Additional Security Parameters

To determine detailed access permissions:

  1. Select the security subject in the Groups and Users box.

  2. Click the Show Full List of Operations button to display additional operations.

  3. Set permissions for the operations to be allowed or denied in the Permissions for Selected list.

Access Permissions Set Description

The table contains description of operations with object types:

Operation Operation description Object types

Read

The operation enables the user to open objects for view and combines the operations described below.

When the checkbox to allow or deny operation is selected, the following checkboxes are automatically selected next to the operations:

  • Read descriptor.

  • Read parameters.

  • Read metadata.

  • Print.

  • Export.

  • Execution.

  • Retrieve data.

  • Read dictionary elements.

  • Read update.

  • Apply update.

  • Apply SQL command.

  • Create connection.

  • Read formulas.

All

Change

The operation enables the user to open objects for edit and combines the operations described below.

When the checkbox to allow or deny operation is selected, the following checkboxes are automatically selected next to the operations:

  • Change descriptor.

  • Change parameters.

  • Change metadata.

  • Import.

  • Create.

  • Save data.

  • Change dictionary elements.

  • Add elements to dictionary.

  • Delete elements from dictionary.

  • Write data to scenario.

  • Insert data.

  • Change data.

  • Delete data.

  • Change table structure.

  • Change text.

  • Write update.

  • Save formulas.

All

Change permissions

The operation enables the user to change object access control settings and combines the operations described below.

When the checkbox to allow or deny operation is selected, the following checkboxes are automatically selected next to the operations:

  • Change element access permissions.

  • Transfer data permissions.

  • Transfer permissions.

All

Delete

The operation enables the user to delete objects from the repository.

All

Read descriptor

The operation enables the user to get objects' internal structure and open objects for view. When the operation is denied, repository objects are not displayed.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the read operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the read parameters and the read metadata operations to allow to open objects for view.

All

Change descriptor

The operation enables the user to change objects' internal structure and open objects for edit if they can be read.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the change operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the change parameters and the change metadata operations to allow to open objects for edit.

All

Read parameters

The operation enables the user to get objects' parameters specified on creating and open objects for view.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the read operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the read descriptor and the read metadata operations to allow to open objects for view.

All

Edit parameters

The operation enables the user to change objects' parameters specified on creating and open objects for edit if they can be read.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the change operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the change descriptor and the change metadata operations to allow to open objects for edit.

All

Read metadata

The operation enables the user to get objects' metadata and open objects for view. Objects' metadata is object properties.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the read operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the read descriptor and the read parameters operations to allow to open objects for view.

All

Change metadata

The operation enables the user to change objects' metadata and open objects for edit if they can be read. Objects' metadata is object properties.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the change operation is selected.

NOTE. If the checkbox is selected manually, select additional checkboxes next to the change descriptor and the change parameters operations to allow to open objects for edit.

All

Print

The operation enables the user to print objects' contents if they can be read.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the read operation is selected.

Dashboard

Regular report

Express report

Modeling problem

Modeling container

Standard cube

Cube view

Virtual cube

Calculated cube

Unit

Document

Workspace

Export

The operation enables the user to export objects' contents if they can be read.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the read operation is selected.

Dashboard

Regular report

Express report

Modeling problem

Modeling container

Standard cube

Cube view

Virtual cube

Calculated cube

MDM dictionary

Composite MDM dictionary

Query

View

External table

Table

Log

Unit

Document

Resources

Styles table

Workspace

Import

The operation enables the user to import objects' data if they can be changed.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the change operation is selected.

Dashboard

Regular report

Express report

Standard cube

Cube view

Virtual cube

Calculated cube

MDM dictionary

Composite MDM dictionary

View

External table

Table

Log

Unit

Document

Resources

Styles table

Workspace

Repository connection

Create

The operation enables the user to create objects in the object navigator.

The checkbox next to the operation can be selected manually or automatically when the checkbox next to the change operation is selected.

IMPORTANT. Operations can be allowed/denied only for the existing objects in the Navigator section, for example, to deny creating objects in a folder. To separate access permissions to object classes, use attribute-based access control rules. Discretionary rules cannot be used to deny creating objects of any class in the object navigator.

All

See also:

Access Control Settings | Setting Up Discretionary Access Control Parameters