Administration Access Rights

Assign administrative access rights to grant a resource (user) more advanced permissions to pages, portlets, processes, and jobs. Audit trail, API, software download, license information, resource capacity planning, process, and portfolio access rights are also listed.
ccppmop153
Assign administrative access rights to grant a resource (user) more advanced permissions to pages, portlets, processes, and jobs. Audit trail, API, software download, license information, resource capacity planning, process, and portfolio access rights are also listed.
Administration Access Rights
The following access rights are available to manage administrative tasks:
  • Administration - Access
    Allows the user to access the Administration menu. Users need additional rights to perform individual administrative actions.
    Type:
    Global
  • Administration - Application Setup
    Allows users to edit the following options:
    • Clarity PPM
       system options and settings, including Organization and Access menu 
    • Timesheet options, and to create, close, and mark time reporting periods for deletion 
    • Data Administration menu and General Settings menu
    Users with this access right can also run the Health Report under the
    Administration, Security and Diagnostics
    menu.
    Includes:
    Administration - Access to access the Administration menu.
    Type:
    Global
  • Administration - Authorization
    Allows users to manage resources and groups.
    Includes:
    Administration - Access
    Type:
    Global
  • Administration - Partition Models
    Allows users to manage partition models.
    Requires:
    Administration - Access
    Type:
    Global
  • Administration - Resources
    Allows users to navigate to the administration pages for viewing and editing resources.
    Requires:
    Resource - Edit Administration
    right to view individual resources.
    Type:
    Global
  • Administration - Studio
    Allows user to access 
    Clarity PPM
    Studio pages. This right allows the user to create, edit, and delete UI Themes. The user can view queries, portlets, and portlet pages. To manage portlets, the user requires the appropriate instance or global rights as listed in the
    Portlets Access Rights
    section. To manage objects, the user requires the object Administration right.
    Type:
    Global
  • Administration - XOG
    Allows users to import and export information through the XML Open Gateway interface.
    Type:
    Global
API Access Rights
The following access rights are required for REST API access and product integrations:
  • API - Access
    Allows the user to run an application that uses the REST APIs. In addition, you need the appropriate application rights to view or update specific functional areas in the product.
Audit Trail Access Rights
The following access rights are available for audit:
  • Audit Trail - Access
    Allows users to access audit page.
    Type
    : Global
  • Audit Trail - View - All
    Allows users to view any audit page.
    Type
    : Global
Jobs Access Rights
The following access rights are available for managing jobs:
  • Jobs - Access
    Allows users to access job pages. Additional rights such as the Jobs - Run - All right or instance level rights such as the Job - Run right, Job - View Output right, or Job - Edit Properties right are required.
    Type:
    Global
  • Job - Edit Properties
    Allows users to view and edit the job properties for specific jobs. This right also lets users reschedule jobs and view output.
    Type:
    Global
  • Job - Run
    Allows users to access and run jobs, edit job properties, and view job output.
    Requires:
    Jobs - Access access right. Some jobs may not require additional rights for successful execution. See
    Jobs Reference
    to review specific job parameters and requirements.
    Type:
    Intance
  • Jobs - Run - All
    Allows users to run any job. This right also allows users to schedule any job, edit properties for any job, and view the output of any job.
    Requires: 
    Jobs - Access access right. Some jobs may not require additional rights for successful execution. See 
    Jobs Reference
     to review specific job parameters and requirements.
    Type: 
    Global
  • Jobs - View Output
    Allows users to view the output of the jobs to which they have access.
    Requires:
    Jobs - Access right
    Type:
    Global
  • Jobs - View Output - All
    Allows users to view the output of any job.
    Requires:
    Jobs - Access right
  • Jobs - Administrator
    Allows you to manage job definitions and job categories.
    Type:
    Global
  • Jobs - Administrator Access
    Allows users to view job definitions. With this right, users can also view jobs categories.
    Type:
    Global
  • Jobs - Create Definition
    Allows users to create, edit, and view job definitions.
    Requires:
    Jobs - Administrator Access right
    Type:
    Global
  • Jobs - Edit Definition
    Allows users to view and change job definitions.
    Requires:
    Jobs - Administrator right
    Type:
    Instance
  • Jobs - Edit Definition - All
    Allows users to edit any job definition.
    Requires:
    Jobs - Administrator Access right
    Type:
    Global
License Information Access Group Rights
To view license information, you must either be associated with the
License Information Access
group or be assigned each of the access rights. This access group allows users to view and navigate license information pages and portlets and includes the following access rights:
  • Page - View
    Allows users to view a general page in 
    Clarity PPM
    . For instance pages (such as portfolio pages), this right is not required.
    Type:
    Instance
  • Portlet - View
    Allows users to view a specific portlet.
    Type:
    Instance
Page Access Rights
The following access rights are available for pages:
  • Page - View
    Allows users to view a general page in 
    Clarity PPM
    . For instance pages (such as portfolio pages), this right is not required.
    Type:
    Instance
  • Page Definition Editor
    Allows users to edit, view, and delete the definition of a specific page.
    Required:
    Administration - Studio
    access right to access the
    Clarity PPM
     Studio menu.
    Type:
    Instance
  • Page Definition Editor - All
    Allows users to edit, view, and delete the definition of all pages.
    Required:
    Administration - Studio
    access right to access the
    Clarity PPM
     Studio menu.
    Type:
    Global
  • Page Definition Viewer
    Allows the user to view the definition of a specific page.
    Required:
    Administration - Studio
    access right to access the
    Clarity PPM
     Studio menu.
    Type:
    Instance
  • Page Definition Viewer - All
    Allows the user to view the definition of all pages.
    Required:
    Administration - Studio
    access right to access the
    Clarity PPM
     Studio menu.
    Type:
    Global
  • Page Viewer - All
    Lets the user view any configured portlet page. Before the users can view them, link the portlet pages to a menu. The user requires the rights to navigate the menu. For example, if a page links to the Administration menu, the users require the
    Administration - Access
    right.
    Type:
    Global
Portlet Access Rights
The following access rights are available for portlets:
  • Portlet Definition Editor
    Allows the user to edit and view the definition of a specific portlet.
    Requires:
    Administration - Studio
    to access the Studio menu.
    Type:
    Instance
  • Portlet Definition Editor - All
    Allows a user to edit and view the definitions of all portlets available from Studio.
    Requires:
    Administration - Access
    to access the Administration and Studio menus.
    Type:
    Global
  • Portlet - View
    Allows users to view a specific portlet.
    Type:
    Instance
  • Portlet Viewer - All
    Lets you view and add stock portlets to portlet pages. The right helps add a stock portlet to a personal dashboard.
    Type:
    Global
Portfolio Access Rights
The following access rights are available to resources, groups, and OBS units to create, view, and edit a portfolio:
  • Portfolio - Navigate
    Allows users to access the Portfolio Management menu.
    Type:
    Global
  • Portfolio - Create
    Allows users to create portfolios.
    Includes:
    Portfolio - Navigate
    to access Portfolio Management menu.
    Type:
    Global
  • Portfolio - Create Scenarios
    Allows user to create scenarios for a specific portfolio.
    Requires:
    • Portfolio - Navigate
      to access the Portfolio Management menu
    • Portfolio - View
      to view a specific portfolio.
    Type:
    Instance
  • Portfolio - Edit
    Allows users to view, edit, and delete specific portfolios. This right also lets users change the portfolio layout and attach, modify, or delete a scenario. With this right, users can view investments, scenarios, and portlets in the portfolio to which they have access.
    Requires
    :
    Portfolio - Navigate
    to access the Portfolio Management menu.
    Type:
    Instance
  • Portfolio - Edit - All
    Allows users to view, edit, and delete all portfolios. Users can see only the investments, scenarios, and portlets to which they have access.
    Requires:
    Portfolio - Navigate
    to access the Portfolio Management menu.
    Type:
    Global
  • Portfolio - Edit Access Rights
    Allows users to view, edit, and delete the access rights for portfolios to which they have access.
    Requires:
    Portfolio - Navigate
    to access the Portfolio Management menu.
    Type:
    Instance
  • Portfolio - Edit Access Rights - All
    Allows users to view, edit, and delete the access rights for any portfolio to which
    they have access.
    Required:
    Portfolio - Navigate
    to access the Portfolio Management menu.
    Type:
    Global
  • Portfolio - Manager - Auto (Automatic)
    Automatically assigned when users create an investment or are assigned as the manager of an investment. This right allows users to view, edit, and delete the portfolios that they create. This right also lets users view, edit, and delete the access rights for the portfolio. The
    Portfolio - Navigate
    right is required.
    This access right is equivalent to the
    Portfolio - Edit
    access right, and includes the
    Portfolio - Read
    ,
    Portfolio - Edit
    ,
    Portfolio - Delete
    , and
    Portfolio - Navigate
    access rights.
    If you reassign the portfolio manager, this access right transfers to the new manager, and the previous manager’s access rights to this portfolio is revoked.
    Type:
    Instance
  • Portfolio - View
    Allows you to view a specific portfolio.
    Required:
    Portfolio - Navigate to access the Portfolio Management menu.
    Type:
    Instance
  • Portfolio - View - All
    Allows users to view all portfolios. Users can view only investments, scenarios, and portlets in the portfolio to which they have access.
    Requires:
    Portfolio - Navigate
    to access the Portfolio Management menu.
    Type:
    Global
Process Access Rights
The following access rights are available to work with processes:
  • Process Access
    Allows the user to access the process pages.
    Type:
    Global
  • Process - AutoStart - All
    Allows resource to auto start a new process instance from any of the process definitions in the system.
    Type:
    Global
  • Process - Cancel
    Allows users to cancel process instances from a specific process definition.
    Type:
    Instance
  • Process - Cancel - All
    Allows users to cancel of all process instances.
    Type:
    Global
  • Process - Create Definition
    Allows users or to create or change processes for any object type to which they have access. Users with this right can modify, copy, or start any process that they create. Users can create processes from the
    Processes
    page of an object or from the Data Administration, Processes menu.
    Type:
    Instance
  • Process - Delete
    Allows users to delete process instances from a specific process definition.
    Type:
    Instance
  • Process - Delete - All
    Allows users to delete a process instance from any process definition.
    Type:
    Global
  • Process - Edit Definition
    Allows users to edit a specific process definition, but cannot start any process instances.
    Type:
    Instance
  • Process - Edit Definition - All
    Allows users to edit all process definitions. Typically, this right is given to administrators and senior executives. Users with this right cannot start processes.
    Type:
    Global
  • Process - Manage
    Allows users to start automatically a process instance for the process definition to which they have access. Users can also start a new process instance, delete a process instance, or cancel a process instance.
    Type:
    Instance
  • Process - Manage - All
    Allows users to start automatically any process. This right is typically given to administrators and senior executives. Users with this right can change processes that they create and can start processes for objects to which they have access. This access right also allows users to start a new process instance, delete a process instance, or cancel a process instance.
    Type:
    Global
  • Process - Start
    Allows users to start a new process instance from a specific process definition.
    Type:
    Instance
  • Process - Start - All
    Allows users to start (that is, initiate) of all process instances.
    Type:
    Global
  • Process View Instance - All
    Allows users to view all process instances.
    Type:
    Global
  • Process - View Definition
    Allows users to view the process definition from the objects to which they have access. Users with this right cannot start processes.
    Type:
    Instance
  • Process - View Definition - All
    Allows users to view all process definitions. Typically, this right is administrators and senior executives. Users with this right cannot start processes.
    Type:
    Global
  • Process Engine Monitoring
    Allows users to navigate to process engine monitoring and administration.
    Type:
    Global
Scenario Access Rights (Capacity Planning)
Best Practice:
Capacity planning scenarios are designed for you to view a subset of all resources or investments. Limit resources or investments through a security OBS or through instance-level resource access rights. A more manageable amount of data displays for those resources and investments you manage. Additionally, avoid accessing capacity planning scenarios as a 
Clarity PPM
 administrator or as a user with global access rights to all resources.
The following access rights are available to work with capacity planning scenarios:
  • Scenario - Edit
    Allows users to edit and delete a specific scenario.
    Includes:
    Scenario - View
    and the ability to delete the scenario
    Requires:
    Portfolio - Navigate
    Type:
    Global
  • Scenario - Edit Access Rights
    Allows users to edit access rights for a specific scenario.
    Requires:
    Portfolio - Navigate
    ,
    Portfolio - View
    , or
    Scenario - View
    Type:
    Instance
  • Scenario - Manager - Automatic
    When you create a scenario, access is automatically assigned. The access allows you to view, edit, and delete scenarios that you own. You can also view, edit, and delete access for that scenario.
    Type:
    Global
  • Scenario - Navigate
    Allows users to view the Scenario toolbar on capacity planning scenario-enabled pages and create new scenarios.
    Type:
    Global
  • Scenario - View
    Allows users to view a specific scenario.
    Requires:
    Portfolio - Navigate
    or
    Portfolio - View
      
    Type:
    Instance
Software Download Access Rights
The following access rights are available for downloading software:
  • Software Download - Microsoft Project Interface
    Allows users to download the CA PPM Microsoft Project Interface.
    Type:
    Global
  • Software Download - Open Workbench
    Required to download Open Workbench.
    Type:
    Global