Table of Contents

Search

  1. Preface
  2. Introduction
  3. IDD Concepts
  4. Implementation Process
  5. IDD Configuration Manager
  6. Manual IDD Configuration
  7. IDD Global Properties
  8. Sizing and Platform Requirements
  9. Application Components
  10. IDD Security Configuration
  11. Data Security
  12. Example Role-Based Security Configuration
  13. Data Masking
  14. Siperian BPM Workflow Engine
  15. Locale Codes
  16. Troubleshooting
  17. Glossary

Data Director Implementation Guide

Data Director Implementation Guide

Configure Resource Privileges for Custom Resources

Configure Resource Privileges for Custom Resources

Next, for each role (except the party_no_privileges_role), expand the Custom Resources node, expand the IDD application node, and assign the following privileges:
Role Name
Resource Privileges
party_no_privileges_role
No permissions.
party_read_only_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resource (or READ if you want users to run existing queries only and not create new queries).
  • READ privileges to the SUBJECT_AREA/Party resource.
party_create_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
  • READ and UPDATE privileges on the SUBJECT_AREA/Party (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and CREATE privileges on TASK_TYPE/Party: ReviewNoApprove, which gives users access to the
    Send for Approval
    button.
  • READ and UPDATE privileges to the SUBJECT_AREA/Party resource.
party_update_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
  • READ and UPDATE privileges on the SUBJECT_AREA/Party resource (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and UPDATE privileges on TASK_TYPE/Party:ReviewNoApprove, which gives users access to the
    Send for Approval
    button.
How you configure access to these custom resources affects what users see in the IDD application. For example:
  • If a user does not have CREATE privileges to SEARCH_QUERY/Create, they will not have the option to create or save a new query in IDD.
  • If a user does not have CREATE privileges to SEARCH_QUERY/CreatePublic, they will not see the Public Query option in the Save Query As dialog.
  • In general, users need to have READ and EXECUTE privileges on tasks that will be assigned to them. If a user does not have CREATE privileges to a given TASK_TYPE, they will not be able to create that task in IDD.

0 COMMENTS

We’d like to hear from you!