...
Step 1 | |
---|---|
Step 2 | For a User, click the User Roles tab. A list of Roles assigned to the User displays. |
Step 3 | Click Edit. An Edit Members pop-up displays that allows you to assign Roles to the User / Group. For example:
|
Step 4 | To filter the Users/Groups listed in the Collection window, enter characters in the text field above the Name column. Only Users/Groups containing that sequence of characters will display in the list. |
Step 5 | To assign a Role to the User / Group, move the Role from the Collection window to the Roles window:
To unassign a Role to the User / Group, move the Role from the Roles window to the Collection window:
|
Step 6 | Click Save. |
...
Role Name | Available Functions | Contains Roles | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| All functions; this is the Universal Controller administrator role. The easiest way to assign full permissions to a user is to add the user to the Administrator Group, which by default is assigned the ops_admin role.
|
| |||||||||||||||
| Create, read, update, and delete agent clusters. | ||||||||||||||||
| Read Audits. | ||||||||||||||||
|
(Also see Bundle Permissions and Promotion Target Permissions, below.) | ||||||||||||||||
| Create, update, and delete Dashboard Details with Everyone visibility; updating includes updating Dashboard visibility. | ||||||||||||||||
| Create, update, and delete Dashboard Details that are visible for a group in which this user is a member; updating includes updating Dashboard visibility. | ||||||||||||||||
| Create, update, delete Database Connections. | ||||||||||||||||
| Create, read, update, delete Email Connections. | ||||||||||||||||
| Create Filters with Everyone visibility. | ||||||||||||||||
| Create Filters that belong to a group of which this user is a member. | ||||||||||||||||
| Read Forecast Calendar, Forecasts List, and Forecast Details.
| ||||||||||||||||
| List Import/Export XML. | ||||||||||||||||
| Read and update LDAP Settings. | ||||||||||||||||
| |||||||||||||||||
| Create, update, and delete OMS Servers. | ||||||||||||||||
| Create, read, update, and delete PeopleSoft Connections. | ||||||||||||||||
| Accept bundles being promoted to a target server. (The Accept Bundle command is executed on the target server automatically as part of the Promote and Promote Bundle commands and does not involve user interaction.) | ||||||||||||||||
|
Note |
|
| ||||||||||||||
| Read, update, and delete Universal Controller system properties and Password Settings. | ||||||||||||||||
|
The Strict Report Create Constraints Universal Controller system property specifies whether or not to restrict report creation only to users with the ops_admin, ops_report_admin, ops_report_group, or ops_report_global role. |
| |||||||||||||||
| Create global reports. | ||||||||||||||||
| Create reports that belong to a group to which this user is a member. | ||||||||||||||||
| Publish reports. (This role was applicable only to the Controller 5.x release.) | ||||||||||||||||
| Restore old versions of records. | ||||||||||||||||
| Create, read, update, and delete SAP Connections. | ||||||||||||||||
| Run Server Operations. | ||||||||||||||||
|
| ||||||||||||||||
| Create, read, update, and delete SNMP Managers, to which the Controller sends SNMP notifications. | ||||||||||||||||
| Read and update Single Sign-On Settings. | ||||||||||||||||
| Create, read, update, and delete Universal Event Templates. |
| |||||||||||||||
| Read Universal Event Templates. | ||||||||||||||||
| Create, read, update, and delete Universal Templates (including Universal Template Event Templates). |
| |||||||||||||||
| Read Universal Templates (including Universal Template Event Templates). | ||||||||||||||||
| Create, read, update, and delete users and groups. | ||||||||||||||||
| Create, update, and delete Widgets. |
...
Step 1 | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
Step 2 | Click the Permissions tab. A list of permissions assigned to the User / Group displays.
| |||||||||||
Step 3 | Click New. The Permissions Details pop-up displays. | |||||||||||
Step 4 | Select permissions for the selected user or group.
|
...
Field Name | Description | ||||||
---|---|---|---|---|---|---|---|
Details | This section contains detailed information about the permission. | ||||||
| Applies this permission to records whose name matches the string specified here. Wildcards are supported. | ||||||
| Applies this permission both to records that belong to any Business Service and to records that do not belong to any Business Service. | ||||||
| Applies this permission to records that do not belong to any Business Service. If this option is enabled, the user / user group will have the defined permissions on all records that do not belong to any Business Service. | ||||||
| Applies this permission to records that are members of the selected Business Service(s). Click the lock icon to unlock the field and select Business Services. | ||||||
Metadata | This section contains Metadata information about this record. | ||||||
UUID | Universally Unique Identifier of this record. | ||||||
Updated By | Name of the user that last updated this record. | ||||||
Updated | Date and time that this record was last updated. | ||||||
Created By | Name of the user that created this record. | ||||||
Created | Date and time that this record was created. | ||||||
Buttons | This section identifies the buttons displayed above and below the Permissions Details that let you perform various actions. | ||||||
Save | Saves a new record in the Controller database. | ||||||
Save & New | Saves a new record in the Controller database and redisplays empty Details so that you can create another new record. | ||||||
Update |
| ||||||
Delete |
| ||||||
Refresh | Refreshes any dynamic data displayed in the Details. | ||||||
Close | For pop-up view only; closes the pop-up view of this record. |
...
Anchor | ||||
---|---|---|---|---|
|
Options | Description | ||
---|---|---|---|
Read | Grants permission to read an Agent definition.
| ||
Update | Grants permission to update an Agent definition. (Only certain fields can be updated.) | ||
Delete | Grants permission to delete an Agent. | ||
Execute | Grants permission to execute a task on an Agent. | ||
Commands |
|
...
(You also can assign Agent Cluster Permissions to a user by assigning the ops_agent_cluster_admin role to the user.)
Options | Description | ||
---|---|---|---|
Create | Grants permission to create a new Agent Cluster. | ||
Read | Grants permission to read an Agent Cluster definition.
| ||
Update | Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.) | ||
Delete | Grants permission to delete an Agent Cluster. | ||
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Application. |
Read | Grants permission to read an Application. |
Update | Grants permission to update an Application. |
Delete | Grants permission to delete an Application. |
Commands | See Application Control Tasks for details. Options:
|
...
(You also can assign Bundle Permissions to a user by assigning the ops_bundle_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a Bundle matching both the specified name wildcard and business service membership, including the use of the Create Bundle By Date and Create Bundle By Business Service commands. |
Read | Grants permission to read a Bundle matching both the specified name wildcard and business service membership.
|
Update | Grants permission to update a Bundle matching both the specified name wildcard and business service membership, including the use of the Add To Bundle command. |
Delete | Grants permission to delete a Bundle matching both the specified name wildcard and business service membership. |
Commands |
For the ALL or Promote Bundle command:
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Calendar. |
Read | Grants permission to read a Calendar. |
Update | Grants permission to update a Calendar. |
Delete | Grants permission to delete a Calendar. |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Credential. |
Read | Grants permission to read a Credential. |
Update | Grants permission to update a Credential. |
Delete | Grants permission to delete a Credential. |
Execute | Grants permission to execute a task that requires a Credential. |
Commands | N/A |
...
(You also can assign Database Connection Permissions to a user by assigning the ops_dba role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new Database Connection. |
Read | Grants permission to read a Database Connection. |
Update | Grants permission to update a Database Connection. |
Delete | Grants permission to delete a Database Connection. |
Execute | Grants permission to execute a task that requires a Database Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
...
(You also can assign Email Connection Permissions to a user by assigning the ops_email_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new Email Connection. |
Read | Grants permission to read an Email Connection. |
Update | Grants permission to update an Email Connection. |
Delete | Grants permission to delete an Email Connection. |
Execute | Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Email Template. |
Read | Grants permission to read an Email Template. |
Update | Grants permission to update an Email Template. |
Delete | Grants permission to delete an Email Template. |
Commands |
|
...
(You also can assign OMS Server Permissions to a user by assigning the ops_oms_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new OMS Server. |
Read | Grants permission to read an OMS Server. |
Update | Grants permission to update an OMS Server. |
Delete | Grants permission to delete an OMS Server. |
Commands |
|
...
(You also can assign PeopleSoft Connection Permissions to a user by assigning the ops_peoplesoft_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new PeopleSoft Connection. |
Read | Grants permission to read a PeopleSoft Connection. |
Update | Grants permission to update a PeopleSoft Connection. |
Delete | Grants permission to delete a PeopleSoft Connection. |
Execute | Grants permission to execute a task that requires a PeopleSoft Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
...
(You also can assign Promotion Target Permissions to a user by assigning the ops_promotion_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a Promotion Target matching both the specified name wildcard and business service membership. |
Read | Grants permission to read a Promotion Target matching both the specified name wildcard and business service membership. |
Update | Grants permission to update a Promotion Target matching both the specified name wildcard and business service membership. |
Delete | Grants permission to delete a Promotion Target matching both the specified name wildcard and business service membership |
Execute | Grants permission to promote a Bundle using a Promotion Target matching both the specified name wildcard and business service membership, assuming the user has both Read permission and Promote Bundle command permission for the Bundle. |
Commands |
|
...
(You also can assign SAP Connection Permissions to a user by assigning the ops_sap_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new SAP Connection. |
Read | Grants permission to read an SAP Connection. |
Update | Grants permission to update an SAP Connection. |
Delete | Grants permission to delete an SAP Connection. |
Execute | Grants permission to execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Script. |
Read | Grants permission to read a Script. |
Update | Grants permission to update a Script. |
Delete | Grants permission to delete a Script. |
Execute | Grants permission to execute a Script contained by a task. |
Commands |
|
...
(You also can assign SNMP Manager Permissions to a user by assigning the ops_snmp_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new SNMP Manager. |
Read | Grants permission to read an SNMP Manager. |
Update | Grants permission to update an SNMP Manager. |
Delete | Grants permission to delete an SNMP Manager. |
Execute | Grants permission to execute a task that requires an SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Task. |
Read | Grants permission to read a Task. |
Update | Grants permission to update a Task. |
Delete | Grants permission to delete a Task. |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description | |||||
---|---|---|---|---|---|---|
Create | Task instances are created automatically when the task launches, so the Create permission does not appear. | |||||
Read | Grants permission to read a Task Instance | |||||
Update | Grants permission to update certain fields on a Task Instance. | |||||
Delete | Grants permission to delete a Task Instance. | |||||
Commands | For command descriptions, see Manually Running and Controlling Tasks are created automatically when the task launches, so the Create permission does not appear. | |||||
Read | Grants permission to read a Task Instance | |||||
Update | Grants permission to update certain fields on a Task Instance. | |||||
Delete | Grants permission to delete a Task Instance. | |||||
Commands | For command descriptions, see Manually Running and Controlling Tasks.
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a Trigger. |
Read | Grants permission to read a Trigger. |
Update | Grants permission to update a Trigger. |
Delete | Grants permission to delete a Trigger. |
Commands |
|
...
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a Variable. |
Read | Grants permission to read a Variable. |
Update | Grants permission to update a Variable. |
Delete | Grants permission to delete a Variable. |
Commands | N/A |
...
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a virtual resource. |
Read | Grants permission to read a virtual resource. |
Update | Grants permission to update a virtual resource. |
Delete | Grants permission to delete a virtual resource. |
Execute | Grants permission to execute a virtual resource. |
Commands |
|
...
Step 1 | From the Administration navigation pane, select Security > Groups. The Groups list displays. |
---|---|
Step 2 | As desired, filter the list to select the group(s) whose permissions you want to export. When you perform the export, all groups matching the filter will be exported. |
Step 3 | Access the Action menu and select Export > Permissions For Group. |
To export or import the Permissions For Group XML, you must have the ops_admin role or the ops_imex and ops_user_admin roles.
...