Table of Contents

Search

  1. Preface
  2. Introduction
  3. IDD Concepts
  4. Implementation Process
  5. IDD Configuration Manager
  6. Manual IDD Configuration
  7. IDD Global Properties
  8. Appendix A: Sizing and Platform Requirements
  9. Appendix B: Application Components
  10. Appendix C: IDD Security Configuration
  11. Appendix D: Data Security
  12. Appendix E: Example Role-Based Security Configuration
  13. Appendix F: Data Masking
  14. Appendix G: Siperian BPM Workflow Engine
  15. Appendix H: Locale Codes
  16. Appendix I: Troubleshooting
  17. Appendix J: Glossary

Data Director Implementation Guide

Data Director Implementation Guide

Configure Resource Privileges for Custom Resources

Configure Resource Privileges for Custom Resources

Next, for each role (except the party_no_privileges_role), expand the Custom Resources node, expand the IDD application node, and assign the following privileges:
Role Name
Resource Privileges
party_no_privileges_role
No permissions.
party_read_only_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resource (or READ if you want users to run existing queries only and not create new queries).
  • READ privileges to the SUBJECT_AREA/Party resource.
party_create_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
  • READ and UPDATE privileges on the SUBJECT_AREA/Party (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and CREATE privileges on TASK_TYPE/Party: ReviewNoApprove, which gives users access to the
    Send for Approval
    button.
  • READ and UPDATE privileges to the SUBJECT_AREA/Party resource.
party_update_role
  • READ privileges to the CHART/View resource so that users can see charts in the
    Start workspace
    .
  • READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
  • READ and UPDATE privileges on the SUBJECT_AREA/Party resource (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and UPDATE privileges on TASK_TYPE/Party:ReviewNoApprove, which gives users access to the
    Send for Approval
    button.
How you configure access to these custom resources affects what users see in the IDD application. For example:
  • If a user does not have CREATE privileges to SEARCH_QUERY/Create, they will not have the option to create or save a new query in IDD.
  • If a user does not have CREATE privileges to SEARCH_QUERY/CreatePublic, they will not see the Public Query option in the Save Query As dialog.
  • In general, users need to have READ and EXECUTE privileges on tasks that will be assigned to them. If a user does not have CREATE privileges to a given TASK_TYPE, they will not be able to create that task in IDD.

0 COMMENTS

We’d like to hear from you!