Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Step 1

Open a User or Group record.

Step 2

For a User, click the User Roles tab. A list of Roles assigned to the User displays.
 

 
For a Group, click the Group Roles tab. A list of Roles assigned to the Group displays.
 

Step 3

Click Edit. An Edit Members pop-up displays that allows you to assign Roles to the User / Group. For example:
 
Image RemovedImage Added
 

  • The Collection window displays all Roles that have not been assigned to this User / Group.
  • The Roles List window displays all Roles that have been assigned to this User / Group.

Step 4

To filter the Users/Groups listed in the Collection window, enter characters in the text field above the Name column. Only Users/Groups containing that sequence of characters will display in the list.

Step 5

To assign a Role to the User / Group, move the Role from the Collection window to the Roles window:

Step 6

Click Save.

...

The following table summarizes the roles available in the Controller.

ops_adminAll functions; this is the Universal Controller administrator role. The easiest way to assign full permissions to
  • To move a single Role, double-click it or click it once and then click the > arrow.
  • To move multiple Roles, Ctrl-click them and then click the > arrow.
  • To move all Roles, click the >> arrow.

To unassign a Role to the User / Group, move the Role from the Roles window to the Collection window:

  • To move a single Role, double-click it or click it once and then click the < arrow.
  • To move multiple Roles, Ctrl-click them and then click the < arrow.
  • To move all Roles, click the << arrow.

Role Name

Available Functions

Contains Roles

Anchor
ops_adminops_admin

Step 6

Click Save.

Anchor
Description of Roles
Description of Roles
Description of Roles

The following table summarizes the roles available in the Controller.

By default, the ops
  • .
  • Accept bundles being promoted to a target server. (The Accept Bundle command is executed on the target server automatically as part of the Promote and Promote Bundle commands and does not involve user interaction.)

Role Name

Available Functions

Contains Roles

Anchor
ops_admin
ops_admin
ops_admin

All functions; this is the Universal Controller administrator role. The easiest way to assign full permissions to a user is to add the user to the Administrator Group, which by default is assigned the ops_admin role.
 

Note
titleNote

The ops_admin role contains all other roles. If a user is assigned the ops_admin role, no other roles need to be assigned to that user, and unassigning any other role from the user will not revoke that role.


  • ops_agent_cluster_admin
  • ops_audit_view
  • ops_bundle_admin
  • ops_dba
  • ops_email_admin
  • ops_filter_global
  • ops_filter_group
  • ops_forecast_view
  • ops_imex
  • ops_ldap_admin
  • ops_multi_update
  • ops_oms_admin
  • ops_peoplesoft_admin
  • ops_promotion_admin
  • ops_property_admin
  • ops_report_admin
  • ops_restore_version
  • ops_sap_admin
  • ops_server_operation_admin
  • ops_service
  • ops_snmp_admin
  • ops_sso_admin
  • ops_universal_event_template_admin
  • ops_universal_template_admin
  • ops_user_admin

Anchor
ops_agent_cluster_admin
ops_agent_cluster_admin
ops_agent_cluster_admin

Create, read, update, and delete agent clusters.
 
(Also see Agent Cluster Permissions, below.)


Anchor
ops_audit_view
ops_audit_view
ops_audit_view

Read Audits.


Anchor
ops_bundle_admin
ops_bundle_admin
ops_bundle_admin


Anchor
ops_dashboard_global
ops_dashboard_global
ops_dashboard_global

Create, update, and delete Dashboards Dashboard Details with Everyone visibility; updating includes updating Dashboard visibility.


Anchor
ops_dashboard_group
ops_dashboard_group
ops_dashboard_group

Create, update, and delete Dashboards Dashboard Details that are visible for a group in which this user is a member; updating includes updating Dashboard visibility.


Anchor
ops_dba
ops_dba
ops_dba

Create, update, delete Database Connections.
 
(Also see Database Connection Permissions, below.)


Anchor
ops_email_admin
ops_email_admin
ops_email_admin

Create, read, update, delete Email Connections.
 
(Also see Email Connection Permissions, below.)


Anchor
ops_filter_global
ops_filter_global
ops_filter_global

Create Filters with Everyone visibility.


Anchor
ops_filter_group
ops_filter_group
ops_filter_group

Create Filters that belong to a group of which this user is a member.


Anchor
ops_forecast_view
ops_forecast_view
ops_forecast_view

Read Forecast Calendar, Forecasts List, and Forecast Details.
 

Note
titleNote

Users also can read forecast information, without being assigned this role, if they have Read permission for the Task specified in the Forecast Details.



Anchor
ops_imex
ops_imex
ops_imex

List Import/Export XML.


Anchor
ops_ldap_admin
ops_ldap_admin
ops_ldap_admin

Read and update LDAP Settings.


Anchor
ops_multi_update
ops_multi_update
ops_multi_update

Update multiple records.


Anchor
ops_oms_admin
ops_oms_admin
ops_oms_admin

Create, update, and delete OMS Servers.


Anchor
ops_peoplesoft_admin
ops_peoplesoft_admin
ops_peoplesoft_admin

Create, read, update, and delete PeopleSoft Connections.
 
(Also see PeopleSoft Connection Permissions, below.)


Anchor
ops_promotion_accept_bundle
ops_promotion_accept_bundle
ops_promotion_accept_bundle

Accept bundles being promoted to a target server. (The Accept Bundle command is executed on the target server automatically as part of the Promote and Promote Bundle commands and does not involve user interaction.)


Anchor
ops_promotion_admin
ops_promotion_admin
ops_promotion_admin


Note
titleNote
Note
titleNote

By default, the ops_promotion_admin role also grants Read permission for any type of definition that can be added to a Bundle, given the expectation that a promotion administrator would review the content of a Bundle before promoting it. To change this default behaviour, see the Promotion Read Permission Required Universal Controller property.

 
(Also see Bundle Permissions and Promotion Target Permissions, below.)

  • ops_promotion_accept_bundle

Anchor
ops_property_admin
ops_property_admin
ops_property_admin

Read, update, and delete Universal Controller system properties and Password Settings.


Anchor
ops_report_admin
ops_report_admin
ops_report_admin

report

visibility

Dashboards

Dashboards

The Strict Report Create Constraints Universal Controller system
  •  role.
  • Create, update, and delete Dashboard Details with Everyone visibility and Dashboard Details that are visible for a group in which this user is a member; updating includes updating Dashboard visibility.


The Strict Report Create Constraints Universal Controller system property specifies whether or not to restrict report creation only to users with the ops_admin, ops_report_admin, ops_report_group, or ops_report_global role.
 
The Strict Dashboard Create Constraints Universal Controller system property specifies whether or not to restrict Dashboard creation only to users with the ops_admin, ops_report_admin, ops_dashboard_group, or ops_dashboard_global role.

  • ops_dashboard_global
  • ops_dashboard_group
  • ops_report_global
  • ops_report_group
  • ops_report_publish
  • ops_widget_admin

Anchor
ops_report_global
ops_report_global
ops_report_global

Create global reports.


Anchor
ops_report_group
ops_report_group
ops_report_group

Create reports that belong to a group to which this user is a member.


Anchor
ops_report_publish
ops_report_publish
ops_report_publish

Publish reports. (This role was applicable only to the Controller 5.x release.)


Anchor
ops_restore_version
ops_restore_version
ops_restore_version

Restore old versions of records.


Anchor
ops_sap_admin
ops_sap_admin
ops_sap_admin

Create, read, update, and delete SAP Connections.
 
(Also see SAP Connection Permissions, below.)


Anchor
ops_server_operation_admin
ops_server_operation_admin
ops_server_operation_admin

Run Server Operations.


Anchor
ops_service
ops_service
ops_service

widget

  • role, the Audit tab on the Data Backup/Purge Details, which allows for conveniently viewing related Audit records, will not be available.
  • Read Users

Groups

  • and related data (Roles, Group Membership, and Permissions).
  • Update the User Details of the user.
  • Read Groups and related data (Roles, Group Membership, Child Groups, and Permissions).


Anchor
ops_snmp_admin
ops_snmp_admin
ops_snmp_admin

Create, read, update, and delete SNMP Managers, to which the Controller sends SNMP notifications.
 
(Also see SNMP Manager Permissions, below.)


Anchor
ops_sso_admin
ops_sso_admin
ops_sso_admin

Read and update Single Sign-On Settings.


Anchor
ops_universal_template_admin
ops_universal_template_admin
ops_universal_event_template_admin

Create, read, update, and delete Universal Event Templates.
  • ops_universal_event_template_view

Anchor
ops_universal_template_view
ops_universal_template_view
ops_universal_event_template_view

Read Universal Event Templates.

Anchor
ops_universal_usertemplate_admin
ops_useruniversal_template_admin
ops_universal_usertemplate_admin

Create, read, update, and delete users and groups. Universal Templates (including Universal Template Event Templates).

  • ops_universal_template_view

Anchor
ops_universal_widgettemplate_adminview
ops_widgetuniversal_template_adminview
ops_universal_widgettemplate_admin

Create,

view

Read Universal Templates (including Universal Template Event Templates).


Anchor
ops_user_admin
ops_user_admin
ops_user_admin

Create, read, update, and delete users and groups.


Anchor
ops_widget_admin
ops_widget_admin
ops_widget_admin

Create, update, and delete Widgets.


...

You can further narrow down which records each permission applies to by specifying either name parameters or Business Services. For example, a given permission might apply only to tasks whose name begins with "SF," or a permission might apply only to tasks that have been assigned to a specific Business Service or to tasks that do not belong to any Business Services. See General Permissions Field Descriptions, below, for more details.

To add permissions to a user or group:

...

Step 1

...

Open a User or Group record.

...

Step 2

Click the Permissions tab. A list of permissions assigned to the User / Group displays.
 
For Example:
 
Image Removed
 

...

titleNote

...

Step 3

...

Click New. The Permissions Details pop-up displays.
 
Image Removed

...

Step 4

...

Select permissions for the selected user or group.
 
The permissions available differ depending on the Type of permission that you select. Available permissions are Create, Read, Update, Delete, and Execute. For some record types, additional Commands are available. If the permission does not apply to the record type in the Type drop-down, the permission does not appear in the display.
 
These permissions automatically include other permissions:

  • Create permission includes Read and Update permissions.
  • Update permission includes Read permission.
  • Delete permission includes Read permission.

...

The following fields of information and buttons display in the Permissions Details for all Permission types:

...

Field Name

...

Description

...

Details

...

This section contains detailed information about the permission.

...

Applies this permission to records whose name matches the string specified here. Wildcards are supported.

...

Applies this permission both to records that belong to any Business Service and to records that do not belong to any Business Service.

...

Applies this permission to records that do not belong to any Business Service. If this option is enabled, the user / user group will have the defined permissions on all records that do not belong to any Business Service.

...

Applies this permission to records that are members of the selected Business Service(s). Click the lock icon to unlock the field and select Business Services.

...

Metadata

...

This section contains Metadata information about this record.

...

UUID

...

Universally Unique Identifier of this record.

...

Updated By

...

Name of the user that last updated this record.

...

Updated

...

Date and time that this record was last updated.

...

Created By

...

Name of the user that created this record.

...

Created

...

Date and time that this record was created.

...

Buttons

...

This section identifies the buttons displayed above and below the Permissions Details that let you perform various actions.

...

Save

...

Saves a new record in the Controller database.

...

Save & New

...

Saves a new record in the Controller database and redisplays empty Details so that you can create another new record.

...

Update

...

Delete

...

Refresh

...

Refreshes any dynamic data displayed in the Details.

...

Close

...

For pop-up view only; closes the pop-up view of this record.

...

This section identifies the different types of permissions that you can add to a user or group.

...

Image Removed
 

...

Options

...

Description

...

Read

...

Grants permission to read an Agent definition.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

...

Update

...

Grants permission to update an Agent definition. (Only certain fields can be updated.)

...

Delete

...

Grants permission to delete an Agent.

...

Execute

...

Grants permission to execute a task on an Agent.

...

Commands

...

  • ALL: Grants permission to suspend and resume Agents.
  • Resume Agent: Grants permission to resume the ability of a suspended Agent to run tasks.
  • Suspend Agent: Grants permission to suspend the ability of an Agent to run tasks.

...

(You also can assign Agent Cluster Permissions to a user by assigning the ops_agent_cluster_admin role to the user.)

Image Removed
more details.

To add permissions to a user or group:

Step 1

Open a User or Group record.

Step 2

Click the Permissions tab. A list of permissions assigned to the User / Group displays.
 
For Example:
 
Image Added
 

Note
titleNote

Anchor
Member of Business Services
Member of Business Services
The Business Services column represents a virtual field whose value is determined by data from both the Member of Business Services field and the Member of Any Business Service or Unassigned field. If you want to apply a sort relating to the data in Business Services, you have to add either or both Member of Business Services and Member of Any Business Service or Unassigned fields as columns and apply the desired sort on either or both of them.


Step 3

Click New. The Permissions Details pop-up displays.
 
Image Added

Step 4

Select permissions for the selected user or group.
 
The permissions available differ depending on the Type of permission that you select. Available permissions are Create, Read, Update, Delete, and Execute. For some record types, additional Commands are available. If the permission does not apply to the record type in the Type drop-down, the permission does not appear in the display.
 
These permissions automatically include other permissions:

  • Create permission includes Read and Update permissions.
  • Update permission includes Read permission.
  • Delete permission includes Read permission.

Anchor
General Permissions Field Descriptions
General Permissions Field Descriptions
General Permissions Field Descriptions

The following fields of information and buttons display in the Permissions Details for all Permission types:

Field Name

Description

Details

This section contains detailed information about the permission.

Anchor
Name
Name
Name

Applies this permission to records whose name matches the string specified here. Wildcards are supported.

Anchor
Member of Any Business Service or Unassigned
Member of Any Business Service or Unassigned
Member of Any Business Service or Unassigned

Applies this permission both to records that belong to any Business Service and to records that do not belong to any Business Service.

Anchor
Unassigned to Business Service
Unassigned to Business Service
Unassigned to Business Service

Applies this permission to records that do not belong to any Business Service. If this option is enabled, the user / user group will have the defined permissions on all records that do not belong to any Business Service.

Anchor
Member of Business Services field
Member of Business Services field
Member of Business Services

Applies this permission to records that are members of the selected Business Service(s). Click the lock icon to unlock the field and select Business Services.

Metadata

This section contains Metadata information about this record.

UUID

Universally Unique Identifier of this record.

Updated By

Name of the user that last updated this record.

Updated

Date and time that this record was last updated.

Created By

Name of the user that created this record.

Created

Date and time that this record was created.

Buttons

This section identifies the buttons displayed above and below the Permissions Details that let you perform various actions.

Save

Saves a new record in the Controller database.

Save & New

Saves a new record in the Controller database and redisplays empty Details so that you can create another new record.

Update

Include Page
UC67:Update button
UC67:Update button

Delete

Include Page
UC67:Delete button
UC67:Delete button

Refresh

Refreshes any dynamic data displayed in the Details.

Close

For pop-up view only; closes the pop-up view of this record.

Anchor
Types of Permissions
Types of Permissions
Types of Permissions

This section identifies the different types of permissions that you can add to a user or group.

Anchor
Agent Permissions
Agent Permissions
Agent Permissions

Image Added
 

Options

Description

Read

Grants permission to read an Agent definition.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Agent definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent.

Execute

Grants permission to execute a task on an Agent.

Commands

  • ALL: Grants permission to suspend and resume Agents.
  • Resume Agent: Grants permission to resume the ability of a suspended Agent to run tasks.
  • Suspend Agent: Grants permission to suspend the ability of an Agent to run tasks.

Anchor
Agent Cluster Permissions
Agent Cluster Permissions
Agent Cluster Permissions

(You also can assign Agent Cluster Permissions to a user by assigning the ops_agent_cluster_admin role to the user.)

Image Added
 

Options

Description

Create

Grants permission to create a new Agent Cluster.

Read

Grants permission to read an Agent Cluster definition.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent Cluster.

Commands

  • ALL: Grants permission to issue any command.
  • Resume Agent Cluster: Grants permission to resume the ability of a suspended Agent Cluster to run tasks.
  • Suspend Agent Cluster: Grants permission to suspend the ability of an Agent Cluster to run tasks.
  • Resume Agent Cluster Membership: Grants permission to resume the membership of an Agent in an Agent Cluster.
  • Suspend Agent Cluster Membership: Grants permission to suspend the membership of an Agent from an Agent Cluster.
  • Resolve Agent Cluster: Grants permission to resolve the Network Alias of an Agent Cluster with a Distribution type of Network Alias.

Anchor
Application Permissions
Application Permissions
Application Permissions

Image Added
 

Options

Description

Create

Grants permission to create a new Application.

Read

Grants permission to read an Application.

Update

Grants permission to update an Application.

Delete

Grants permission to delete an Application.

Commands

See Application Control Tasks for details. Options:

  • ALL: Grants permission to execute a Start, Stop, and Query from the Application resource screen.
  • Start: Grants permission to execute a Start from the Application resource screen.
  • Stop: Grants permission to execute a Stop from the Application resource screen.
  • Query: Grants permission to execute a Query from the Application resource screen.

Anchor
Bundle Permissions
Bundle Permissions
Bundle Permissions

(You also can assign Bundle Permissions to a user by assigning the ops_bundle_admin role to the user.)

Image Added


Options

Description

Create

Grants permission to create a Bundle matching both the specified name wildcard and business service membership, including the use of the Create Bundle By Date and Create Bundle By Business Service commands.

Read

Grants permission to read a Bundle matching both the specified name wildcard and business service membership.

  • User can run a Bundle Report for a Bundle matching both the specified name wildcard and business service membership.
  • User can Read a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership.

Update

Grants permission to update a Bundle matching both the specified name wildcard and business service membership, including the use of the Add To Bundle command.

Delete

Grants permission to delete a Bundle matching both the specified name wildcard and business service membership.

Commands

  • ALL: Grants permission to issue any command.
  • Promote Bundle: Grants permission to promote a Bundle.

For the ALL or Promote Bundle command:

  • User can promote a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.
  • User can Cancel, Reschedule, or Delete a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.

Anchor
Calendar Permissions
Calendar Permissions
Calendar Permissions

Image Added
 

Options

Description

Create

Grants permission to create a new Agent ClusterCalendar.

Read

Grants permission to read an Agent Cluster definitiona Calendar.
 
The Read check box will be checked automatically if the the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.)

Delete

Grants permission to delete an Agent Cluster.

Commands

  • ALL: Grants permission to issue any command.
  • Resume Agent Cluster: Grants permission to resume the ability of a suspended Agent Cluster to run tasks.
  • Suspend Agent Cluster: Grants permission to suspend the ability of an Agent Cluster to run tasks.
  • Resume Agent Cluster Membership: Grants permission to resume the membership of an Agent in an Agent Cluster.
  • Suspend Agent Cluster Membership: Grants permission to suspend the membership of an Agent from an Agent Cluster.
  • Resolve Agent Cluster: Grants permission to resolve the Network Alias of an Agent Cluster with a Distribution type of Network Alias.

...

a Calendar.

Delete

Grants permission to delete a Calendar.

Commands

  • ALL: Grants permission to issue any command.
  • Copy Calendar: Grants permission to copy a Calendar.

Anchor
Credential Permissions
Credential Permissions
Credential Permissions

Image Added
 

Options

Description

Create

Grants permission to create a new Application.

Read

Grants permission to read an Application.

Credential.

Read

Grants permission to read a Credential.
 
The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

Update

Grants permission to update an Applicationa Credential.

Delete

Grants permission to delete an Applicationa Credential.

Commands

See Application Control Tasks for details. Options:

ALL:

Execute

(You also can assign Bundle Permissions to a user by assigning the ops_bundle_admin role to the user.)

Image Removed

Options

Description

Create

Grants permission to create a Bundle matching both the specified name wildcard and business service membership, including the use of the Create Bundle By Date and Create Bundle By Business Service commands.

Read

Grants permission to read a Bundle matching both the specified name wildcard and business service membership.

  • User can run a Bundle Report for a Bundle matching both the specified name wildcard and business service membership.
  • User can Read a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership.

Update

Grants permission to execute

a Start, Stop, and Query from the Application resource screen.
  • Start: Grants permission to execute a Start from the Application resource screen.
  • Stop: Grants permission to execute a Stop from the Application resource screen.
  • Query: Grants permission to execute a Query from the Application resource screen.
  • ...

    Grants permission to update a Bundle matching both the specified name wildcard and business service membership, including the use of the Add To Bundle commanda task that requires a Credential.

    Commands

    N/A

    Anchor
    Database Connection Permissions
    Database Connection Permissions
    Database Connection Permissions

    (You also can assign Database Connection Permissions to a user by assigning the ops_dba role to the user.)

    Image Added


    Options

    Description

    Create

    Grants permission to create a new Database Connection.

    Read

    Grants permission to read a Database Connection.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update a Database Connection.

    Delete

    Grants permission to delete a Database Connection.

    Execute

    Grants permission to execute a task that requires a Database Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Database Connection: Grants permissions to copy a Database Connection.
    • Test Connection: Grants permission to test a Database Connection.

    Anchor
    Email Connection Permissions
    Email Connection Permissions
    Email Connection Permissions

    (You also can assign Email Connection Permissions to a user by assigning the ops_email_admin role to the user.)

    Image Added


    Options

    Description

    Create

    Grants permission to create a new Email Connection.

    Read

    Grants permission to read an Email Connection.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update an Email Connection.

    Delete

    Grants permission to delete a Bundle matching both the specified name wildcard and business service membership.

    Commands

    For the ALL or Promote Bundle command:

    • User can promote a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.
    • User can Cancel, Reschedule, or Delete a Promotion Schedule associated with a Bundle matching both the specified name wildcard and business service membership, assuming the user has Read permission for the Bundle.

    ...

    an Email Connection.

    Execute

    Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Email Connection: Grants permissions to copy an Email Connection.
    • Test Connection: Grants permission to test an Email Connection.

    Anchor
    Email Template Permissions
    Email Template Permissions
    Email Template Permissions

    Image Added


    Options

    Description

    Create

    Grants permission to create a new CalendarEmail Template.

    Read

    Grants permission to read a Calendaran Email Template.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update a Calendaran Email Template.

    Delete

    Grants permission to delete a Calendaran Email Template.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy CalendarEmail Template: Grants permission to copy a Calendaran Email Template.

    Anchor

    ...

    OMS Server Permissions

    ...

    OMS Server Permissions

    ...

    OMS Server Permissions

    (You also can assign OMS Server Permissions to a user by assigning the ops_oms_admin role to the user.)

    Image Added


    Options

    Description

    Create

    Grants permission to create a new CredentialOMS Server.

    Read

    Grants permission to read a Credentialan OMS Server.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update an OMS Server.

    Delete

    Grants permission to delete an OMS Server.

    Commands

    • ALL: Grants permission to
    update a Credential
    • suspend and resume OMS Servers.

    Delete

    • Resume: Grants permission to
    delete a Credential.

    Execute

    Grants permission to execute a task that requires a Credential.

    Commands

    N/A

    ...

    • resume the connection of a suspended OMS Server.
    • Suspend: Grants permission to suspend the connection of an OMS Server.

    Anchor
    PeopleSoft Connection Permissions
    PeopleSoft Connection Permissions
    PeopleSoft Connection Permissions

    (You also can assign Database PeopleSoft Connection Permissions to a user by assigning the ops_peoplesoft_dbaadmin role to the user.)

    Image RemovedImage Added


    Options

    Description

    Create

    Grants permission to create a new Database PeopleSoft Connection.

    Read

    Grants permission to read a Database PeopleSoft Connection.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update a Database PeopleSoft Connection.

    Delete

    Grants permission to delete a Database PeopleSoft Connection.

    Execute

    Grants permission to execute a task that requires a Database PeopleSoft Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Database PeopleSoft Connection: Grants permissions permission to copy a Database Connection.Test Connection: Grants permission to test a Database PeopleSoft Connection.

    Anchor

    ...

    Promotion Target Permissions

    ...

    Promotion Target Permissions

    ...

    Promotion Target Permissions

    (You also can assign Email Connection Promotion Target Permissions to a user by assigning the ops_emailpromotion_admin role to the user.)

    Image RemovedImage Added


    Options

    Description

    Create

    Grants permission to create a new Email ConnectionPromotion Target matching both the specified name wildcard and business service membership.

    Read

    Grants permission to read an Email Connection.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is falsea Promotion Target matching both the specified name wildcard and business service membership.
     
    User can View Target Server Info for Promotion Target matching both the specified name wildcard and business service membership.

    Update

    Grants permission to update an Email Connectiona Promotion Target matching both the specified name wildcard and business service membership.

    Delete

    Grants permission to delete an Email Connection.a Promotion Target matching both the specified name wildcard and business service membership

    Execute

    Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)promote a Bundle using a Promotion Target matching both the specified name wildcard and business service membership, assuming the user has both Read permission and Promote Bundle command permission for the Bundle.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Email Connection: Grants permissions to copy an Email Connection.
    • Test ConnectionRefresh Target Agents: Grants permission to test an Email Connectionrefresh Target Agents.

    Anchor

    ...

    SAP Connection Permissions
    SAP Connection Permissions

    ...

    SAP Connection Permissions

    ...

    Image Removed(You also can assign SAP Connection Permissions to a user by assigning the ops_sap_admin role to the user.)

    Image Added


    Options

    Description

    Create

    Grants permission to create a new Email TemplateSAP Connection.

    Read

    Grants permission to read an Email TemplateSAP Connection.
     
    The Read check box will be checked automatically if the the Business Service Visibility Restricted Universal Controller system property is falsefalse.

    Update

    Grants permission to update an SAP Connection.

    UpdateDelete

    Grants permission to update delete an Email TemplateSAP Connection.

    DeleteExecute

    Grants permission to delete an Email Template.execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Email TemplateSAP Connection: Grants permission permissions to copy an Email TemplateSAP Connection.

    Anchor

    ...

    Script Permissions

    ...

    Script Permissions

    ...

    (You also can assign OMS Server Permissions to a user by assigning the ops_oms_admin role to the user.)

    ...

    Script Permissions

    Image Added
     

    Options

    Description

    Create

    Grants permission to create a new OMS ServerScript.

    Read

    Grants permission to read an OMS Server.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is falsea Script.

    Update

    Grants permission to update an OMS Servera Script.

    Delete

    Grants permission to delete an OMS Servera Script.

    CommandsExecute

    ALL:

    Grants permission to

    suspend and resume OMS Servers.Resume

    execute a Script contained by a task.

    Commands

    • ALL: Grants permission to resume the connection of a suspended OMS Serverissue any command.Suspend
    • Copy Script: Grants permission to suspend the connection of an OMS Servercopy a Script.

    Anchor

    ...

    SNMP Manager Permissions

    ...

    SNMP Manager Permissions

    ...

    SNMP Manager Permissions

    (You also can assign PeopleSoft Connection SNMP Manager Permissions to a user by assigning the ops_peoplesoftsnmp_admin role to the user.)

    Image RemovedImage Added


    Options

    Description

    Create

    Grants permission to create a new PeopleSoft ConnectionSNMP Manager.

    Read

    Grants permission to read a PeopleSoft Connectionan SNMP Manager.
     
    The Read check box will be checked automatically if the the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update a PeopleSoft Connectionan SNMP Manager.

    Delete

    Grants permission to delete a PeopleSoft Connectionan SNMP Manager.

    Execute

    Grants permission to execute a task that requires a PeopleSoft Connectionan SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    Commands

    • ALL: Grants permission to issue any command.
    • Copy PeopleSoft ConnectionSNMP Manager: Grants permission permissions to copy a PeopleSoft Connectionan SNMP Manager.

    Anchor

    ...

    (You also can assign Promotion Target Permissions to a user by assigning the ops_promotion_admin role to the user.)

    ...

    Task Permissions

    ...

    Task Permissions
    Task Permissions

    Image Added
     

    ...

    Image Removed
     

    Options

    Description

    Create

    Grants permission to create a new Script.

    Read

    Grants permission to read a Script.

    Update

    Grants permission to update a Script.

    Delete

    Grants permission to delete a Script.

    Execute

    Grants permission to execute a Script contained by a task.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Script: Grants permission to copy a Script.

    ...

    (You also can assign SNMP Manager Permissions to a user by assigning the ops_snmp_admin role to the user.)

    Image Removed

    ...

    Options

    ...

    Description

    ...

    Create

    ...

    Grants permission to create a new SNMP Manager.

    ...

    Read

    ...

    Grants permission to read an SNMP Manager.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    ...

    Update

    ...

    Grants permission to update an SNMP Manager.

    ...

    Delete

    ...

    Grants permission to delete an SNMP Manager.

    ...

    Execute

    ...

    Grants permission to execute a task that requires an SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    ...

    Commands

    ...

    • ALL: Grants permission to issue any command.
    • Copy SNMP Manager: Grants permissions to copy an SNMP Manager.

    ...

    Options

    Description

    Create

    Grants permission to create a Promotion Target matching both the specified name wildcard and business service membershipnew Task.

    Read

    Grants permission to read a Promotion Target matching both the specified name wildcard and business service membership.
     
    User can View Target Server Info for Promotion Target matching both the specified name wildcard and business service membership.

    Update

    Grants permission to update a Promotion Target matching both the specified name wildcard and business service membership.

    Delete

    Grants permission to delete a Promotion Target matching both the specified name wildcard and business service membership

    Execute

    Grants permission to promote a Bundle using a Promotion Target matching both the specified name wildcard and business service membership, assuming the user has both Read permission and Promote Bundle command permission for the Bundle.

    Commands

    • ALL: Grants permission to issue any command.
    • Refresh Target Agents: Grants permission to refresh Target Agents.

    ...

    (You also can assign SAP Connection Permissions to a user by assigning the ops_sap_admin role to the user.)

    Image Removed

    ...

    Options

    ...

    Description

    ...

    Create

    ...

    Grants permission to create a new SAP Connection.

    ...

    Read

    ...

    Grants permission to read an SAP Connection.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    ...

    Update

    ...

    Grants permission to update an SAP Connection.

    ...

    Delete

    ...

    Grants permission to delete an SAP Connection.

    ...

    Execute

    ...

    Grants permission to execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.)

    ...

    Commands

    ...

    • ALL: Grants permission to issue any command.
    • Copy SAP Connection: Grants permissions to copy an SAP Connection.

    a Task.

    Update

    Grants permission to update a Task.

    Delete

    Grants permission to delete a Task.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Task: Grants permission to copy a Task.
    • Launch: Grants permission to launch a Task.
    • Recalculate Forecast: Grants permission to recalculate a forecast.
    • Reset Statistics: Grants permission to reset statistics, including statistics being tracked by each parent Workflow of a Task.
    • Reset z/OS Override Statistics: Grants permission to reset z/OS override statistics.
    • Set Execution Restriction: Grants permission to set an execution restriction for a task in a workflow.

    Anchor
    Task Instance Permissions
    Task Instance Permissions
    Task Instance Permissions

    Image Added
     

    Options

    Description

    Create

    Task instances are created automatically when the task launches, so the Create permission does not appear.

    Read

    Grants permission to read a Task Instance

    Update

    Grants permission to update certain fields on a Task Instance.

    Delete

    Grants permission to delete a Task Instance.

    Commands

    For command descriptions, see Manually Running and Controlling Tasks.

    • ALL: Grants permission to issue any command.
    • Cancel: Grants permission to cancel a Task Instance.
    • Clear All Dependencies: Grants permission to clear all dependencies on a Task Instance.
    • Clear Predecessors: Grants permission to clear all predecessors on a Task Instance.
    • Clear Exclusive: Grants permission to clear all mutual exclusive dependencies from a Task Instance.
    • Clear Resources: Grants permission to clear all resource dependencies of a Task Instance.
    • Clear Time Wait/Delay: Grants permission to clear all Wait To Start and Delay On Start specifications for a Task Instance.
    • Force Finish: Grants permission to force finish a Task Instance.
    • Force Finish/Cancel: Grants permission to force finish/cancel a Task Instance.
    • Hold: Grants permission to put a Task Instance on hold.
    • Insert Task: Grants permission to insert a task on the workflow monitor of a workflow Task Instance.
    • Mark as Satisfied: Can mark a dependency as satisfied.
    • Re-run: Grants permission to re-run a Task Instance.
    • Release: Grants permission to release a Task Instance from hold.
    • Release Recursive: Grants permission to release a workflow and all its tasks from hold.
    • Retrieve Output: Grants permission to execute the Retrieve Output button.
    • Set Priority Low: Grants permission to change the priority of a task to Low.
    • Set Priority Medium: Grants permission to change the priority of a task to Medium.
    • Set Priority High: Grants permission to change the priority of a task to High.
    • Set Completed: Grants permission to set a Manual Task Instance status to completed.
    • Set Started: Grants permission to set a Manual Task Instance status to a new started time.
    • Skip: Grants permission to skip a Task Instance.
    • Unskip: Grants permission to unskip a Task Instance selected to be skipped.
    Note
    titleNote

    Universal Controller will initially check for command permission specifically for the task instance.

    If no command permission is granted for the task instance, Universal Controller will check if command permission is granted for the parent workflow task instance, and then continue to check for command permission up the workflow task instance hierarchy.


    Anchor
    Trigger Permissions
    Trigger Permissions
    Trigger Permissions

    Image Added
     

    Options

    Description

    Create

    Grants permission to create a new TaskTrigger.

    Read

    Grants permission to read a TaskTrigger.

    Update

    Grants permission to update a TaskTrigger.

    Delete

    Grants permission to delete a Task.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Task: Grants permission to copy a Task.
    • Launch: Grants permission to launch a Task.
    • Recalculate Forecast: Grants permission to recalculate a forecast.
    • Reset Statistics: Grants permission to reset statistics, including statistics being tracked by each parent Workflow of a Task.
    • Reset z/OS Override Statistics: Grants permission to reset z/OS override statistics.
    • Set Execution Restriction: Grants permission to set an execution restriction for a task in a workflow.

    ...

    Image Removed
     

    ...

    Options

    ...

    Description

    ...

    Create

    ...

    Task instances are created automatically when the task launches, so the Create permission does not appear.

    ...

    Read

    ...

    Grants permission to read a Task Instance

    ...

    Update

    ...

    Grants permission to update certain fields on a Task Instance.

    ...

    Delete

    ...

    Grants permission to delete a Task Instance.

    ...

    Commands

    ...

    For command descriptions, see Manually Running and Controlling Tasks.

    Note
    titleNote

    Universal Controller will initially check for command permission specifically for the task instance.

    If no command permission is granted for the task instance, Universal Controller will check if command permission is granted for the parent workflow task instance, and then continue to check for command permission up the workflow task instance hierarchy.

    ...

    Image Removed
     

    Options

    Description

    Create

    Grants permission to create a Trigger.

    Read

    Grants permission to read a Trigger.

    Update

    Grants permission to update a Trigger.

    Delete

    Grants permission to delete a Trigger.

    Commands

  • ALL: Grants permission to issue any command.
  • Assign Execution User: Grants permission to override the execution user of task instances launched by a Trigger.
  • Copy Trigger: Grants permission to copy a Trigger.
  • Disable Trigger: Grants permission to disable a Trigger.
  • Enable Trigger: Grants permission to enable a Trigger.
  • Recalculate Forecast: Grants permission to recalculate a forecast.
  • Set Skip Count: Grants permission to perform a Set Skip Count action with/without Update permission.  
  • Trigger Now: Grants permission to Trigger (launch) a task.

    Trigger.

    Commands

    • ALL: Grants permission to issue any command.
    • Assign Execution User: Grants permission to override the execution user of task instances launched by a Trigger.
    • Copy Trigger: Grants permission to copy a Trigger.
    • Disable Trigger: Grants permission to disable a Trigger.
    • Enable Trigger: Grants permission to enable a Trigger.
    • Recalculate Forecast: Grants permission to recalculate a forecast.
    • Set Skip Count: Grants permission to perform a Set Skip Count action with/without Update permission.  
    • Trigger Now: Grants permission to Trigger (launch) a task.

    Anchor
    Universal Event Permissions
    Universal Event Permissions
    Universal Event Permissions

    The authorization for publishing and monitoring Universal Events is separate from the Universal Event Template administration and requires the Universal Event permission.

    The permission Name wildcard applies to the published Universal Event Name.

    The Name of a published global Universal Event is derived from the Universal Event Template Name.

    The Name of a published local Universal Event is derived from the Universal Template Name and the Universal Template Event Template Name.
             <template-name>.<event-template-name>

    The permission Member of Any Business Service or Unassigned, Unassigned to Business Service, and Member of Business Services applies to the published Universal Event Member of Business Services.

    For a global Universal Event published through the Web Service API, the publisher optionally specifies the Member of Business Services.

    For a local Universal Event published by a Universal Task Instance Extension, the Universal Event inherits the Universal Task Instance Member of Business Services.

    Image Added


    Options

    Description

    Create

    Grants permission to publish Universal Events.

    Read

    Grants permission to monitor Universal Events.

    Commands

    -- None --

    Anchor
    Variable Permissions
    Variable Permissions
    Variable Permissions

    ...

    By default, enhanced global variable security is enabled; the Variable Security Enabled Universal Controller system property is set to true.

    ...

    All defined Variable permissions will be enforced unless enhanced global variable security has been disabled by setting Variable Security Enabled to false. This allows all global variables to be managed and used by any valid Universal Controller user.

    ...

    Options

    Description

    Create

    Grants permission to create a virtual resource.

    Read

    Grants permission to read a virtual resource.
     
    The Read check box will be checked automatically if the Business Service Visibility Restricted Universal Controller system property is false.

    Update

    Grants permission to update a virtual resource.

    Delete

    Grants permission to delete a virtual resource.

    Execute

    Grants permission to execute a virtual resource.

    Commands

    • ALL: Grants permission to issue any command.
    • Copy Virtual Resource: Grants permission to copy a Virtual Resource.

    ...

    By default, enhanced virtual resource security is enabled; the Virtual Resource Security Enabled Universal Controller system property is set to true.

    ...

    All defined Virtual Resource permissions will be enforced unless enhanced virtual resource security has been disabled by setting Virtual Resource Security Enabled to false. This allows all virtual resources to be managed and used by any valid Universal Controller user.

    ...

    The Controller lets you export user groups and their permissions, which then can be imported into another Controller system. Only the permissions listed under the Permissions tab for each group will be exported.
     

    Step 1

    From the Administration navigation pane, select Security > Groups. The Groups list displays.

    Step 2

    As desired, filter the list to select the group(s) whose permissions you want to export. When you perform the export, all groups matching the filter will be exported.

    Step 3

    Access the Action menu and select Export > Permissions For Group.
     

    ...