...
Role Name | Available Functions | Contains Roles | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| All functions; this is the Universal Controller administrator role. The easiest way to assign full permissions to a user is to add the user to the Administrator Group, which by default is assigned the ops_admin role.
| The ops_admin role contains all other roles. | |||||||||||
| Create, read, update, and delete agent clusters. | ||||||||||||
| Read all Audits.
| ||||||||||||
|
(Also see Bundle Permissions and Promotion Target Permissions, below.) | ||||||||||||
| Create, update, and delete Dashboard Details with Everyone visibility; updating includes updating Dashboard visibility. | ||||||||||||
| Create, update, and delete Dashboard Details that are visible for one or more to any of the groups in which the user is a member of; updating includes updating Dashboard visibility. | ||||||||||||
| Create, update, delete Database Connections. | ||||||||||||
| Create, read, update, delete Email Connections. | ||||||||||||
| Create Filters with Everyone visibility. | ||||||||||||
| Create Filters that belong to a group of which this user is a member. | ||||||||||||
| Read Forecast Calendar, Forecasts List, and Forecast Details.
| ||||||||||||
| List Import/Export XML. | ||||||||||||
| Modify the JCL contents and update it. |
| |||||||||||
| Submit the JCL view request to the agent and view the contents of it. | ||||||||||||
| Read and update LDAP Settings. | ||||||||||||
| |||||||||||||
ops_oauth_admin | Create, read, update, and delete OAuth Clients. | ||||||||||||
| Create, update, and delete OMS Servers. | ||||||||||||
| Create, read, update, and delete PeopleSoft Connections. | ||||||||||||
| Accept bundles being promoted to a target server. (The Accept Bundle command is executed on the target server automatically as part of the Promote and Promote Bundle commands and does not involve user interaction.) | ||||||||||||
|
|
| |||||||||||
| Read, update, and delete Universal Controller system properties and Password Settings. | ||||||||||||
|
The Strict Report Create Constraints Universal Controller system property specifies whether or not to restrict report creation only to users with the ops_admin, ops_report_admin, ops_report_group, or ops_report_global role. |
| |||||||||||
| Create global reports. | ||||||||||||
| Create reports that belong to a group to which this user is a member. | ||||||||||||
| Publish reports. (This role was applicable only to the Controller 5.x release.) | ||||||||||||
| Restore old versions of records. | ||||||||||||
| Create, read, update, and delete SAP Connections. | ||||||||||||
| Run Server Operations. | ||||||||||||
|
| ||||||||||||
ops_simulation_view | Read Simulation records. | ||||||||||||
| Create, read, update, and delete SNMP Managers, to which the Controller sends SNMP notifications. | ||||||||||||
| Read and update SAML Single Sign-On and OAuth Single Sign-On Settings. | ||||||||||||
| Create, read, update, and delete Universal Event Templates. |
| |||||||||||
| Read Universal Event Templates. | ||||||||||||
| Create, read, update, and delete Universal Templates (including Universal Template Event Templates). |
| |||||||||||
| Read Universal Templates (including Universal Template Event Templates). | ||||||||||||
| Create, read, update, and delete users and groups. |
| |||||||||||
| Allows an authenticated user to impersonate another user by using the X-Impersonate-User HTTP header on a Web Service request. | ||||||||||||
ops_webhook_admin |
| ||||||||||||
ops_webhook_view | Read Webhooks. | ||||||||||||
| Create, update, and delete Widgets. |
...
Anchor | ||||
---|---|---|---|---|
|
Options | Description | ||
---|---|---|---|
Read | Grants permission to read an Agent definition.
| ||
Update | Grants permission to update an Agent definition. (Only certain fields can be updated.) | ||
Delete | Grants permission to delete an Agent. | ||
Execute | Grants permission to execute a task on an Agent. | ||
Commands |
|
...
(You also can assign Agent Cluster Permissions to a user by assigning the ops_agent_cluster_admin role to the user.)
Options | Description | ||
---|---|---|---|
Create | Grants permission to create a new Agent Cluster. | ||
Read | Grants permission to read an Agent Cluster definition.
| ||
Update | Grants permission to update an Agent Cluster definition. (Only certain fields can be updated.) | ||
Delete | Grants permission to delete an Agent Cluster. | ||
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Application. |
Read | Grants permission to read an Application. |
Update | Grants permission to update an Application. |
Delete | Grants permission to delete an Application. |
Commands | See Application Control Tasks for details. Options:
|
...
(You also can assign Bundle Permissions to a user by assigning the ops_bundle_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a Bundle matching both the specified name wildcard and business service membership, including the use of the Create Bundle By Date and Create Bundle By Business Service commands. |
Read | Grants permission to read a Bundle matching both the specified name wildcard and business service membership.
|
Update | Grants permission to update a Bundle matching both the specified name wildcard and business service membership, including the use of the Add To Bundle command. |
Delete | Grants permission to delete a Bundle matching both the specified name wildcard and business service membership. |
Commands |
For the ALL or Promote Bundle command:
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Calendar. |
Read | Grants permission to read a Calendar. |
Update | Grants permission to update a Calendar. |
Delete | Grants permission to delete a Calendar. |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Credential. |
Read | Grants permission to read a Credential. |
Update | Grants permission to update a Credential. |
Delete | Grants permission to delete a Credential. |
Execute | Grants permission to execute a task that requires a Credential. |
CommandsN/A |
|
Anchor | ||||
---|---|---|---|---|
|
(You also can assign Database Connection Permissions to a user by assigning the ops_dba role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new Database Connection. |
Read | Grants permission to read a Database Connection. |
Update | Grants permission to update a Database Connection. |
Delete | Grants permission to delete a Database Connection. |
Execute | Grants permission to execute a task that requires a Database Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
...
(You also can assign Email Connection Permissions to a user by assigning the ops_email_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new Email Connection. |
Read | Grants permission to read an Email Connection. |
Update | Grants permission to update an Email Connection. |
Delete | Grants permission to delete an Email Connection. |
Execute | Grants permission to execute a task that requires an Email Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Email Template. |
Read | Grants permission to read an Email Template. |
Update | Grants permission to update an Email Template. |
Delete | Grants permission to delete an Email Template. |
Commands |
|
...
(You also can assign OMS Server Permissions to a user by assigning the ops_oms_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new OMS Server. |
Read | Grants permission to read an OMS Server. |
Update | Grants permission to update an OMS Server. |
Delete | Grants permission to delete an OMS Server. |
Commands |
|
...
(You also can assign PeopleSoft Connection Permissions to a user by assigning the ops_peoplesoft_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new PeopleSoft Connection. |
Read | Grants permission to read a PeopleSoft Connection. |
Update | Grants permission to update a PeopleSoft Connection. |
Delete | Grants permission to delete a PeopleSoft Connection. |
Execute | Grants permission to execute a task that requires a PeopleSoft Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
...
(You also can assign Promotion Target Permissions to a user by assigning the ops_promotion_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a Promotion Target matching both the specified name wildcard and business service membership. |
Read | Grants permission to read a Promotion Target matching both the specified name wildcard and business service membership. |
Update | Grants permission to update a Promotion Target matching both the specified name wildcard and business service membership. |
Delete | Grants permission to delete a Promotion Target matching both the specified name wildcard and business service membership |
Execute | Grants permission to promote a Bundle using a Promotion Target matching both the specified name wildcard and business service membership, assuming the user has both Read permission and Promote Bundle command permission for the Bundle. |
Commands |
|
...
(You also can assign SAP Connection Permissions to a user by assigning the ops_sap_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new SAP Connection. |
Read | Grants permission to read an SAP Connection. |
Update | Grants permission to update an SAP Connection. |
Delete | Grants permission to delete an SAP Connection. |
Execute | Grants permission to execute a task that requires an SAP Connection. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Script Permissions
Options | Description |
---|---|
Create | Grants permission to create a new Script. |
Read | Grants permission to read a Script. |
Update | Grants permission to update a Script. |
Delete | Grants permission to delete a Script. |
Execute | Grants permission to execute a Script contained by a task. |
Commands |
|
...
(You also can assign SNMP Manager Permissions to a user by assigning the ops_snmp_admin role to the user.)
Options | Description |
---|---|
Create | Grants permission to create a new SNMP Manager. |
Read | Grants permission to read an SNMP Manager. |
Update | Grants permission to update an SNMP Manager. |
Delete | Grants permission to delete an SNMP Manager. |
Execute | Grants permission to execute a task that requires an SNMP Manager. (Displays only if the Strict Connection Execute Constraints Universal Controller system property is true.) |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a new Task. |
Read | Grants permission to read a Task. |
Update | Grants permission to update a Task. |
Delete | Grants permission to delete a Task. |
Commands |
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description | |||||
---|---|---|---|---|---|---|
Create | Task instances are created automatically when the task launches, so the Create permission does not appear. | |||||
Read | Grants permission to read a Task Instance | |||||
Update | Grants permission to update certain fields on a Task Instance. | |||||
Delete | Grants permission to delete a Task Instance. | |||||
Commands | For command descriptions, see Manually Running and Controlling Tasks.
|
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a Trigger. |
Read | Grants permission to read a Trigger. |
Update | Grants permission to update a Trigger. |
Delete | Grants permission to delete a Trigger. |
Commands |
|
...
Anchor | ||||
---|---|---|---|---|
|
Options | Description |
---|---|
Create | Grants permission to create a virtual resource. |
Read | Grants permission to read a virtual resource. |
Update | Grants permission to update a virtual resource. |
Delete | Grants permission to delete a virtual resource. |
Execute | Grants permission to execute a virtual resource. |
Commands |
|
...
Anchor | ||||
---|---|---|---|---|
|
Webhook Permissions
Options | Description |
---|---|
Create | Grants permission to create a Webhook. |
Read | Grants permission to read a Webhook. |
Update | Grants permission to update a Webhook. |
Delete | Grants permission to delete a Webhook. |
Commands |
|
...