Administer > Administer ITBA > System Administrator > Users and Roles - Role Management

Users and Roles - Role Management

You can define user roles and application permissions in the ADMIN tab. You can also assign resources to specific permissions.

ClosedTo access:

Select ADMIN> Users and Roles > Role Management.

ClosedRoles and Permissions

Each role contains set of permissions. Permissions define which actions can be performed by the user. For example, you can create a role that enables its users to create pages or view specific ones. In some cases, actions can be performed according to the resource attached to a permission.

Note Users that are created in the ADMIN tab and require permissions to view reports pages, must be assigned those permissions in SAP BusinessObjects Enterprise.

ClosedResources

A resource is a logical group of one or more ITBA application data items (for example pages). Once you define resources, you attach the resources to a permission. For example, you can specify that the CIO has View permissions for CIO resources, while the Administrator has View permissions for all resources.

Tip It is recommended to define resources prior to defining roles. For details, see Users and Roles - Resource Management.

ClosedPre-Defined Roles

Note Every out-of-the-box Scorecard has its own dedicated resource and role.

ITBA roles can be assigned any permissions. ITBA roles are available with the following out-of-the-box permissions:

Pre-Defined Role (from A-Z) Description Permissions Module
Administrator

The application administrator.

When a user with the Administrator role activates a CAP, everyone get permissions to view, edit, delete all the Scorecards in the CAP.

All Permissions IT Business Analytics
Scorecard Administrator

Creates and manages specific Scorecards and Pages. Only a user with the Scorecard Administrator role can view the created Scorecard. Once a Scorecard is created, the system automatically generates a resource for the Scorecard and a role called GEN_<Scorecard name>. This Scorecard can then only be managed by the Scorecard creator and users with the relevant GEN_<Scorecard name> role.

In Dashboard, a user can only see a Scorecard when he has the relevant permission. If a component is configured with a specific Scorecard, Perspective, Objective, KPI, or KPI Breakdown, the user cannot see it, and the following message appears:
Data is not displayed because you do not have the correct viewing permissions.
Contact your administrator.

When a user with the Scorecard Administrator role activates a CAP, only the user gets permissions to view, edit, delete all the Scorecards in the CAP.

When a user with the Scorecard Administrator role drags a KPI from the Public Metrics and KPIs directory into a Scorecard in the Studio, a clone of the KPI is added to the Scorecard and the original KPI remains in the Public Metrics and KPIs directory to be available for other Scorecard Administrators. If a user with the Administrator role drags a KPI from the Public Metrics and KPIs directory into a Scorecard in the Studio, the KPI is added to the Scorecard and is removed from the Public Metrics and KPIs directory.

Administer Pages

Cascade Scorecard

Explorer Access

Manage Annotation

Manage Page

Select KPI

Studio

Data Set

IT Business Analytics
Viewer

Note The Viewer user list of permissions cannot be modified (by any user).

Permission Viewer user allowed access
Users and roles N
Administer pages N
Edit settings N
Data Source management N
Admin access N
Select KPI N
View Settings N
Manage page N
View Scorecard

Y

The Super Administrator can assign the specific Scorecards the Viewer user can view.

View Page

Y

The Super Administrator can assign the specific Dashboard pages the Viewer user can view.

Manage annotations Y
context management N
Cascade Scorecard Y
ABC Management N
Explorer access Y
Studio N
Content acceleration packs N
Data Set Y
 

ClosedPre-Defined Permissions

ITBA Application Elements Create and Edit View
Studio
  • To enter the STUDIO tab you need the Studio permission
  • To create Scorecards in the Studio, you need the Studio permission.

    Note The View Scorecard permission enables customer with different departments to use ITBA. Each department can have its own Scorecards that cannot be viewed or used by other departments. This removes the need for each department to install its own ITBA instance.

  • To edit relevant Scorecards, you need the View Scorecard permission for the relevant Scorecard.
  • To view the STUDIO tab you need the Studio permission.
  • To view specific Scorecards (their Perspectives, Objectives, and KPIs) you need the View Scorecard permission for the relevant Scorecard.
  • To view all the standalone KPIs in the Studio, you need the Select KPI permission.
Explorer N/A
  • To view the EXPLORER tab you need the Explorer Access permission
  • To view the relevant Scorecards (their Perspectives, Objectives, and KPIs) in Explorer, you need the View Scorecard permission.
  • To view all the standalone KPIs in the Studio, you need the Select KPI permission.
  • To view the prediction analysis, you need the Forecast permission.
  • To view the data set information you need the Data Set permission.
Admin
  • To access the ADMIN tab but not the tabs in the ADMIN tab, you need the Admin Access permission.
  • To access the ADMIN tab but not the tabs in the ADMIN tab, you need the Admin Access permission.
  • Users and Roles

    • User Management
    • Role Management
    • Resource Management
    • LDAP 
      Management
    • Dimension Level Permission
  • To view the ADMIN tab you need the Admin Access permission.
  • To modify the contents of the Users and Roles accordion tab you need the Edit Settings permission.
  • To view the ADMIN tab you need the Admin Access permission.

  • To view the Users and Roles accordion tab you need the Users and Roles permission.
  • Data Source Management
  • To view the ADMIN tab you need the Admin Access permission.
  • To access the Data Source Management page and to activate the content packs you need the Data Source Management permission.
  • Content Flow Management
  • To view the ADMIN tab you need the Admin Access permission.
  • To monitor and manage the ETL process for Data Warehouse you need the ABC Management permission.
  • Settings

    • Data Warehouse
    • Foundation
    • Single Sign-On
    • Pages
    • Website
    • Dashboard Settings
    • Engine Settings
    • Score Thresholds
    • BA Settings
  • To view the ADMIN tab you need the Admin Access permission.
  • To edit the contents of the Scorecard settings, Foundation settings, and Data Warehouse settings accordion tabs you need the Edit Settings permission.
  • To view the ADMIN tab you need the Admin Access permission.
  • To view the Scorecard settings, Foundation settings, and Data Warehouse settings accordion tabs you need the View Settings permission.
  • Semantic Layer
  • To view the ADMIN tab you need the Admin Access permission.
  • To view the ADMIN tab you need the Admin Access permission.
  • To use the Context Designer feature you need the  Context Management permission.
  • Content Acceleration Pack
  • To view the ADMIN tab you need the Admin Access permission.
  • To view, edit, delete Content Acceleration Packs, you need the Content Acceleration Pack permissions.
Dashboard
  • To add pages, view and modify all the pages in the Dashboard (add components, delete components, and even delete components) you need the Administer Pages permission.
  • To add pages, view and modify all the pages in the Dashboard (add components, delete components, and even delete components) you need the Administer Pages permission.
  • To configure components on the page you need the Select KPI permission
  • Specific page in Dashboard
  • To view and modify (add components, delete components, and even delete) the relevant page in the Dashboard you need the Manage Page permission.
  • To create a new page in Dashboard you need the Administer Pages permission. Once the page is created and assigned to a user, a user with the Manage Page permission can add components to the page, and modify it.
  • To view a specific page in Dashboard you need the View Page permission for that page.
  • Components on a page
  • To view Scorecards you need the View Scorecard permission.

  • To view the contents of the Active KPIs area in all the components filters and to be able to move KPIs from the Active KPIs area to the Selected KPIs area in the filter you need the Select KPI permission.
  • If you do not have this permission, you can, in all the component filters, view the contents of the Selected KPIs area, you cannot modify the selection, and cannot view the contents of the Active KPIs area as the contents are grayed out.
  • To view the small black arrow (near the Scorecard title) that indicates that the Scorecard has Cascading Scorecards and to be able to click the arrow to display the Cascading Scorecards for which you has permission you need the Cascade Scorecard permission.
  • If you do not have this permission, the small arrow is not displayed and you do not know that Cascading Scorecards are available.

  • To view specific Scorecards and data you need the View Scorecard permission.
Annotations (in Dashboard and Explorer)
  • To edit or delete an existing annotation you need the Manage Annotation permission.
  • If you do not have this permission, you can only view the annotation and the Edit and Delete buttons of the annotation are hidden.

ClosedCreate a role

  1. Select ADMIN> Users and Roles > Role Management.
  2. In the Roles area, click to create a new role.
  3. Enter the name and description for the role.
  4. Click OK to save your role.

After creating a role, follow the procedure for attaching permissions and resources.

ClosedEdit role details

  1. Select ADMIN> Users and Roles > Role Management.
  2. In the Roles area, select a role.
  3. In the Role Details area, click Edit Details.
  4. Edit the role as required and click OK.

ClosedAttach permissions

  1. Select Admin > Users and Roles > Role Management.
  2. In the Roles area, select a role.
  3. In the Role Details area, click . The Assign Permission to Role wizard opens.
  4. Select a permission from the list.
  5. Attach a resource to the selected permission, if required.
  6. Complete the wizard procedure to save your assignments.
  7. Log off from ITBA and log on again to complete the permission assignments.

ClosedAdd a resource to a permission

  1. Select ADMIN> Users and Roles > Role Management.
  2. In the Roles area, select a role.
  3. In the Permissions list select a permission.
  4. Click to open the Assign Resources to Permissions page in the Assign Permission to Role wizard.
  5. Select a permission and use the arrows to move the required resources from the Available Resources list to the Selected Resources list.

ClosedUse Case - Permissions

For details, see Permissions .

ClosedRole Management Page

Click to refresh the page.

  • ClosedRoles Area

    User interface elements are described below (when relevant, unlabeled elements are shown in angle brackets):

    UI Element

    Description

    Create Role. Creates a new role.

    Enter the Role Name and Role Description and click OK.

    Delete Role. Deletes the selected role.

    Click Refresh to refresh the display.

    When in ITBA, when you navigate to another tab and then return to Admin > Users and Roles, the display is not automatically refreshed. To refresh the display, click in the toolbar.

    <Role List>

    A list of roles currently defined in the ADMIN tab. When you select a role, the details appear in the Role Details area and Permissions list.

    For a list of pre-defined roles, see Pre-Defined Roles.

  • ClosedRole Details Area

    User interface elements are described below (when relevant, unlabeled elements are shown in angle brackets):

    UI Element

    Description
    Role Name The name of the selected role.
    Role Description The description of the selected role.
    Edit Details

    Edits the selected role name and description.

    Attach permission. Assigns selected permissions to roles. You select permissions using the Assign Permission to Role wizard. For user interface details, see Assign Permission to Role Wizard.

    Manage permission. Modifies the selected permission. Opens the Assign Resources to Permissions page in the Assign Permission to Role wizard. For user interface details, see Assign resources to permissions page.

    Detach permission. Removes the selected permission from the role.

    Permissions List The list of permissions and resources for the selected role.
    Permission The permission sets and permissions attached to the selected role.
    Resources

    The list of resources for each permission.

    Not Applicable. None of the available resources apply to this permission. For details, see Users and Roles - Resource Management.

    <Resource Name>. The permission is attached to a specific resource.

    All. The permission is applicable to all resources.

ClosedAssign Permission to Role Wizard

This wizard enables you to assign permissions to the selected role, as well as assign resources to the permissions. Click to access the wizard.

Wizard Map

The Assign Permission to Role wizard contains:

Select Permission Page > Assign Resources to Permissions Page > Confirmation Page.

  • ClosedSelect Permission Page

    This page may lead directly to the Confirmation page depending on whether the selected permission has resources attached.

    User interface elements are described below (when relevant, unlabeled elements are shown in angle brackets):

    UI Element

    Description
    <Permissions tree>

    Select a permission from the tree.

    Displays the pre-defined permissions. For details, see Pre-Defined Permissions.

  • ClosedAssign resources to permissions page

    This page only appears if the permissions are applicable for a resource.

    Note Click to access this page directly.

    User interface elements are described below (when relevant, unlabeled elements are shown in angle brackets):

    UI Element

    Description
    Permission A tree containing the permissions.

    Select a permission and use the arrows to move the required resources from the Available Resources list to the Selected Resources list.

    Available and Selected Resources Each permission can be applicable for specific resources, for all resources, or not applicable to a resource.
  • ClosedConfirmation Page

    User interface elements are described below (when relevant, unlabeled elements are shown in angle brackets):

    UI Element

    Description
    Permission The permissions assigned to this role.
    Resource The list of resources associated with the each permission.
    Add another

    Click to commit the current permission and continue in the wizard to add another permission. The Select Permission Page opens.

    Finish Click to commit the assigned permissions and finish wizard functions.
    Cancel Click to cancel the current assignment. All previous actions in the wizard are still valid.