Set Use Permissions for Policies

Policies are pre-set definitions that determine the level of access a user has to the Admin menu and certain Administrative functions. When assigned to a Role, the Policies determine which specific Admin menu items that users assigned to that Role have access to, and also whether they have access to the selected Design functions when they log in.

If a policy is granted for a particular branch of the Admin menu, then all operations below that branch are available, unless another policy explicitly revokes permissions to a menu item further down the branch.

You can only grant (or revoke) permissions if your Role can access the Policies branch of the menu.

You can only grant (or revoke) permissions to Roles at a lower level, or "rank", than your highest role. Rank refers to the level of administrative abilities of a Role (rather than a hierarchical level) - the higher the rank, the more administrative ability the Role has. The ranking of roles in SAI360 is:

  1. System Administrator
  2. Site Administrator
  3. All other roles.

For example if you are a member of the Application Administrator role, then you can grant or revoke policy use permissions for all Roles except System Administrator and Application Administrator. You cannot modify your own Role's policy use permissions - only higher roles can do this, so, in this example, only the System Administrator Role can grant or revoke permissions to the Application Administrator Role.

To set permissions for Admin menu items

  1. In the web application, select Designer Menu path separator Security Permissions Menu path separator Policies from the menu. A list of all security Policies is displayed.
  2. Double-click on the Policy you want to assign to a Role, or remove from a Role.

    The Policy Admin form is displayed.

    See the table below for a list of all policies and their related Admin menu items.

  3. Click Add New Roles. This opens the Policy Permission data entry page.
  4. Select one or more Roles from the selection list.

    Members of the Roles you select here will be able to see the Admin or Design menu, and the menu items relevant to the Policy selected in Step 2.

  5. Click OK to close the selection list.
  6. Click Save.
  7. Restart the web server to apply the changes.

Policies and their related Admin menu items

Policy

Admin Menu Item

Advanced Filtering - Build

Allows users to build their own User Filters. Rather than using this policy you should use the 'Build User Filters' role.

Clean Component

Gives user access to clear data from components. See:

Designer Menu path separator Configuration Management Menu path separator Clean Component

Edit List View

Allows users to build customized List Views. Rather than using this policy you should use the 'List View Edit' role.

See: User List Views

Filtering and View - Admin

Allows a user to administer User Filters and User List Views.

This will give the user access to menu items:

  • Admin Menu path separator User Defined Filters/Views Menu path separator User Defined Filters
  • Admin Menu path separator User Defined Filters/Views Menu path separator User Defined Views.

Maintain All Localities

Allows a user to create and maintain All Localities.

Gives user access to menu item:

  • Admin Menu path separator Localities Menu path separator All Localities.

Maintain Analytics

Allows a user to create or edit Analytics Rules.

Gives user access to menu item:

  • Designer Menu path separator Analytics Menu path separator Rules Builder
  • Designer Menu path separator Analytics Menu path separator Java Docs

Maintain API Keys

Allows a user to create API Keys.

After upgrade, this policy will be attached to the system role "Policy Role - Maintain API key".

Gives user access to menu item:

  • Designer Menu path separator Security Menu path separator API Key

Maintain Audit Log Admin

Allows a user to control the Audit Log settings.

Gives the user access to menu item:

  • Admin Menu path separator Audit Log Menu path separator ...

Maintain Component Filters

Allows a user to create and maintain Component Filters.

Gives the user access to menu item:

  • Designer Menu path separator Filters Menu path separator Component Filters.

Maintain Component Use Permissions

Allows a user to set Security Component Use Permissions.

Gives the user access to menu item:

  • Designer Menu path separator Security Menu path separator Component

Maintain Components

Allows users to Access the Designer Tools, allowing them to maintain fields and relationships for components.

Gives the user access to menu item:

  • Designer Menu path separator Component Management.

Note: Contact SAI360 if new components are required. Additional licence fees may apply.

Maintain Constants

Allows users to create and maintain user defined Constants.

Gives the user access to menu item:

  • Designer Menu path separator Constants Menu path separator ...

Maintain Dashboards

Allows the creation and maintenance of Dashboards.

Gives the user access to menu item:

  • Designer Menu path separator Dashboards Menu path separator Dashboard Designer

Maintain Default Locality

Gives the user the ability to Apply Default Locality for the entire system.

Gives the user access to menu item:

  • Admin Menu path separator LocalitiesMenu path separator Default Locality

Maintain Events/Imports/System Settings/Rollups

Gives the user access to maintain event types eg. Emissions, Sustainability emails, events. Menu item:

  • Designer Menu path separator Events

Gives the user access to maintain imports. Menu items:

  • Designer Menu path separator Imports Menu path separator Data Import
  • Admin Menu path separator Imports Menu path separator Import Status Dashboard
  • Admin Menu path separator Imports Menu path separator Import Trigger

Gives the user access to create Reminder List Groups. Menu item:

  • Designer Menu path separator Forms and Views Menu path separator Reminder List Groups

Gives the user access to rebuild rollup tables. Menu item:

  • Admin Menu path separator Tools Menu path separator Rebuild Rollup Tables

Maintain External API Tokens

Allows a user to create External API Tokens for use in Data Imports and Rest Callout form actions

Gives the user access to menu item:

  • Designer Menu path separator Security Menu path separator External API Tokens

Maintain Forms

Allows a user to design and maintain Forms, as well as List Views from within the Web Application.

Gives the user access to menu item:

  • Designer Menu path separator Forms and Views.

Note:
in addition to this Policy, you must assign the Role "Policy Role - Configuration Elements" to grant access to the Design Tools, since the policy only gives access to the menu item.

Maintain Global Settings

Allows a user to maintain the Global Settings for the system.

Gives the user access to menu item:

  • Admin Menu path separator Global Settings

Maintain Internationalization

Gives the user access to the Languages menu:

  • Designer Menu path separator Languages Menu path separator Export Localisation,
  • Designer Menu path separator Languages Menu path separator Import Localisation
  • Designer Menu path separator Languages Menu path separator Maintain Languages

Maintain Lookup Filters

Allows the user to add or modify Lookup Filters.

Gives the user access to menu item:

  • Designer Menu path separator Filters Menu path separator Lookup Filters

Maintain Lookups

Allows user to add and modify Lookups, and items within the lookups.

Gives the user access to menu item:

  • Designer Menu path separator Field Types Menu path separator Lookup

Maintain Matrices

Allows user to add and modify Matrices.

Gives the user access to menu item:

  • Designer Menu path separator Field Types Menu path separator Matrix

Maintain Policies Use Permissions

Gives the user power to administer Security Policies Use Permissions.

Gives the user access to menu item:

  • Designer Menu path separator Security Permissions Menu path separator Policies

Maintain Profiles

Grants access to create and maintain Profiles.

Gives the user access to menu item:

  • Admin Menu path separator Profiles

Maintain Security Roles

Grants access to maintain Security Roles.

Gives the user access to menu item:

  • Admin Menu path separator Security Menu path separator Security Roles

Maintain Terms of Use

Grants access to maintain the Terms of Use

Gives the user access to menu item:

  • Admin Menu path separator Terms of Use Menu path separator Terms of Use Admin

Maintain Users

Grants access to maintain Security Users.

Gives the user access to menu item:

  • Admin Menu path separator Security Menu path separator Security Users.

Maintain Views

Allows a user to apply component filters to Views.

Gives the user access to menu item:

  • Designer Menu path separator Forms and Views Menu path separator Views.

Monitoring

Grants access to all Monitoring activities.

Gives the user access to menu item:

  • Admin Menu path separator Monitoring Menu path separator ...

Questionnaire Administration

Allows a user to import and maintain Questionnaire Templates in the Web Application.

Gives the user access to menu item:

  • Admin Menu path separator Questionnaires Menu path separator Questionnaire Templates.

View Audit Log Entries

Allows a user to View Audit Log Entries.

Gives the user access to menu item:

  • Admin Menu path separator Audit Log Menu path separator Log Entries

Visualization Administration

Enables the user access the Visualization Admin area

Gives the user access to menu item:

  • Admin Menu path separator Visualization Menu path separator Visualizations Admin

Walkthrough Administration

Allows a user to create and maintain Walkthrough Templates in the Web Application.

Gives the user access to menu item:

  • Admin Menu path separator Walkthrough Menu path separator Walkthrough Templates.

Web Application Publish

Enables the user to perform a Publish.

Gives the user access to menu item:

  • Designer Menu path separator System Menu path separator Publish

See Also

Grant Use and Design Permissions to a Role

Set Use Permissions for Components

Set Permissions for BI User Console, BI Folders, Reports and Dashboards

API Keys

External API Tokens