Summary of Power User Security changes (Version 5.1 - 5.3)

The tables below highlight Power User Capability changes from 5.1 through 5.3.

Data Sources

Power User Capabilities 5.1 5.2
Create a new Data Source
+
Grant another Power User ability to use or Edit the created Data Source from the Data Source Editor
+
Grant a Group's Power Users the ability to use or edit the created Data Source on the Group Editor
+

Groups

Power User Capabilities 5.1 5.2 5.2.1
Create a new Group
+ +
Add members to Group from Group Editor (never accesses User Editor)
+
+
Grant approved Privileges to Group; i.e., An Admin has enabled a Privilege for the instance and granted Power Users ability to assign to Groups
+
+
Grant Permissions to a Group when has Edit Access to these objects:  Dimensions, Dimension Values, Datasets, User Maps +
+
+
Grant Permissions to a Group when has Edit Access to these objects:   Categories, Elements, Data Sources
 + +
Edit Groups that Power User Created or to which Power User granted Edit access
  + +
Grant Permissions to a Group when has Edit Access to these additional objects:  Bursts,Data Dependencies, Data Collection Triggers


+
Grant Folder Permissions to a Group when creates or has Permission to Add/Remove Content from a Folder  


+

Categories

Power User Capabilities 5.1 5.2 5.3
Create a new Category +
+
+
Manage View or Edit access for Category content (at User or Group level)
+
+
Assign/Revoke edit access to other Power Users for a Category from the Category Editor
+
+
Restrict Categories that Power User can use when creating new elements or changing the Category of an existing object


+

Elements, Datasets and User Maps

Power User Capability 5.1 5.2 5.3
Create a new Element (Metric, Multi-Metric, Report, External Report, Ext. Content) +
+
+
Manage View or Edit access to an object (at User or Group level) when Power User has Edit Access to object

+
+
Assign/Revoke edit access to other Power Users for an Element from the object Editor
+
+
Only use Data Collection Triggers  to which Power User has Edit Access


+

Dimensions

Power User Capability  5.1 5.2 5.3
Create a new Dimension + +
+
Manage view access to a created Dimension (at User or Group level) +
+
+
Assign/Revoke edit access to other Power Users for the Dimension from the Dimension Editor +
+
+
Only associate Data Collection Triggers to which Power User has Edit Access


+
Only Edit Dimensions when  PU's have at least Use access to the Dimension's Data Source


+

Data Collection Triggers

Power User Capability 5.1 5.2 5.3
Create a new Data Collection Trigger

+
+
Manage view access to a Trigger with Edit Access (at User or Group level)

+
+
Assign/Revoke edit access to Groups and other Power Users for the  Trigger from the Trigger Editor only if Power User has Edit Access

+
+
Only associate Data Collection Triggers to which Power User has  Edit  Access with elements, Datasets,  User Maps, Dimensions and Event  Calendars


+
Only associate Data Collection Triggers to which Power User has  Edit Access with Data Dependencies


+

Data Dependencies

Power User Capability 5.1 5.2 5.3
Create a new Data Dependency
  +
+
Manage view access to a created Data Dependency (at User or Group level)
  +
+
Assign/Revoke edit access to Groups and other Power Users for the Data Dependency from the Data Dependency Editor

+
+
Only associate Data Collection Triggers to which Power User has Edit Access with the Data Dependency


+

Bursts

Power User Capability 5.1 5.2
Create a new Burst containing content to which Power User has at least full View Access
  +
Manage view access to a created Burst (at User or Group level)   +
Share Bursts with Groups of which Power User is a member and other members of those Groups
  +

Folders

Power User Capability 5.1 5.2
Create a new Folder containing content to which Power User has at least full View Access

+
Share a Folder with Users or Groups according to Privileges (implied or Extended)

  +

Shared Drives & FTP Connections

Power User Capability 5.1 5.2
Receive Permission to use a Shared Drive created by an Admin
+
+
Create a FTP Connection for use by self
+
+



Extend Power User's Privileges to Grant Edit/View Access to All Groups/Users

Power User Capability 5.1 5.2 5.2.1 5.3
Power users without "Grant to All" Privilege



Grant Dimension View or Edit Access to Groups of which Power User is a Member and Users within those Groups +
+
+
+
Grant Dataset/User Map View or Edit Access to Groups of which Power User is a Member and Users within those Groups +
+
+
+
Grant Data Source Use or Edit Access to Groups of which Power User is a Member and Power Users within those Groups
+ +
+
Grant Category content View or Edit Access to Groups of which Power User is a Member and Users within those Groups
+
+
+
Grant Data Collection Trigger Use Access to Groups of which Power User is a Member and Users within those Groups


+
+
Grant Data Collection Trigger Edit access to Groups of which Power User is a Member and Users within those Groups



+
Grant Data Dependency access to Groups of which Power User is a Member and Users within those Groups


+
+
Allow Power Users to Share Folders with Groups of which Power User is a Member and Users within those Groups


+
+
Power users with "Grant to All" Privilege



Grant Dimension View or Edit Access to all Groups and Users +
+
+
+
Grant Dataset/User Map View or Edit Access to all Groups and Users within those Groups +
+
+
+
Grant Data Source use or Edit Access to all Groups and Power Users within those Groups
+
+
+
Grant Category content View or Edit Access to all Groups and Users within those Groups
+
+
+
Grant Data Collection Trigger access to any User or Group


+
+
Grant Data Dependency access to Groups of which Power User is a Member and Users within those Groups


+
+
Share Folders with any User or Group


+
+

Underlying rules:

  • Power Users can only grant View or Edit Access to objects to which the Power User has Edit Access.
  • Regular Users
    • never receive Edit Access; only View Access to Dimensions, Dimension Values, Datasets/User Maps, and Category content
    • cannot use or edit Data Sources
    • may be given Privileges to:
      • create Folders
      • add personal FTP Connections
      • grant Use of a Shared Drive
    • may create Bursts without any assigned Privilege
    • may share Folders and Bursts that they create with Groups to which they belong and to User Members of the same group(s)

0 Comments

Add your comment

E-Mail me when someone replies to this comment