Create/Maintain Groups and Assign Privileges
For prior versions, please refer to Create/Maintain Groups and Assign Privileges (Prior to 5.2.1)
Privileges, as well as Permissions, assigned to a Group, are inherited by all Group members. Privileges govern whether or not a user can use certain features and/or and set selected personal Preferences. Permissions are used to grant access to specific objects and data.
The "Default Group" is the only Group that is created automatically when Metric Insights is first installed and, by default, all Users can be assigned to this Group when their account is created unless otherwise specified. The Default Group's Permissions represent the baseline access level that is provided to all users. Beginning with 5.3.0, a basic set of Privileges is automatically assigned to the Default Group for all new customers.
There is also a special type of group called an "All Access Group" that provides its members with View Access to view all elements and Dimensions in Metric Insights. You set this option using the checkbox on either the Group Editor or the User Editor.
A User may belong to one Group or multiple Groups. When assigned to multiple Groups, users inherit Privileges and Permissions from every Group of which they are members.
This article covers creating or maintaining a Group as well as assigning Privileges and Permissions.
In 5.3.0, Power Users have a new optional Privilege: Create Groups. With this Privilege, the Power User can create new Groups or be given Edit Access to the Group. Some functionality will not be available to the Power User when the user accesses the Group Editor but these will be noticeable since there are no "add" buttons.
1. Add or Edit a Group: Admin > Groups > Group List
- Choose Groups from the Admin menu
- To edit an existing Group and click on its Group Name (active link) to open the Group Editor
- To add a New Group to Add a New Group from the pop-up (see 1.1 below)
1.1. Add Group pop-up
On the Add Group popup:
- Name is required and must be unique
- All Access Group?: Change to "yes" if you want this group to have View access to all available elements and Dimensions
- LDAP Org. Unit: Complete if your organization uses Single Sign-on This will identify your LDAP connection
NOTE: To learn more about managing users/groups via LDAP, refer to Script for synchronizing/creating users with LDAP
External Group ID: Purely informational field
5. Save to access the Group Editor
6. A Group does not have to be granted any Privileges and/or Permissions at the time it is created; however, a warning message displayed when the Group Editor opens cautions the Admin. The initial ability of the Group's members to access content and perform system functions will be extremely constrained until the Group has been assigned at least minimum rights. These actions will allow Group members to benefit from Metric Insights.
2. Select Privileges
- Click [+ Privilege to Group] to open the Add Privileges pop-up
- Use Filter to select a specific Privilege
- Use Grouping to limit display
- Select All to choose all Privileges for the Group or
- Select individual Privileges using the boxes
3. Add Group Members
Users may be added:
- Manually or
- Using an input (CSV) file
3.1. Manually Add Users
- Use Search bar to narrow search
- Select the users via check-boxes
- [+ Add selected]
3.2. Add multiple Members via a CSV file
- Indicate the Delimiter your input file uses
- Enter full File name
- If this is an existing group, you can select to simply Add additional users or to Override (recreate the Group)
4. Assign Access to various Metric Insights objects
- Add Dimension via drop-down in pop-up (all or selected via option 2)
- Add Specific Dimension Values for each Dimension added above
- Adding by Category will add all of the elements contained in that Category
- Add elements individually
4.3. Datasets and User Maps
4.4. Other Access (new in version 5)
Portal Pages and Shared Drive sections are new in Release 5.2 - 5.3
4.5. Power Users (access assigned here only applies to Power Users)
The sections above all follow a similar format and contain buttons to allow Use, View or Edit Access Permissions for specific objects.
In addition to the access (Permissions) assigned here, some may also require specific Privileges be granted, see Understanding Power Users (Release 5.3 and beyond)
5. Assign Permission to Edit Group (applies to Power Users access only)
This function is ONLY available to Admins and Power Users with Edit Access
- Select User from the drop-down - only Power Users will be listed in this drop-down
The selected Power User must also have the Privilege "Create Groups" to be able to Edit this Group