Page tree

Unsupported content

   

This version of the documentation is no longer supported. However, the documentation is available for your convenience. You will not be able to leave comments.

Skip to end of metadata
Go to start of metadata

To manage and assign roles for user accounts, go to Administration > Users > Roles. The Roles page shows a summary table listing the currently defined user roles, their description, and the associated LDAP groups (if applicable). From this page you can add, edit, or delete user roles.

Every role is assigned one or more activity. To view information about a role, click the role name. The detail page for the selected role is displayed in the working area, listing all activities assigned to the role.

Each user can have different activities (access rights) associated with his account. An activity can be, for example, the ability to create a new model or analysis, or the ability to configure a domain. As single users may need to perform several activities, all privileges can be aggregated into custom groups called roles.

Tip

A role is a set of activities that a user can perform. A user can have one or more roles.

User accounts may have one or more of the following roles:

administrator

The user is allowed to perform any activity on the BMC TrueSight Capacity Optimization Console.

reporter

The user is allowed to create, modify and run standard reports.

analyzer

The user is allowed to create, modify and run analyses of system performances and business drivers.

configurator

The user is allowed to configure domains and systems and business drivers.

modeler

The user is allowed to create, modify and run models.

enterprise reporter

The user is allowed to create, modify, upload and run enterprise reports.

To learn how implement role-based access control to user accounts, and more about built-in roles and activities in BMC TrueSight Capacity Optimization, see:

To add a role

  1. Under Administration > Users > Roles, click Add role, and enter the following information:
    1. Name: A unique name for the role.
    2. (Optional) Description: A description for the role.
    3. Assign to all new users: To have this role automatically assigned to new users, select Automatically assign at user creation time.
    4. (Optional) External names: If you have configured LDAP user authentication, you can specify the names of LDAP groups to associate with this role, separated by a semi-colon (";").
    5. Activities: From the list of Available activities, select one or more (Click, Ctrl+click or Click+drag) activities to associate with the role, and then click .
      The activities you selected are now added to Selected.
    6. User roles/access groups edit restrictions: Use this option to control the creation of users based on roles and/or access groups.
      1. Allow user creation/edit with any role (default):Click to toggle to Restrict user creation/edit based on the following roles, and select one or more roles (Click, Ctrl+click or Click+drag) which will be allowed to create users, and click .
      2. Allow user creation/edit with any access group (default): Click to toggle to Restrict user creation/edit based on the following access groups, and select one or more access groups (Click, Ctrl+click or Click+drag) which will be allowed to create users, and click .
  2. Click Save.
    At this point, an Activity table is displayed that lists all activities you selected, and a description for each one of them. See Built-in roles and activities for more information on all available activities.
    Edit and Delete are also displayed that give you an option to either Edit your current role and the activities it contains, or to Delete it. (See illustration below)

To edit or delete a role

  1. Click a role to edit or delete from the Roles table. Alternately, you can also click the  buttons to perform these actions directly.
    The detail page for the selected role is displayed in the working area, listing all activities associated with the account.
  2. Click Edit or Delete.
    For Edit, the Edit role page is displayed. Make changes, and click Save.
    Clicking Delete will present a confirmation and information (only if you click the buttons directly) box. Click Proceed to delete the selected role.

Built-in roles and activities in BMC TrueSight Capacity Optimization

The following table lists the built-in activities and the built-in roles to which they are assigned:

Built-in activity

Description

Assigned to built-in roles

WEB_ANALYZE

View analyses saved in the Works folder

  • ADMIN
  • WORKSPACE-READER
  • WORKSPACE-EDITOR

WEB_MODEL

View models saved in the Works folder

  • ADMIN
  • WORKSPACE-READER
  • WORKSPACE-EDITOR

WEB_CONFIGURE

View active systems and business drivers associated with one or more domains

  • ADMIN
  • WORKSPACE-READER
  • WORKSPACE-EDITOR

WEB_RM

Access the Resource Monitor node in Administration

  • ADMIN
  • WORKSPACE-READER
  • WORKSPACE-EDITOR

WEB_EVENTS

Access the Event Manager node in Administration

  • ADMIN
  • WORKSPACE-READER
  • WORKSPACE-EDITOR

WEB_MODEL_EDIT

Add, edit and delete models

  • ADMIN
  • WORKSPACE-EDITOR

WEB_ANALYZE_EDIT

Add, edit and delete analyses

  • ADMIN
  • WORKSPACE-EDITOR

WEB_CONFIGURE_EDIT

Add, edit and delete domains, systems and business drivers

  • ADMIN
  • WORKSPACE-EDITOR

WEB_RM_EDIT

Add, edit and delete monitors and alert rules in Resource Monitor

  • ADMIN
  • WORKSPACE-EDITOR

WEB_EVENTS_EDIT

Add, edit and delete event rules in Event Manager

  • ADMIN
  • WORKSPACE-EDITOR

WEB_REPORT

View reports saved in Works

  • ADMIN
  • REPORTS-READER
  • REPORTS-EDITOR

WEB_REPORT_SEC

Access Reports

  • ADMIN
  • REPORTS-READER
  • REPORTS-EDITOR

WEB_REPORT_EDIT

Add, edit and delete reports

  • ADMIN
  • REPORTS-EDITOR

WEB_REPORT_PUBLISH

Publish or unpublish reports

  • ADMIN
  • REPORTS-EDITOR

WEB_DASHBOARD

Access the Console Views tab

  • ADMIN
  • VIEWS-READER
  • VIEWS-EDITOR

WEB_ADMIN_DASHBOARD

Have administrator privileges to views

  • ADMIN
  • VIEWS-EDITOR

WEB_ADMIN_GM_VIEW

View General Manager

N/A

WEB_ADMIN_GM_EDIT

Make changes using General Manager

N/A

WEB_ADMIN_IDENTRECONC

Perform reconciliation activities

ADMIN

WEB_ADMIN_EDIT

Edit the following Administration properties:

  • System > Configuration
  • System > Maintenance
  • Data warehouse
  • Scheduler > Instances
  • Data hub
  • Template management

ADMIN

WEB_ADMIN_TASKS_EDIT

Edit the following Administration properties:

  • Scheduler > Task groups
  • Scheduler > System tasks
  • Scheduler > ETL tasks

ADMIN

WEB_ADMIN_BENCHMARKS_EDIT

Edit the following Administration properties:

  • Benchmark management

ADMIN

WEB_ADMIN_REPORTING_EDIT

Edit the following Administration properties:

  • Tag management > Tagging rules
  • Advanced reporting

ADMIN

WEB_ADMIN

Access the Administration section

ADMIN

WEB_ANALYZE_TEMPLATE_EDIT

Add, edit and delete analysis templates

ADMIN

WEB_CALENDAR_EDIT

Modify the Administration calendar

ADMIN

WEB_CONFIGURE_ALL

Access the All Systems and Business Drivers node (inactive, dismissed or newly discovered entities)

ADMIN

WEB_LOADRUNNER_IMPORTER

Import Load Test results (requires Load Testing solution)

ADMIN

WEB_ADMIN_USERS_ACGROUPS_ASSIGNABLE

Manage user access groups from the Administration section

ADMIN

WEB_ADMIN_USERS_ASSIGNABLE

Manage user accounts from the Administration section

ADMIN

WEB_ADMIN_USERS_ROLES_ASSIGNABLE

Manage user roles from the Administration section

ADMIN

WEB_APPLVIEW_HOME

By default, access the Workspace section home page instead of the Console home page

ADMIN

API_CHARGEBACKAccess the chargeback section
  • ADMIN
  • API-CLIENT
API_DATAAccess the data section
  • ADMIN
  • API-CLIENT
API_SEARCHAccess the search section
  • ADMIN
  • API-CLIENT
WEB_ADMIN_AUTENTICATION_EDIT

Edit the following Administration section

  • Authentication
ADMIN
WEB_ADMIN_ETLAccess to administration ETLADMIN
WEB_ADMIN_TASKHave a administration privileges to taskADMIN
WEB_CONFIGUREAccess to configuration tabADMIN
WEB_REPORT_GLOBAL_CREATORAccess to Report Global CreatorADMIN
WEB_VPAccess to the Virtual PlannerADMIN

Related topics

Managing BMC TrueSight Capacity Optimization User administration

LDAP

Security