Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Role Name

Available Functions

Contains Roles

Anchor
ops_admin
ops_admin
ops_admin

All functions; this is the Universal Controller administrator role. The easiest way to assign full permissions to a user is to add the user to the Administrator Group, which by default is assigned the ops_admin role.
 

Note
titleNote

The ops_admin role contains all other roles. If a user is assigned the ops_admin role, no other roles need to be assigned to that user, and unassigning any other role from the user will not revoke that role.

  • ops_agent_cluster_admin
  • ops_audit_view
  • ops_bundle_admin
  • ops_dba
  • ops_email_admin
  • ops_filter_global
  • ops_filter_group
  • ops_forecast_view
  • ops_imex
  • ops_ldap_admin
  • ops_multi_update
  • ops_oms_admin
  • ops_peoplesoft_admin
  • ops_promotion_admin
  • ops_property_admin
  • ops_report_admin
  • ops_restore_version
  • ops_sap_admin
  • ops_server_operation_admin
  • ops_service
  • ops_snmp_admin
  • ops_sso_admin
  • ops_universal_template_admin
  • ops_user_admin

Anchor
ops_agent_cluster_admin
ops_agent_cluster_admin
ops_agent_cluster_admin

Create, read, update, and delete agent clusters.
 
(Also see Agent Cluster Permissions, below.)


Anchor
ops_audit_view
ops_audit_view
ops_audit_view

Read Audits.


Anchor
ops_bundle_admin
ops_bundle_admin
ops_bundle_admin


Anchor
ops_dashboard_global
ops_dashboard_global
ops_dashboard_global

Create, update, and delete Dashboards Dashboard Details with Everyone visibility; updating includes updating Dashboard visibility.


Anchor
ops_dashboard_group
ops_dashboard_group
ops_dashboard_group

Create, update, and delete Dashboards Dashboard Details that are visible for a group in which this user is a member; updating includes updating Dashboard visibility.


Anchor
ops_dba
ops_dba
ops_dba

Create, update, delete Database Connections.
 
(Also see Database Connection Permissions, below.)


Anchor
ops_email_admin
ops_email_admin
ops_email_admin

Create, read, update, delete Email Connections.
 
(Also see Email Connection Permissions, below.)


Anchor
ops_filter_global
ops_filter_global
ops_filter_global

Create Filters with Everyone visibility.


Anchor
ops_filter_group
ops_filter_group
ops_filter_group

Create Filters that belong to a group of which this user is a member.


Anchor
ops_forecast_view
ops_forecast_view
ops_forecast_view

Read Forecast Calendar, Forecasts List, and Forecast Details.
 

Note
titleNote

Users also can read forecast information, without being assigned this role, if they have Read permission for the Task specified in the Forecast Details.


Anchor
ops_imex
ops_imex
ops_imex

List Import/Export XML.


Anchor
ops_ldap_admin
ops_ldap_admin
ops_ldap_admin

Read and update LDAP Settings.


Anchor
ops_multi_update
ops_multi_update
ops_multi_update

Update multiple records.


Anchor
ops_oms_admin
ops_oms_admin
ops_oms_admin

Create, update, and delete OMS Servers.


Anchor
ops_peoplesoft_admin
ops_peoplesoft_admin
ops_peoplesoft_admin

Create, read, update, and delete PeopleSoft Connections.
 
(Also see PeopleSoft Connection Permissions, below.)


Anchor
ops_promotion_accept_bundle
ops_promotion_accept_bundle
ops_promotion_accept_bundle

Accept bundles being promoted to a target server. (The Accept Bundle command is executed on the target server automatically as part of the Promote and Promote Bundle commands and does not involve user interaction.)


Anchor
ops_promotion_admin
ops_promotion_admin
ops_promotion_admin

Promotion Targets

Bundles

Refresh Target Agents

Promote records

Promote

schedule the promotion

Promotion Schedules

Generate a Bundle report

Note
titleNote

By default, the ops_promotion_admin role also grants Read permission for any type of definition that can be added to a Bundle, given the expectation that a promotion administrator would review the content of a Bundle before promoting it. To change this default behaviour, see the Promotion Read Permission Required Universal Controller property.

 
(Also see Bundle Permissions and Promotion Target Permissions, below.)

  • ops_promotion_accept_bundle

Anchor
ops_property_admin
ops_property_admin
ops_property_admin

Read, update, and delete Universal Controller system properties and Password Settings.


Anchor
ops_report_admin
ops_report_admin
ops_report_admin

report

visibility

ops_widget_admin

DashboardsDashboard DetailsDashboards

Dashboard Details

The Strict Report Create Constraints Universal Controller system property specifies whether or not to restrict report creation only to users with the ops_admin, ops_report_admin, ops_report_group, or ops_report_global role.
 
The Strict Dashboard Create Constraints Universal Controller system property specifies whether or not to restrict Dashboard creation only to users with the ops_admin, ops_report_admin, ops_dashboard_group, or ops_dashboard_global role.

  • ops_dashboard_global
  • ops_dashboard_group
  • ops_report_global
  • ops_report_group
  • ops_report_publish
  • ops_widget_admin

Anchor
ops_report_global
ops_report_global
ops_report_global

Create global reports.


Anchor
ops_report_group
ops_report_group
ops_report_group

Create reports that belong to a group to which this user is a member.


Anchor
ops_report_publish
ops_report_publish
ops_report_publish

Publish reports. (This role was applicable only to the Controller 5.x release.)


Anchor
ops_restore_version
ops_restore_version
ops_restore_version

Restore old versions of records.


Anchor
ops_sap_admin
ops_sap_admin
ops_sap_admin

Create, read, update, and delete SAP Connections.
 
(Also see SAP Connection Permissions, below.)


Anchor
ops_server_operation_admin
ops_server_operation_admin
ops_server_operation_admin

Run Server Operations.


Anchor
ops_service
ops_service
ops_service


Anchor
ops_snmp_admin
ops_snmp_admin
ops_snmp_admin

Create, read, update, and delete SNMP Managers, to which the Controller sends SNMP notifications.
 
(Also see SNMP Manager Permissions, below.)


Anchor
ops_sso_admin
ops_sso_admin
ops_sso_admin

Read and update Single Sign-On Settings.


Anchor
ops_universal_template_admin
ops_universal_template_admin
ops_universal_template_admin

Create, read, update, and delete Universal Templates.

  • ops_universal_template_view

Anchor
ops_universal_template_view
ops_universal_template_view
ops_universal_template_view

Read Universal Templates.


Anchor
ops_user_admin
ops_user_admin
ops_user_admin

Create, read, update, and delete users and groups.


Anchor
ops_widget_admin
ops_widget_admin
ops_widget_admin

Create, update, and delete Widgets.


...

Options

Description

Read

Grants permission to read an Agent definition.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Agent definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent.

Execute

Grants permission to execute a task on an Agent.

Commands

  • ALL: Grants permission to suspend and resume Agents.
  • Resume Agent: Grants permission to resume the ability of a suspended Agent to run tasks.
  • Suspend Agent: Grants permission to suspend the ability of an Agent to run tasks.

...

Options

Description

Create

Grants permission to create a new Agent Cluster.

Read

Grants permission to read an Agent Cluster definition.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent Cluster.

Commands

  • ALL: Grants permission to issue any command.
  • Resume Agent Cluster: Grants permission to resume the ability of a suspended Agent Cluster to run tasks.
  • Suspend Agent Cluster: Grants permission to suspend the ability of an Agent Cluster to run tasks.
  • Resume Agent Cluster Membership: Grants permission to resume the membership of an Agent in an Agent Cluster.
  • Suspend Agent Cluster Membership: Grants permission to suspend the membership of an Agent from an Agent Cluster.
  • Resolve Agent Cluster: Grants permission to resolve the Network Alias of an Agent Cluster with a Distribution type of Network Alias.

...

Options

Description

Create

Grants permission to create a new Calendar.

Read

Grants permission to read a Calendar.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Calendar.

Delete

Grants permission to delete a Calendar.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Calendar: Grants permission to copy a Calendar.

...

Options

Description

Create

Grants permission to create a new Credential.

Read

Grants permission to read a Credential.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Credential.

Delete

Grants permission to delete a Credential.

Execute

Grants permission to execute a task that requires a Credential.

Commands

N/A

...

Options

Description

Create

Grants permission to create a new Database Connection.

Read

Grants permission to read a Database Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a Database Connection.

Delete

Grants permission to delete a Database Connection.

Execute

Grants permission to execute a task that requires a Database Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy Database Connection: Grants permissions to copy a Database Connection.
  • Test Connection: Grants permission to test a Database Connection.

...

Options

Description

Create

Grants permission to create a new Email Connection.

Read

Grants permission to read an Email Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Email Connection.

Delete

Grants permission to delete an Email Connection.

Execute

Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy Email Connection: Grants permissions to copy an Email Connection.
  • Test Connection: Grants permission to test an Email Connection.

...

Options

Description

Create

Grants permission to create a new Email Template.

Read

Grants permission to read an Email Template.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Email Template.

Delete

Grants permission to delete an Email Template.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Email Template: Grants permission to copy an Email Template.

...

Options

Description

Create

Grants permission to create a new OMS Server.

Read

Grants permission to read an OMS Server.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an OMS Server.

Delete

Grants permission to delete an OMS Server.

Commands

  • ALL: Grants permission to suspend and resume OMS Servers.
  • Resume: Grants permission to resume the connection of a suspended OMS Server.
  • Suspend: Grants permission to suspend the connection of an OMS Server.

...

Options

Description

Create

Grants permission to create a new PeopleSoft Connection.

Read

Grants permission to read a PeopleSoft Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a PeopleSoft Connection.

Delete

Grants permission to delete a PeopleSoft Connection.

Execute

Grants permission to execute a task that requires a PeopleSoft Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy PeopleSoft Connection: Grants permission to copy a PeopleSoft Connection.

...

Options

Description

Create

Grants permission to create a new SAP Connection.

Read

Grants permission to read an SAP Connection.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an SAP Connection.

Delete

Grants permission to delete an SAP Connection.

Execute

Grants permission to execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy SAP Connection: Grants permissions to copy an SAP Connection.

...

Options

Description

Create

Grants permission to create a new SNMP Manager.

Read

Grants permission to read an SNMP Manager.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an SNMP Manager.

Delete

Grants permission to delete an SNMP Manager.

Execute

Grants permission to execute a task that requires an SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

Commands

  • ALL: Grants permission to issue any command.
  • Copy SNMP Manager: Grants permissions to copy an SNMP Manager.

...

By default, enhanced global variable security is enabled; the Variable Security Enabled Universal Controller system property is set to true.

...

All defined Variable permissions will be enforced unless enhanced global variable security has been disabled by setting Variable Security Enabled to false. This allows all global variables to be managed and used by any valid Universal Controller user.

...

Options

Description

Create

Grants permission to create a virtual resource.

Read

Grants permission to read a virtual resource.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update a virtual resource.

Delete

Grants permission to delete a virtual resource.

Execute

Grants permission to execute a virtual resource.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Virtual Resource: Grants permission to copy a Virtual Resource.

...

By default, enhanced virtual resource security is enabled; the Virtual Resource Security Enabled Universal Controller system property is set to true.

...

All defined Virtual Resource permissions will be enforced unless enhanced virtual resource security has been disabled by setting Virtual Resource Security Enabled to false. This allows all virtual resources to be managed and used by any valid Universal Controller user.

...

The Controller lets you export user groups and their permissions, which then can be imported into another Controller system. Only the permissions listed under the Permissions tab for each group will be exported.
 

Step 1

From the Administration navigation pane, select Security > Groups. The Groups list displays.

Step 2

As desired, filter the list to select the group(s) whose permissions you want to export. When you perform the export, all groups matching the filter will be exported.

Step 3

Access the Action menu and select Export > Permissions For Group.
 

...