In Metric Insights, the set of measures that limits Users' access to specific parts of the system is referred to as Security. It can be implemented by Admins or Power Users through Privileges and Permissions, which are assigned to Groups and individual Users.
Privileges and Permissions
There are two key concepts when it comes to Metric Insights security:
- Privileges, or functional access, define what a user can do in the system. For example, Privileges define the right to create Elements or Objects, manage other users, or add comments to Elements.
- Permissions, or content access, define what content a user can view or edit. These are applied to specific Objects, Categories, or Folders, allowing for granular control over content.
When it comes to Administrators, they can view and operate everything in the Metric Insights instance. However, when there's a need to allow Power Users or Regular Users to access something, they must receive a corresponding Privilege and Permission.
For example, for a Power User to be able to see a specific Category, they must receive the Privilege that allows Power Users to see Categories in general, as well as the Permission to view that chosen Category.
The set of Privileges and Permissions a User must be granted before they're able to view or edit any Object is described in detail in the chapters of the Controlling Access within Metric Insights manual.
Definitions
| Term | Definition |
|---|---|
| Object | An Element, Dataset, User Map, Reference Object, or configured item that is used in support of Metric Insights functionality; e.g., Metric, Category, Data Source, Template, Folder. |
| Privilege | A right granted to a Group or individual User that allows the member or User to perform specific Metric Insights functions or use non-configurable methods of fetching data; e.g., Create Folders, Create Datasets, Create Content using CSV files, Maintain Personal Settings. For more details on every Privilege, check the Privileges List. |
| Permission | A right granted to a Group or individual User that allows the member or User to access content; i.e., data contained in an Object. There are two types of Access: View Access and Edit Access. For more information about granting privileges, check the Assigning Privileges and Permissions article. |
| View Access | The type of access that permits a Regular or Power User to see content in an Element, Dataset/User Map, Dimension, or Category. |
| Edit Access | The type of access that grants a Power User the ability to edit an Object using its Editor. |
| User | A person who has an account in Metric Insights: There are four types of Users in Metric Insights: Admins, System Admins, Power Users, and Regular Users. For more details, check the What Types of Users Exist in Metric Insights? article. |
| Administrator (Admin) | The type of User that can perform any function in the system, maintain all types of Objects, and see all data; has all Privileges and Permissions automatically. |
| System Admin | The type of User that, besides the Admin capabilities, can also maintain System Variables and System Backups. |
| Power User (PU) | The type of User that, when given assigned Privileges and Permissions, can see selected elements and objects, organize their content into Favorites, Folders and Bursts, maintain personal settings, create content and maintain Objects that the PU creates or to which the PU has been granted Edit Access. |
| Regular User (RU) | The type of User that, based on assigned Privileges and Permissions, can View selected Elements and Objects, organize their content into Favorites, Folders and Bursts, and maintain personal settings but cannot create content or edit other Objects. |
| Group | Created to allow Members (Power Users and/or Regular Users) to inherit the same set of Privileges and Permissions that have been granted to the Group. There are three types of Group: Regular, Default and All Access. For more details about each type, see the Group Types Overview article. |