Universal Controller will initially check for command permission specifically for the task instance.

If no command permission is granted for the task instance, Universal Controller will check if command permission is granted for the parent workflow task instance, and then continue to check for command permission up the workflow task instance hierarchy.


Anchor
Trigger Permissions
Trigger Permissions
Trigger Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a Trigger.

Read

Grants permission to read a Trigger.

Update

Grants permission to update a Trigger.

Delete

Grants permission to delete a Trigger.

Commands

  • ALL: Grants permission to issue any command.
  • Assign Execution User: Grants permission to override the execution user of task instances launched by a Trigger.
  • Copy Trigger: Grants permission to copy a Trigger.
  • Disable Trigger: Grants permission to disable a Trigger.
  • Enable Trigger: Grants permission to enable a Trigger.
  • Recalculate Forecast: Grants permission to recalculate a forecast.
  • Set Skip Count: Grants permission to perform a Set Skip Count action with/without Update permission.  
  • Trigger Now: Grants permission to Trigger (launch) a task.

...

For a local Universal Event published by a Universal Task Instance Extension, the Universal Event inherits the Universal Task Instance Member of Business Services.

Image RemovedImage Added


Options

Description

Create

Grants permission to publish or push Universal Events.

Read

Grants permission to monitor Universal Events.

Note
titleNote

For Pre-Defined Global Universal Events, Webhook and/or Universal Monitor execution users must have "read" permission for the underlying record associated with the Universal Event in addition to "read" permission for the Universal Event itself. 

For example, the execution user for a Universal Monitor that monitors the UAC - Agent Changed Universal Event for the Universal Agent AGNT0001 must have "read" permission for the UAC - Agent Changed Universal Event and "read" permission for the Agent AGNT0001.


Commands

-- None --

Anchor
Variable Permissions
Variable Permissions
Variable Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a Variable.

Read

Grants permission to read a Variable.

Update

Grants permission to update a Variable.

Delete

Grants permission to delete a Variable.

CommandsN/A

-- None --

Anchor
Enabling Enhanced Variable Security
Enabling Enhanced Variable Security
Enabling / Disabling Enhanced Variable Security

...

Anchor
Virtual Resource Permissions
Virtual Resource Permissions
Virtual Resource Permissions

Image RemovedImage Added
 

Options

Description

Create

Grants permission to create a virtual resource.

Read

Grants permission to read a virtual resource.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a virtual resource.

Delete

Grants permission to delete a virtual resource.

Execute

Grants permission to execute a virtual resource.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Virtual Resource: Grants permission to copy a Virtual Resource.

...

Anchor
Webhook Permissions
Webhook Permissions

Webhook Permissions

Image RemovedImage Added

Options

Description

Create

Grants permission to create a Webhook.

Read

Grants permission to read a Webhook.

Update

Grants permission to update a Webhook.

Delete

Grants permission to delete a Webhook.

Commands
  • ALL: Grants permission to issue any command.
  • Enable: Grants permission to enable Webhook.
  • Disable: Grants permission to disable Webhook.
  • Assign Execution User: Grants permission to assign execution user to Webhook. 

...