Configure Resource Privileges for Custom Resources
Configure Resource Privileges for Custom Resources
Next, for each role (except the party_no_privileges_role), expand the Custom Resources node, expand the IDD application node, and assign the following privileges:
Role Name
Resource Privileges
party_no_privileges_role
No permissions.
party_read_only_role
READ privileges to the CHART/View resource so that users can see charts in the
Start workspace
.
CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resource (or READ if you want users to run existing queries only and not create new queries).
READ privileges to the SUBJECT_AREA/Party resource.
party_create_role
READ privileges to the CHART/View resource so that users can see charts in the
Start workspace
.
READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
READ and UPDATE privileges on the SUBJECT_AREA/Party (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and CREATE privileges on TASK_TYPE/Party: ReviewNoApprove, which gives users access to the
Send for Approval
button.
READ and UPDATE privileges to the SUBJECT_AREA/Party resource.
party_update_role
READ privileges to the CHART/View resource so that users can see charts in the
Start workspace
.
READ and CREATE privileges to the SEARCH_QUERY/Create and SEARCH_QUERY/CreatePublic resources.
READ and UPDATE privileges on the SUBJECT_AREA/Party resource (only if you want to allow the role to bypass workflow altogether). Normally, users have READ and UPDATE privileges on TASK_TYPE/Party:ReviewNoApprove, which gives users access to the
Send for Approval
button.
How you configure access to these custom resources affects what users see in the IDD application. For example:
If a user does not have CREATE privileges to SEARCH_QUERY/Create, they will not have the option to create or save a new query in IDD.
If a user does not have CREATE privileges to SEARCH_QUERY/CreatePublic, they will not see the Public Query option in the Save Query As dialog.
In general, users need to have READ and EXECUTE privileges on tasks that will be assigned to them. If a user does not have CREATE privileges to a given TASK_TYPE, they will not be able to create that task in IDD.