Managing security roles


As an administrator, you can manage security roles. Roles control the access rights to BMC AMI Products for Web functions. By default, a number of roles are provided to cover most situations. However, you can customize the existing roles or create new roles to suit your security needs.

Product roles and rights

The following table lists the default roles and the functions to which they have access or the ability to use.

Product

Default role

Function

BMC AMI Common Enterprise Services (CES)

CES Administrator

Access to CES configuration settings for Database, Host Connections, Certificates, Issue Tracking, Licensing, Personal Access Tokens, Update Center, Security, Web Server, and Webhooks.

Super Admin

Access to administrative functions for all BMC AMI Products for Web

Personal Access Tokens Administrator

Ability to add, edit, and delete Personal Access tokens

Workbench Team Profile Exporter

Ability to export Workbench team profiles to any group of which they are a member

Workbench Team Profile Administrator

Ability to view, add, and delete Workbench team profiles for all groups

BMC AMI iStrobe

iStrobe Administrator

Ability to use the functions in iStrobe Administration to configure and control access to iStrobe content, such as:

  • Submit Strobe Measurements
  • Strobe Administration
  • Use Performance Tracker
  • Folder Creation
  • Folder Management
  • Strobe Insight Reports Access

iStrobe Performance Tracker

Access to use the iStrobe Performance Tracker function

iStrobe User

Access to Submit Strobe Measurements and Folder Creation in iStrobe

BMC AMI DevX Code Pipeline

Code Pipeline Administrator

Access to manage Code Pipeline server connections for use in the Code Pipeline Web Interface, and access to Code Pipeline Administrator Area (until this is removed)

Code Pipeline User

Access to the Code Pipeline Web Deployment application, and to the Code Pipeline Mobile and Web applications.

Code Pipeline Approver

Access to the Code Pipeline Mobile and Web applications

Abend-AID

Abend-AID Administrator

Access to Abend-Aid web UIs.

BMC Compuware Topaz for Java Performance (TJP)

Topaz for Java Performance User

Full access to Topaz for Java Performance

BMC AMI DevX Total Test

Total Test Administrator

Ability to administer the Total Test Web client for components, including permissions to create, read, modify, delete, and execute components.

An administrator has permissions to create, update, and delete all test artifacts in the repository, including connections and environments.

Only selected users should have this role.

Total Test User

Access to the Total Test Web client, and to Workbench for Eclipse and the CLI functions that require information from the repository. Most users who are allowed to use Total Test should have this role.

Access to the Total Test Web client include the ability to create, read, modify, delete, and execute components.

BMC AMI Security Session Monitor

Session Monitor User

Full access to Session Monitor

BMC AMI Ops Automation for Batch ThruPut (BMC ThruPut Manager)

BMC ThruPut Manager User

Full access to BMC ThruPut Manager

On the Roles tab, you can view a list of configured roles, including the name of the role and a description of the role. For information about default roles, see Product roles and rights.

On the UI, you can move a column, refresh the table, delete one or more row entries, search and sort the values in the table, and choose how many records you want to view in the table. For more information about these actions, see Common-UI-actions.

You can also perform the following actions:

Purpose

Action

Add a security role and assign rights to it.

Click Add. For more information, see Adding-a-security-role.

Edit a role definition.

Click Edit.pngin the relevant row.


Important

You cannot edit or remove the CES Administrator and the Super Administrator roles.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*