Administration Access Rights
ccppmop1581
Assign administrative access rights to grant a resource (user) more advanced permissions to pages, portlets, processes, and jobs. Audit trail, API, software download, license information, resource capacity planning, process, and portfolio access rights are also listed.
Administration Access Rights
The following access rights are available to manage administrative tasks:
- Administration - AccessAllows the user to access the Administration menu. Users need additional rights to perform individual administrative actions.Type:Global
- Administration - Application SetupAllows users to edit the following options:
- Classic PPMsystem options and settings, including Organization and Access menu
- Timesheet options, and to create, close, and mark time reporting periods for deletion
- Data Administration menu and General Settings menu
Administration, Security and Diagnosticsmenu.Includes:Administration - Access to access the Administration menu.Type:Global - Administration - AuthorizationAllows users to manage resources and groups.Includes:Administration - AccessType:Global
- Administration - Partition ModelsAllows users to manage partition models.Requires:Administration - AccessType:Global
- Administration - ResourcesAllows users to navigate to the administration pages for viewing and editing resources.Requires:Resource - Edit Administrationright to view individual resources.Type:Global
- Administration - StudioAllows user to accessClassic PPMStudio pages. This right allows the user to create, edit, and delete UI Themes. The user can view queries, portlets, and portlet pages. To manage portlets, the user requires the appropriate instance or global rights as listed in thePortlets Access Rightssection. To manage objects, the user requires the object Administration right.Type:Global
- Administration - XOGAllows users to import and export information through the XML Open Gateway interface.Type:Global
API Access Rights
The following access rights are required for REST API access and product integrations:
- API - AccessAllows the user to run an application that uses the REST APIs. In addition, you need the appropriate application rights to view or update specific functional areas in the product.
Audit Trail Access Rights
The following access rights are available for audit:
- Audit Trail - AccessAllows users to access audit page.Type: Global
- Audit Trail - View - AllAllows users to view any audit page.Type: Global
Jobs Access Rights
The following access rights are available for managing jobs:
- Jobs - AccessAllows users to access job pages. Additional rights such as the Jobs - Run - All right or instance level rights such as the Job - Run right, Job - View Output right, or Job - Edit Properties right are required.Type:Global
- Job - Edit PropertiesAllows users to view and edit the job properties for specific jobs. This right also lets users reschedule jobs and view output.Type:Global
- Job - RunAllows users to access and run jobs, edit job properties, and view job output.Requires:Jobs - Access access right. Some jobs may not require additional rights for successful execution. SeeJobs Referenceto review specific job parameters and requirements.Type:Intance
- Jobs - Run - AllAllows users to run any job. This right also allows users to schedule any job, edit properties for any job, and view the output of any job.Requires:Jobs - Access access right. Some jobs may not require additional rights for successful execution. SeeJobs Referenceto review specific job parameters and requirements.Type:Global
- Jobs - View OutputAllows users to view the output of the jobs to which they have access.Requires:Jobs - Access rightType:Global
- Jobs - View Output - AllAllows users to view the output of any job.Requires:Jobs - Access right
- Jobs - AdministratorAllows you to manage job definitions and job categories.Type:Global
- Jobs - Administrator AccessAllows users to view job definitions. With this right, users can also view jobs categories.Type:Global
- Jobs - Create DefinitionAllows users to create, edit, and view job definitions.Requires:Jobs - Administrator Access rightType:Global
- Jobs - Edit DefinitionAllows users to view and change job definitions.Requires:Jobs - Administrator rightType:Instance
- Jobs - Edit Definition - AllAllows users to edit any job definition.Requires:Jobs - Administrator Access rightType:Global
License Information Access Group Rights
To view license information, you must either be associated with the
License Information Access
group or be assigned each of the access rights. This access group allows users to view and navigate license information pages and portlets and includes the following access rights:- Page - ViewAllows users to view a general page inClassic PPM. For instance pages (such as portfolio pages), this right is not required.Type:Instance
- Portlet - ViewAllows users to view a specific portlet.Type:Instance
Page Access Rights
The following access rights are available for pages:
- Page - ViewAllows users to view a general page inClassic PPM. For instance pages (such as portfolio pages), this right is not required.Type:Instance
- Page Definition EditorAllows users to edit, view, and delete the definition of a specific page.Required:Administration - Studioaccess right to access theClassic PPMStudio menu.Type:Instance
- Page Definition Editor - AllAllows users to edit, view, and delete the definition of all pages.Required:Administration - Studioaccess right to access theClassic PPMStudio menu.Type:Global
- Page Definition ViewerAllows the user to view the definition of a specific page.Required:Administration - Studioaccess right to access theClassic PPMStudio menu.Type:Instance
- Page Definition Viewer - AllAllows the user to view the definition of all pages.Required:Administration - Studioaccess right to access theClassic PPMStudio menu.Type:Global
- Page Viewer - AllLets the user view any configured portlet page. Before the users can view them, link the portlet pages to a menu. The user requires the rights to navigate the menu. For example, if a page links to the Administration menu, the users require theAdministration - Accessright.Type:Global
Portlet Access Rights
The following access rights are available for portlets:
- Portlet Definition EditorAllows the user to edit and view the definition of a specific portlet.Requires:Administration - Studioto access the Studio menu.Type:Instance
- Portlet Definition Editor - AllAllows a user to edit and view the definitions of all portlets available from Studio.Requires:Administration - Accessto access the Administration and Studio menus.Type:Global
- Portlet - ViewAllows users to view a specific portlet.Type:Instance
- Portlet Viewer - AllLets you view and add stock portlets to portlet pages. The right helps add a stock portlet to a personal dashboard.Type:Global
Portfolio Access Rights
The following access rights are available to resources, groups, and OBS units to create, view, and edit a portfolio:
- Portfolio - NavigateAllows users to access the Portfolio Management menu.Type:Global
- Portfolio - CreateAllows users to create portfolios.Includes:Portfolio - Navigateto access Portfolio Management menu.Type:Global
- Portfolio - Create ScenariosAllows user to create scenarios for a specific portfolio.Requires:
- Portfolio - Navigateto access the Portfolio Management menu
- Portfolio - Viewto view a specific portfolio.
Type:Instance
- Portfolio - EditAllows users to view, edit, and delete specific portfolios. This right also lets users change the portfolio layout and attach, modify, or delete a scenario. With this right, users can view investments, scenarios, and portlets in the portfolio to which they have access.Requires:Portfolio - Navigateto access the Portfolio Management menu.Type:Instance
- Portfolio - Edit - AllAllows users to view, edit, and delete all portfolios. Users can see only the investments, scenarios, and portlets to which they have access.Requires:Portfolio - Navigateto access the Portfolio Management menu.Type:Global
- Portfolio - Edit Access RightsAllows users to view, edit, and delete the access rights for portfolios to which they have access.Requires:Portfolio - Navigateto access the Portfolio Management menu.Type:Instance
- Portfolio - Edit Access Rights - AllAllows users to view, edit, and delete the access rights for any portfolio to whichRequired:Portfolio - Navigateto access the Portfolio Management menu.Type:Global
- Portfolio - Manager - Auto (Automatic)Automatically assigned when users create an investment or are assigned as the manager of an investment. This right allows users to view, edit, and delete the portfolios that they create. This right also lets users view, edit, and delete the access rights for the portfolio. ThePortfolio - Navigateright is required.This access right is equivalent to thePortfolio - Editaccess right, and includes thePortfolio - Read,Portfolio - Edit,Portfolio - Delete, andPortfolio - Navigateaccess rights.If you reassign the portfolio manager, this access right transfers to the new manager, and the previous manager’s access rights to this portfolio is revoked.Type:Instance
- Portfolio - ViewAllows you to view a specific portfolio.Required:Portfolio - Navigate to access the Portfolio Management menu.Type:Instance
- Portfolio - View - AllAllows users to view all portfolios. Users can view only investments, scenarios, and portlets in the portfolio to which they have access.Requires:Portfolio - Navigateto access the Portfolio Management menu.Type:Global
Process Access Rights
The following access rights are available to work with processes:
- Process AccessAllows the user to access the process pages.Type:Global
- Process - AutoStart - AllAllows resource to auto start a new process instance from any of the process definitions in the system.Type:Global
- Process - CancelAllows users to cancel process instances from a specific process definition.Type:Instance
- Process - Cancel - AllAllows users to cancel of all process instances.Type:Global
- Process - Create DefinitionAllows users or to create or change processes for any object type to which they have access. Users with this right can modify, copy, or start any process that they create. Users can create processes from theProcessespage of an object or from the Data Administration, Processes menu.Type:Instance
- Process - DeleteAllows users to delete process instances from a specific process definition.Type:Instance
- Process - Delete - AllAllows users to delete a process instance from any process definition.Type:Global
- Process - Edit DefinitionAllows users to edit a specific process definition, but cannot start any process instances.Type:Instance
- Process - Edit Definition - AllAllows users to edit all process definitions. Typically, this right is given to administrators and senior executives. Users with this right cannot start processes.Type:Global
- Process - ManageAllows users to start automatically a process instance for the process definition to which they have access. Users can also start a new process instance, delete a process instance, or cancel a process instance.Type:Instance
- Process - Manage - AllAllows users to start automatically any process. This right is typically given to administrators and senior executives. Users with this right can change processes that they create and can start processes for objects to which they have access. This access right also allows users to start a new process instance, delete a process instance, or cancel a process instance.Type:Global
- Process - StartAllows users to start a new process instance from a specific process definition.Type:Instance
- Process - Start - AllAllows users to start (that is, initiate) of all process instances.Type:Global
- Process View Instance - AllAllows users to view all process instances.Type:Global
- Process - View DefinitionAllows users to view the process definition from the objects to which they have access. Users with this right cannot start processes.Type:Instance
- Process - View Definition - AllAllows users to view all process definitions. Typically, this right is administrators and senior executives. Users with this right cannot start processes.Type:Global
- Process Engine MonitoringAllows users to navigate to process engine monitoring and administration.Type:Global
Scenario Access Rights (Capacity Planning)
Best Practice:
Capacity planning scenarios are designed for you to view a subset of all resources or investments. Limit resources or investments through a security OBS or through instance-level resource access rights. A more manageable amount of data displays for those resources and investments you manage. Additionally, avoid accessing capacity planning scenarios as a Classic PPM
administrator or as a user with global access rights to all resources.The following access rights are available to work with capacity planning scenarios:
- Scenario - EditAllows users to edit and delete a specific scenario.Includes:Scenario - Viewand the ability to delete the scenarioRequires:Portfolio - NavigateType:Global
- Scenario - Edit Access RightsAllows users to edit access rights for a specific scenario.Requires:Portfolio - Navigate,Portfolio - View, orScenario - ViewType:Instance
- Scenario - Manager - AutomaticWhen you create a scenario, access is automatically assigned. The access allows you to view, edit, and delete scenarios that you own. You can also view, edit, and delete access for that scenario.Type:Global
- Scenario - NavigateAllows users to view the Scenario toolbar on capacity planning scenario-enabled pages and create new scenarios.Type:Global
- Scenario - ViewAllows users to view a specific scenario.Requires:Portfolio - NavigateorPortfolio - ViewType:Instance
Software Download Access Rights
The following access rights are available for downloading software:
- Software Download - Microsoft Project InterfaceAllows users to download theClassic PPMMicrosoft Project Interface.Type:Global
- Software Download - Open WorkbenchRequired to download Open Workbench.Type:Global