Roles and permissions using BMC Helix Portal
BMC Helix Discoveryuses BMC Helix Portal to provide single sign-on authentication for users. In BMC Helix Portal, you can create and edit users and user groups, and assign any of the available permissions, such as creating, modifying, viewing, deleting, or managing objects. However, you cannot create new permissions.
For information on the BMC Helix Discovery permissions, see Managing groups.
As a tenant administrator in BMC Helix Portal, you can control access to various features available with the integrated products. Use the following information for assigning permissions to BMC Helix Discovery users.
| BMC Helix Discovery permission name | BMC Helix Portal permission name | Description | DSM Admin | DSM Discovery | DSM Service Creation | DSM Read Only |
|---|---|---|---|---|---|---|
| admin/dns/read | dsm.appliance.network | Enables you to view DNS information. | ✅️ | ✅️ | ||
| admin/interface/read | dsm.appliance.network | Enables you to view interface information from the Appliance Configuration page for network interfaces. | ✅️ | ✅️ | ||
| admin/interface/write | dsm.appliance.network | Enables you to modify interface information. | ✅️ | ✅️ | ||
| admin/log/delete | dsm.log.delete | Enables you to delete log files. | ✅️ | ✅️ | ||
| admin/log/info | dsm.log.read | Enables you to view log files. | ✅️ | ✅️ | ||
| admin/log/read | dsm.log.read | Enables you to view log files. | ✅️ | ✅️ | ||
| admin/loglevel/read | dsm.loglevel.read | Enables you to view the log level information. | ✅️ | ✅️ | ||
| admin/loglevel/write | dsm.loglevel.write | Enables you to change the log level information. | ✅️ | ✅️ | ||
| admin/mail/read | dsm.appliance.mail | Enables you to view email configuration information on the Appliance Configuration page. | ✅️ | ✅️ | ||
| admin/mail/write | dsm.appliance.mail | Enables you to modify email configuration information on the Appliance Configuration page. | ✅️ | ✅️ | ||
| admin/routing/read | dsm.appliance.network | Enables you to view routing information. | ✅️ | ✅️ | ||
| admin/routing/write | dsm.appliance.network | Enables you to modify routing information. | ✅️ | ✅️ | ||
| api/access | dsm.api.access | Enables you to access the external APIs. | ✅️ | |||
| api/datastore/import | dsm.api.import | Enables you to access the data/import API, which enables you to import data into the BMC Helix Discovery datastore. | ✅️ | |||
| api/datastore/write | dsm.api.write | Enables you to access the data/write API, that enables you to modify almost all of the data in the BMC Helix Discovery datastore. Before granting this permission, ensure that you have read and understood the following warning: | ✅️ | |||
| api/event_source | dsm.data.event_source | Enables you to create events for any event source. | ✅️ | |||
| api/license_data | dsm.api.access | Enables you to access the external APIs. | ✅️ | |||
| ui/appmodelling/edit | dsm.model.edit | Enables you to edit the application and service models. | ✅️ | ✅️ | ✅️ | |
| ui/appmodelling/health | dsm.model.health | Enables you to change BMC Helix AIOps health indicators. | ✅️ | ✅️ | ✅️ | |
| ui/appmodelling/publish | dsm.model.publish | Enables you to publish the application and service models. You can also create and delete ModelRules, as well as shared flag overrides. | ✅️ | ✅️ | ✅️ | |
| appliance/backup | dsm.appliance.backup | Enables you to back up or restore an appliance. | ✅️ | ✅️ | ||
| appliance/info/read | dsm.admin.settings | Enables you to view the system configuration. | ✅️ | ✅️ | ✅️ | |
| appliance/info/write | dsm.admin.settings | Enables you to write system configuration. | ✅️ | ✅️ | ✅️ | |
| appliance/maintenance | dsm.appliance.power | Enables you to put the system into maintenance mode. | ✅️ | ✅️ | ||
| appliance/reboot | dsm.appliance.power | Enables you to reboot the appliance. | ✅️ | ✅️ | ||
| appliance/restart | dsm.appliance.power | Enables you to restart services. | ✅️ | ✅️ | ||
| appliance/shutdown | dsm.appliance.power | Enables you to shut down the appliance. | ✅️ | ✅️ | ||
| appliance/support | dsm.admin.support | Enables you to view the support information. | ✅️ | ✅️ | ||
| appliance/updatedevices | dsm.knowledge.update | Enables you to update devices. | ✅️ | ✅️ | ✅️ | |
| appserver/debug | dsm.ui.debug | Enables you to debug the appserver. | ✅️ | ✅️ | ||
| appserver/login | dsm.ui.login | Enables you to log in to the appserver. | ✅️ | ✅️ | ✅️ | ✅️ |
| appserver/sessionaccess | dsm.admin.users | Enables you to access session information. | ✅️ | ✅️ | ||
| baseline/admin | dsm.baseline.admin | Enables you to change the baseline configuration. | ✅️ | ✅️ | ||
| baseline/read | dsm.baseline.read | Enables you to view the baseline configuration from the Baseline page. | ✅️ | ✅️ | ||
| baseline/update | dsm.baseline.write | Enables you to modify the baseline configuration. | ✅️ | ✅️ | ||
| admin/category/createmodify | dsm.admin.category | Enables you to create and modify categories from the Custom Categories page. | ✅️ | ✅️ | ||
| admin/channel/read | dsm.admin.dashboard | Enables you to view channels from the Channels page. | ✅️ | ✅️ | ||
| admin/channel/write | dsm.admin.dashboard | Enables you to write channels from the Channels page. | ✅️ | ✅️ | ||
| cluster/management | dsm.appliance.cluster | Enables you to perform cluster management operations. | ✅️ | ✅️ | ||
| cmdb_sync | dsm.cmdb.sync | Enables you to configure and manage CMDB synchronization. | ✅️ | ✅️ | ✅️ | ✅️ |
| consolidation/consolidation/write | dsm.discovery.consolidation | Enables you to change the configuration on the consolidation appliance. | ✅️ | ✅️ | ✅️ | |
| consolidation/discovery/write | dsm.discovery.consolidation | Enables you to configure consolidation appliances. | ✅️ | ✅️ | ✅️ | |
| consolidation/read | dsm.discovery.consolidation | Enables you to view the configuration on the consolidation appliance. | ✅️ | ✅️ | ✅️ | |
| discovery/credentials/test | dsm.credential.test | Enables you to test discovery credentials. | ✅️ | ✅️ | ✅️ | |
| discovery/filters/read | dsm.discovery.scripts | Enables you to view the discovery filters. | ✅️ | ✅️ | ✅️ | |
| discovery/filters/write | dsm.discovery.scripts | Enables you to modify the discovery filters. | ✅️ | ✅️ | ✅️ | |
| discovery/host/access | dsm.discovery.host | Enables you to capture the network device information. | ✅️ | ✅️ | ✅️ | |
| discovery/kslave/read | dsm.discovery.outposts | Enables you to view the Outposts. | ✅️ | ✅️ | ✅️ | |
| discovery/kslave/write | dsm.discovery.outposts | Enables you to modify the Outposts. | ✅️ | ✅️ | ✅️ | |
| discovery/options/read | dsm.discovery.options | Enables you to view the discovery options. | ✅️ | ✅️ | ✅️ | |
| discovery/options/write | dsm.discovery.options | Enables you to modify the discovery options. | ✅️ | ✅️ | ✅️ | |
| discovery/platforms/read | dsm.discovery.scripts | Enables you to view the discovery scripts. | ✅️ | ✅️ | ✅️ | |
| discovery/platforms/write | dsm.discovery.scripts | Enables you to modify discovery scripts. | ✅️ | ✅️ | ✅️ | |
| discovery/port/settings | dsm.discovery.options | Enables you to configure the port settings. | ✅️ | ✅️ | ✅️ | |
| external_data/ddd/read | dsm.data.external_consumers | Enables you to view the DDD external data configuration. | ✅️ | ✅️ | ||
| external_data/ddd/write | dsm.data.external_consumers | Enables you to modify the DDD external data configuration. | ✅️ | ✅️ | ||
| cluster/file_distribution | dsm.appliance.cluster | Enables you to distribute files to other cluster members. | ✅️ | ✅️ | ||
| admin/import/csv | dsm.data.import | Enables you to import CSV data from the Import CSV Data page. | ✅️ | ✅️ | ✅️ | ✅️ |
| model/audit/purge | dsm.audit.purge | Enables you to purge the audit log. You can purge the audit log of events older than one month (events less than one month old cannot be deleted) from the Audit Purge page. | ✅️ | ✅️ | ||
| model/audit/read | dsm.audit.access | Enables you to view the audit log. | ✅️ | ✅️ | ||
| model/datastore/internal/cluster | dsm.appliance.cluster | Enables you to use the internal cluster interface. | ✅️ | ✅️ | ✅️ | ✅️ |
| model/datastore/main/write | dsm.data_main.read | Enables you to view the datastore through the UI. | ✅️ | ✅️ | ✅️ | ✅️ |
| model/datastore/partition/%s/read | dsm.data_main.write | Enables you to modify the datastore through the UI. | ✅️ | ✅️ | ✅️ | ✅️ |
| model/search/cancel | dsm.search.admin | Enables you to cancel searches submitted by all users. | ✅️ | ✅️ | ||
| model/search/list | dsm.search.admin | Enables you to list searches submitted by all users. | ✅️ | ✅️ | ||
| model/taxonomy/nodekind/read | dsm.taxonomy.read | Enables you to view NodeKind information (node, relationship, and role). | ✅️ | ✅️ | ||
| model/taxonomy/nodekind/write | dsm.taxonomy.write | Enables you to modify NodeKind information (node, relationship, and role). | ✅️ | ✅️ | ||
| model/taxonomy/relkind/read | dsm.taxonomy.read | Enables you to view RelationshipKind information. | ✅️ | ✅️ | ||
| model/taxonomy/relkind/write | dsm.taxonomy.write | Enables you to modify RelationshipKind information. | ✅️ | ✅️ | ||
| model/taxonomy/rolekind/read | dsm.taxonomy.read | Enables you to view the RoleKind information. | ✅️ | ✅️ | ||
| model/taxonomy/rolekind/write | dsm.taxonomy.write | Enables you to modify the RoleKind information. | ✅️ | ✅️ | ||
| cluster/monitored_operation | dsm.appliance.cluster | Enables you to record and request the status of monitored operations. | ✅️ | ✅️ | ||
| reasoning/events/read | dsm.discovery.scan | Enables you to view the discovery scans. | ✅️ | ✅️ | ✅️ | |
| reasoning/events/write | dsm.discovery.scan | Enables you to modify the discovery scans. | ✅️ | ✅️ | ✅️ | |
| reasoning/open_scan | dsm.discovery.scan | Enables you to manage the open discovery scans. | ✅️ | ✅️ | ✅️ | |
| reasoning/pattern/config | dsm.knowledge.config | Enables you to configure patterns. | ✅️ | ✅️ | ✅️ | ✅️ |
| reasoning/pattern/execute | dsm.knowledge.execute | Enables you to run patterns through the UI. | ✅️ | ✅️ | ✅️ | ✅️ |
| reasoning/pattern/write | dsm.knowledge.update | Enables you to modify the pattern information (activate, delete, or compile). | ✅️ | ✅️ | ✅️ | ✅️ |
| reasoning/ranges/read | dsm.discovery.scan | Enables you to view the discovery scan ranges. | ✅️ | ✅️ | ✅️ | |
| reasoning/ranges/write | dsm.discovery.scan | Enables you to modify the discovery scan ranges. | ✅️ | ✅️ | ✅️ | |
| reasoning/start | dsm.discovery.control | Enables you to start reasoning. | ✅️ | ✅️ | ✅️ | |
| reasoning/startstop | dsm.discovery.control | Enables you to start and stop reasoning. | ✅️ | ✅️ | ✅️ | |
| reasoning/status | dsm.discovery.status | Enables you to view the reasoning status information. | ✅️ | ✅️ | ✅️ | ✅️ |
| reasoning/stop | dsm.discovery.control | Enables you to stop reasoning. | ✅️ | ✅️ | ✅️ | |
| reports/read | dsm.reports.read | Enables you to view and download report documents. | ✅️ | ✅️ | ✅️ | ✅️ |
| reports/saved_queries/write | dsm.reports.saved_queries | Enables you to modify user-saved queries. | ✅️ | ✅️ | ||
| appliance/reportsusage/reset | dsm.admin.support | Enables you to view the support information. | ✅️ | ✅️ | ||
| reports/write | dsm.reports.write | Enables you to create report documents. | ✅️ | ✅️ | ||
| security/group/read | dsm.discovery_security.groups | Enables you to view group membership for users. | ✅️ | ✅️ | ||
| security/group/write | dsm.discovery_security.groups | Enables you to modify group membership for users. | ✅️ | ✅️ | ||
| security/https/admin | dsm.appliance.network | Enables you to configure HTTPS on the appliance. | ✅️ | ✅️ | ||
| security/options/read | dsm.discovery_security.options | Enables you to view the security options, which include accounts and passwords, the login page, and the UI security page. | ✅️ | ✅️ | ||
| security/options/write | dsm.discovery_security.options | Enables you to configure the security options, which include accounts and passwords, the login page, and the UI security page. | ✅️ | ✅️ | ||
| security/sessions/view | dsm.admin.users | Enables you to view the list of active sessions. | ✅️ | ✅️ | ||
| security/user/activate | dsm.discovery_security.users | Enables you to activate the user account. | ✅️ | ✅️ | ||
| security/user/read | dsm.discovery_security.users | Enables you to view user security information. | ✅️ | ✅️ | ||
| security/user/write | dsm.discovery_security.users | Enables you to configure user security information. | ✅️ | ✅️ | ||
| system/configuration/read | dsm.admin.system | Enables you to view system configuration and settings. | ✅️ | |||
| system/configuration/write | dsm.admin.system | Enables you to write system configuration and settings. | ✅️ | ✅️ | ||
| system/licensing | dsm.admin.licensing | Enables you to view and modify licensing information. | ✅️ | ✅️ | ||
| system/settings/read | dsm.admin.settings | Enables you to view system configuration. | ✅️ | ✅️ | ✅️ | |
| system/settings/write | dsm.admin.settings | Enables you to write system configuration. | ✅️ | ✅️ | ✅️ | |
| ui/dashboard/admin | dsm.admin.dashboard | Enables you to modify channels from the Channels page. | ✅️ | ✅️ | ||
| ui/report/admin | dsm.search.query | Enables you to access the Generic Search Query page and enter search queries. | ✅️ | ✅️ | ✅️ | ✅️ |
| ui/taxonomy/admin | dsm.taxonomy.read | Enables you to view the taxonomy. | ✅️ | ✅️ | ✅️ | ✅️ |
| vault/close | dsm.discovery_vault.control | Enables you to close the credential vault from the Vault Management page of the UI. | ✅️ | ✅️ | ✅️ | |
| vault/credential_types/read | dsm.discovery_vault.read | Enables you to view the credential types | ✅️ | ✅️ | ✅️ | |
| vault/credentials/export | dsm.discovery_vault.export | Enables you to export the credential vault. | ✅️ | ✅️ | ||
| vault/credentials/read | dsm.discovery_vault.read | Enables you to view credentials. | ✅️ | ✅️ | ✅️ | |
| vault/credentials/write | dsm.discovery_vault.write | Enables you to modify credentials. | ✅️ | ✅️ | ✅️ | |
| vault/open | dsm.discovery_vault.control | Enables you to open the credential vault from the Vault Management page of the UI. | ✅️ | ✅️ | ✅️ | |
| vault/passphrase | dsm.discovery_vault.control | Enables you to set or change the passphrase for the credential vault. | ✅️ | ✅️ | ✅️ | |
data_cmdb_sync read | dsm.data_cmdb_sync.read | Enables you to read from the CMDBSync partition. | ✅️ | ✅️ | ✅️ | ✅️ |
data_cmdb_sync write | dsm.data_cmdb_sync.write | Enables you to write to the CMDBSync partition. | ✅️ |
|
|
|
data_default read | dsm.data_default.read | Enables you to read from the Default partition. | ✅️ | ✅️ | ✅️ | ✅️ |
data_default write | dsm.data_default.write | Enables you to write to the Default partition. | ✅️ |
|
| ✅️ |
data_import read | dsm.data_import.read | Enables you to read from the DDD and Import partitions. | ✅️ | ✅️ | ✅️ | ✅️ |
data_import write | dsm.data_import.write | Enables you to write to the DDD and Import partitions. | ✅️ |
|
|
|
data_internal read | dsm.data_internal.read | Enables you to read from the Internal partition. | ✅️ | ✅️ | ✅️ | ✅️ |
data_internal write | dsm.data_internal.write | Enables you to write to the Internal partition. | ✅️ |
|
|
|
data_other read | dsm.data_other.read | Enables you to view other data. | ✅️ | ✅️ | ✅️ | ✅️ |
data_other write | dsm.data_other.write | Enables you to modify other data. | ✅️ |
|
|
|
data_sensitive read | dsm.data_sensitive.read | Enables you to view sensitive data filters. | ✅️ |
|
|
|
data_sensitive write | dsm.data_sensitive.write | Enables you to modify sensitive data filters. | ✅️ |
|
|
|