Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Panel
Table of Contents
maxlevel2

...

Step 1

From the Administration navigation pane, select Security > Users. The Users list displays a list of all currently defined users.
 
To the right of the list, User Details for a new user displays.
 

Step 2

Enter/select Details for a new user, using the field descriptions below as a guide.

  • Required fields display an asterisk ( * ) after the field name.
  • Default values for fields, if available, display automatically.

To display more of the Details fields on the screen, you can either:

  • Use the scroll bar.
  • Temporarily hide the list above the Details.
  • Click the New button above the list to display a pop-up version of the Details.

Step 3

Optionally, assign one or more roles to the user, assign the user to a group, or assign permissions to this user.

Step 4

Click a Save button. The user is added to the database, and all buttons and tabs in the User Details are enabled.

...

Note
titleNote

To open an existing record on the list, either:

  • Click a record in the list to display its record Details below the list. (To clear record Details below the list, click the New button that displays above and below the Details.)
  • Clicking the Details icon next to a record name in the list, or right-click a record in the list and then click Open in the Action menu that displays, to display a pop-up version of the record Details.
  • Right-click a record in the a list, or open a record and right-click in the record Details, and then click Open In Tab in the Action menu that displays, to display the record Details under a new tab on the record list page (see Record Details as Tabs).

...

The following details identifies the roles and permissions required to read and update user details.

RolesPermissionsFields
  • ops_admin
  • ops_user
-
  • _admin
  • Read any user.
  • Edit any user.
  • All
  • ops_service_role
  • Read any user.
  • Update specific fields in its own details (see Fields).
  • First Name

  • Middle Name

  • Last Name

  • Email

  • Time Zone

  • Title

  • Department

  • Business Phone

  • Mobile Phone
    • ops_service
    • Read any user.

    • none
    • Read its own user record (details).
    • Read its own Role, Permissions, and Member of Groups (group membership),
      but cannot read any Group record.
    • Update specific fields in its own details (see Fields).
    • First Name

    • Middle Name

    • Last Name

    • Email

    • Time Zone

    • Title

    • Department

    • Business Phone

    • Mobile Phone


    The following User Details is for an existing user. See the field descriptions, below, for a description of all fields that display in the User Details.

    ...

    Web Browser

    Field Name

    Description

    Details

    This section contains detailed information about the user.

    Anchor
    User ID
    User ID
    User ID

    Log in ID for this user.

    Anchor
    Password
    Password
    Password

    Password of this user.

    Note
    titleNote

    The hint for this field, as well as the information icon, will display any current characteristics and restrictions for Passwords as defined in Password Settings.


    Anchor
    First Name
    First Name
    First Name

    First name of this user.

    Anchor
    Middle Name
    Middle Name
    Middle Name

    Middle name of this user.

    Anchor
    Last Name
    Last Name
    Last Name

    Last name of this user.

    Anchor
    Name
    Name
    Name

    Automatically generated from the 63586153 First Name and 63586153 Last Name of this user.

    Anchor
    Email
    Email
    Email

    Email address of this user.

    Anchor
    Password Requires Reset
    Password Requires Reset
    Password Requires Reset

    If enabled, the user will be prompted to reset the password at next login.

    Anchor
    Locked Out
    Locked Out
    Locked Out

    If enabled, locks out the user. This field is enabled automatically if the maximum number of successive failed login attempts has been reached by the user.

    Anchor
    Login Method
    Login Method
    Login Method

    Login method(s) that the user can authenticate with. (You can use the Ctrl key to select both methods.)
     
    Options:

    • Standard
    • Single Sign-On

    Anchor
    Time Zone
    Time Zone
    Time Zone

    Time zone of this user. When this user logs in, all scheduling times will be shown in the user's time zone, unless the trigger specifies a different time zone.

    Anchor
    Title
    Title
    Title

    Business title title of this user.

    Anchor
    Department
    Department
    Department

    Business department of this user.

    Anchor
    Manager
    Manager
    Manager

    Business manager of this user.

    Anchor
    Business Phone
    Business Phone
    Business Phone

    Business phone number of this user.

    Anchor
    DepartmentMobile PhoneDepartment
    Mobile Phone
    Department

    Business department

    Mobile Phone

    Mobile phone number of this user.

    Mobile phone number of this user.

    Anchor
    Web Browser AccessWeb Browser Access
    Anchor
    ManagerManager
    Manager

    Business manager of this user.

    AnchorBusiness PhoneBusiness PhoneBusiness Phone

    Business phone number of this user.

    AnchorMobile PhoneMobile PhoneMobile Phone

    Web Browser Access
    Web Browser Access
    Web Browser Access

    Specifies whether or not the user can log in to the user interface.
     
    Options:

    • System Default - User restriction for logging in to the user interface is based on the current system default value of the System Default Web Browser Access Universal Controller system property.
    • Yes - User is not restricted from logging in to the user interface.
    • No - User is restricted from logging in to the user interface.

    Anchor
    Command Line Access
    Command Line Access
    Command Line Access

    Specifies whether or not the user can log in to the user interfaceUniversal Controller Command Line Interface (CLI).
     
    Options:

    • System Default - User restriction for logging in to the user interface CLI is based on the current system default value of the System Default Web Browser Command Line Access Universal Controller system property.
    • Yes - User is not restricted from logging in to the user interfaceCLI.
    • No - User is restricted from logging in to the user interfaceCLI.

    Anchor
    Command Line Web Service AccessCommand Line
    Web Service Access
    Command Line Web Service Access

    Specifies whether or not the user can log in to the Universal Controller Command Line Interface (CLI) RESTful Web Services API.
     
    Options:

    • System Default - User restriction for logging in to the CLI Universal Controller Web Services is based on the current system default value of the System Default Command Line Web Service Access Universal Controller system property.
    • Yes - User is not restricted from logging in to the CLIUniversal Controller Web Services.
    • No - User is restricted from logging in to the CLIUniversal Controller Web Services.
    AnchorActiveActiveActiveIf enabled, the user ID is active and the user can log in. If disabled, the user is deactivated; the user will not appear in user lists and cannot be used for access to the Controller.

    Anchor
    Web Service AccessWeb Service Access
    Web Service Access

    Specifies whether or not the user can log in to the Universal Controller RESTful Web Services API.
     
    Options:

    • System Default - User restriction for logging in to the Universal Controller Web Services is based on the current system default value of the System Default Web Service Access Universal Controller system property.
    • Yes - User is not restricted from logging in to the Universal Controller Web Services.
    • No - User is restricted from logging in to the Universal Controller Web Services.

    Active
    Active
    Active

    If enabled, the user ID is active and the user can log in. If disabled, the user is deactivated; the user will not appear in user lists and cannot be used for access to the Controller.

    Personal Access Tokens This section contains assorted detailed information about the applications that will access the Universal Controller Web Service APIs using the personal access token. Expiration Specifies when the personal access token expires. If left unspecified, the token never expires.
    Anchor
    User Impersonation
    User Impersonation
    User Impersonation

    This section specifies the users that can be impersonated by this user on Universal Controller Web Service requests. 

    Allowed Impersonation Users

    Specifies the users that can be impersonated by this user using the X-Impersonate-User HTTP header on Web Service requests.

    User impersonation requires the ops_user_impersonate role.

    Users with the ops_admin role can impersonate any user and do not need to specify Allowed Impersonation Users. 

    Metadata

    This section contains Metadata information about this record.

    UUID

    Universally Unique Identifier of this record.

    Updated By

    Name of the user that last updated this record.

    Updated

    Date and time that this record was last updated.

    Created By

    Name of the user that created this record.

    Created

    Date and time that this record was created.

    Buttons

    This section identifies the buttons displayed above and below the User Details that let you perform various actions.

    Save

    Saves a new user record in the Controller database.

    Save & New

    Saves a new record in the Controller database and redisplays empty Details so that you can create another new record.

    Save & View

    Saves a new record in the Controller database and continues to display that record.

    New

    Displays empty (except for default values) Details for creating a new record.

    Update

    Include Page
    IL:Update button
    IL:Update button

    Delete

    Include Page
    IL:Delete button
    IL:Delete button

    Refresh

    Refreshes any dynamic data displayed in the Details.

    Close

    For pop-up view only; closes the pop-up view of this user.

    Tabs

    This section identifies the tabs across the top of the User Details that provide access to additional information about the user.

    User Roles

    Allows you to assign roles to this user.

    Member of Groups

    Allows you to assign this user to one or more groups.

    Note
    titleNote

    Universal Controller only supports a user being a member of 1,000 groups or less.


    Permissions

    Allows you to assign permissions to this user.

    ...

    Step 1

    From the Administration navigation pane, select Security > Groups. The Groups list displays a list of all currently defined groups.
     
    To the right of the list, Group Details for a new group displays.
     

    Step 2

    Enter/select Details for a new group, using the field descriptions below as a guide.

    • Required fields display an asterisk ( * ) after the field name.
    • Default values for fields, if available, display automatically.

    To display more of the Details fields on the screen, you can either:

    • Use the scroll bar.
    • Temporarily hide the list above the Details.
    • Click the New button above the list to display a pop-up version of the Details.

    Step 3

    Optionally, assign one or more roles to the group, assign members (users) to the group, assign other groups to this group, or assign permissions to this group.

    Step 4

    Click a Save button. The group is added to the database, and all buttons and tabs in the Group Details are enabled.

    ...

    Note
    titleNote

    To open an existing record on the list, either:

    • Click a record in the list to display its record Details below the list. (To clear record Details below the list, click the New button that displays above and below the Details.)
    • Clicking the Details icon next to a record name in the list, or right-click a record in the list and then click Open in the Action menu that displays, to display a pop-up version of the record Details.
    • Right-click a record in the a list, or open a record and right-click in the record Details, and then click Open In Tab in the Action menu that displays, to display the record Details under a new tab on the record list page (see Record Details as Tabs).

    ...

    The following Group Details is for an existing group. See the field descriptions, below, for a description of all fields that display in the Group Details.
     

    ...

    Field Name

    Description

    Details

    This section contains detailed information about the group.

    Anchor
    Group Name
    Group Name
    Name

    Name of this group.

    Parent

    Name of this group's parent group, if any.

    Description

    Include Page
    IL:Summary
    IL:Summary

    Email

    Email address for this group.

    Manager

    Universal Controller user that is the manager of this group.

    Anchor
    Control Navigation Visibility
    Control Navigation Visibility
    Control Navigation Visibility

    Indication of whether or not to control the visibility of navigation pane entries in the Controller Services, via the Navigation Visibility field, for members of this Group. If Control Navigation Visibility is not checked (the default selection), all entries are visible.

    Anchor
    Navigation Visibility
    Navigation Visibility
    Navigation Visibility

    If Control Navigation Visibility is enabled; Drop-down list of all Navigator entries.
     
    You can manually select and deselect any entry on the list. You also can click Check All above the list to make all Navigator entries visible to users in this Group, or click Uncheck All above the list to hide all Navigator entries from users in this Group.
     

    Note
    titleNote

    If a new Navigation Visibility entry becomes available (for example, when a new Universal Task type has been created) after an administrator has configured the Navigation Visibility feature for a Group, you must explicitly add that new entry to the configuration.

    If a newly created Universal Task type does not appear as an entry in the Navigation Visibility drop-down list, confirm that the Universal Template has at least one field defined, perform the Refresh Navigation Tree operation, and refresh the Group Details (or refresh the Groups list).

    When a Universal Template is deleted, any Navigation Visibility configuration with a reference to its corresponding Universal Task type entry will automatically have that entry removed.


    Metadata

    This section contains Metadata information about this record.

    UUID

    Universally Unique Identifier of this record.

    Updated By

    Name of the user that last updated this record.

    Updated

    Date and time that this record was last updated.

    Created By

    Name of the user that created this record.

    Created

    Date and time that this record was created.

    Buttons

    This section identifies the buttons displayed above and below the Group Details that let you perform various actions.

    Save

    Saves a new group record in the Controller database.

    Save & New

    Saves a new record in the Controller database and redisplays empty Details so that you can create another new record.

    Save & View

    Saves a new record in the Controller database and continues to display that record.

    New

    Displays empty (except for default values) Details for creating a new record.

    Update

    Include Page
    IL:Update button
    IL:Update button

    Copy

    Creates a copy of this Group, which you are prompted to rename.

    Delete

    Include Page
    IL:Delete button
    IL:Delete button

    Refresh

    Refreshes any dynamic data displayed in the Details.

    Close

    For pop-up view only; closes the pop-up view of this group.

    Tabs

    This section identifies the tabs across the top of the Group Details that provide access to additional information about the user.

    Group Roles

    Allows you to assign roles to this group.

    Group Members

    Allows you to assign users to this group.

    Note
    titleNote

    Universal Controller only supports a user being a member of 1,000 groups or less.


    Child Groups

    Allows you to assign other groups to this group.

    Permissions

    Allows you to assign permissions to this group.

    ...

    Step 1

    Open the User or Group record.

    Step 2

    Click the Group Members tab.
     
    For a User, a list of all groups to which the user is assigned displays:
     

     
    For a Group, a list of all users assigned to the group displays.
     

    Step 3

    For a User, either:

    • Click New to create a Group and automatically assign the User to it.
    • Click Edit to display an Edit Members pop-up that allows you to assign the User to existing Groups.


     
    For a Group, either:

    • Click New to create a User and automatically assign it to the Group.
    • Click Edit to display an Edit Members pop-up that allows you to assign existing Users to the Group.

    Step 4

    To filter the Users/Groups listed in the Collection window, enter characters in the text field above the Name column. Only Users/Groups containing that sequence of characters will display in the list.

    Step 5

    To assign a User to a Group, move the User/Group from the Collection window to the List window:

    1. To move a single entry, double-click it or click it once and then click the > arrow.
    2. To move multiple entries, Ctrl-click them and then click the > arrow.
    3. To move all entries, click the >> arrow.

    To unassign the User to a Group, move the User/Group from the List window to the Collection window:

    1. To move a single entry, double-click it or click it once and then click the < arrow.
    2. To move multiple entries, Ctrl-click them and then click the < arrow.
    3. To move all entries, click the << arrow.

    Step 6

    Click Save.

    ...

    Users with the ops.admin role or the ops_user_admin role can control, via the 63586153 and 63586153 Control Navigation Visibility and Navigation Visibility fields in the 63586153 Group Details for a Group, which entries in the Controller Services are visible to users in that Group.

    ...

    User in Multiple Groups

    If a user belongs to multiple Groups, and for any of those Groups the 63586153 Control Navigation Visibility is not enabled, Navigator visibility for that user is not controlled.

    User in Multiple Groups

    If a user belongs to multiple Groups, and for all of those Groups navigation visibility has been deselected for one or more entries, the visible entries from all Groups will be merged. That is, if an entry is not visible to users in Group A, but the entry is visible to users in Group B, the entry will be visible to any user belonging to both Groups.

    Navigation Pane

    If all entries in a folder of a navigation pane (for example, the Tasks folder in the Automation Center navigation pane) are not visible to a Group, that folder does not display for any user in that Group.

    Navigation Pane

    If all entries in a navigation pane are not visible to a Group, that navigation pane does not display for any user in that Group.

    Automation Center Navigation Pane

    If a Group does not have visibility to one or more entries in the configurable Automation Center navigation pane, those entries are not available for configuration for any user in that Group.

    Trigger Types / Task Types

    If a Group does not have visibility to a specific Trigger type or Task type, that Trigger type or Task type does not display in the New drop-down menu on the All Triggers list or the All Tasks list for any user in that Group.

    Universal Task Types

    Dynamically created Universal Task type entries are available for selection / deselection in the 63586153 Navigation Visibility field.

    User Roles

    The role selections for any user override any navigation visibility selections for any Group in which that user is a member.

    User Roles

    Navigation visibility selections for a Group do not apply to any users in the Group with the ops_admin role.

    ...

    If deletion of a user is allowed, the following information associated with the user record also will be deleted:

    ...

    record also will be deleted:

    • User roles.
    • User permissions.
    • Group memberships.
    • User's filters.
    • User's pinned filter preferences.
    • User's layout preferences.
    • User's navigation preferences.
    • User's reports (reports made visible only to that user).
    • User's user preferences.
    • User's dashboards.

    Anchor
    impersonation
    impersonation

    Impersonating a User

    Users with the ops_admin role, the ops_user_admin role, or the ops_user_impersonate role are able to specify an X-Impersonate-User HTTP header, in additional to their authentication header/parameter, when invoking Universal Controller Web Service APIs.

    The X-Impersonate-User HTTP header is specified as the User Id of the user to be impersonated.

    Users with the ops_admin role can impersonate any user.

    Users with only the ops_user_admin role or the ops_user_impersonate role must explicitly declare which users can be impersonated in the Allowed Impersonation Users field.