Change management permissions
Permission roles
Service Management applications use the concept of permissions groups to control access to the various BMC Helix ITSM or Smart IT applications such as forms, views, consoles, and functions. Permission groups are defined within the applications with a prescribed hierarchy. For example, the Master permission supersedes the User permission, which in turn supersedes the Submitter permission, which finally supersedes the Viewer permission. So, if you want to give access to a user to change requests, give access to one of these four permission group types depending on the requirements.
In addition to the above permission group types, you can use the Config permission group type for application administrative purposes in conjunction with any one of the above permission group types.
Infrastructure Change Master
The following sections describe the specific permissions and the level of access related to the Change Management application.
Infrastructure Change Master is an administrator for Change Management. This level of permission is the highest access level for creating and updating change requests.
Users with the Infrastructure Change Master permission can perform the following functions. For these functions, on the System Settings form, make sure that the value of Application permission model is set to Support group and company.
Functions |
Additionally, users with Infrastructure Change Master permission can perform the following administrative functions (the same as the Change Config User):
However, if the Application permission model is set to Support group, any user with this permission can perform the same functions as that of a Change Manager or a Change Coordinator that belong to the assigned support groups. |
---|---|
Best practice | Limit the use of these permissions to users performing a Change Manager role or a Change process owner who require full access to all the change requests. |
Application user license type? | Fixed and floating Important: We recommend that you provide AR System Fixed and Change User Fixed licenses, because the Infrastructure Change Master is always monitoring and fixing change requests. |
Infrastructure Change User
The Infrastructure Change Users perform the role of a Change Manager or Change Coordinator within the Change Management process. You should grant these permissions to users who perform the role of a support group lead within the Incident Management process or a problem coordinator role within the Problem Management process, or both, and who might need to modify changes that result from Incidents, Problems, or Known Errors. Additionally, these permissions should be granted to users who perform the role of a Continuity Manager.
An Infrastructure Change User who does not have the functional role of a Change Coordinator or a Change Manager for the assigned support group can modify the change request only until the change request is in the Planning In Progress stage (excluding changing the status). To execute the change request (changing the status), the user must have a functional role of a Change Coordinator or a Change Manager for the support group to which the change request is assigned.
For example, Allen has the functional role of a Change Coordinator for the BackOffice support group.
- When a change request is assigned to the BackOffice support group for the Change Coordinator Role, Allen can modify the change request and execute it to completion even if he is not directly assigned as the Change Coordinator for that change request.
When a change request is assigned to the FrontOffice support group, Allen can modify the change request only until the change request reaches the Planning In Progress status.
The Infrastructure Change User can edit tasks if this user belongs to the assigned support group for that task, even if the user does not belong to the assigned support group for that change. For example, if Allen does not belong to assigned support groups for a change request, but he belongs to a support group to which the task is assigned, he can edit that specific task (for example, he can add a CI to that task). A task can be edited by any change user if that user is a part of the assigned task group, irrespective of the status of the change request.
The following table lists the actions that the Infrastructure Change User can perform based on the permissions given to the user.
Permissions | Actions | ||||
---|---|---|---|---|---|
The user belongs to the Change Manager, Change Coordinator, or the Change Requester's support group to which the change is assigned | The user has the functional role of a Change Manager or Change Coordinator for the assigned support groups | The user belongs to the Task Assignee support groups | The user can edit the change request till the Planning In Progress stage (before the Planning is completed) | The user can execute the change till the Completion stage (change status of the change request) | The user can edit tasks beyond the Planning In Progress stage |
Yes | Yes | Yes | Yes | Yes | Yes |
Yes | Yes | No | Yes | Yes | Yes |
Yes | No | No | Yes | No | No |
Yes | No | Yes | Yes | No | Yes |
No | No | Yes | No | No | NA |
No | No | No | No | No | No |
Users with the Infrastructure Change User permission can perform the following functions:
Functions |
|
---|---|
Best practice | Grant this permission to users performing the role of a Change Manager or Change Coordinator within the Change Management process. Also, grant this permission to users who play the role of a Group Coordinator within the Incident Management or Problem Management processes, or both, because they might need to create and modify changes that result from incidents, problems, or known errors. |
Application user license type? | Fixed and floating |
Infrastructure Change Submitter
Users with Infrastructure Change Submitter permission can perform the following functions:
Functions |
Important:
|
---|---|
Best practice | Grant this permission to users who must submit and view change requests. Typically, these permissions are given to problem coordinators and IT specialists, who often create change requests. |
Application user license type? | Read |
Infrastructure Change Viewer
Users with the Infrastructure Change Viewer permission can perform the following functions:
Functions |
Important: Users with these permissions cannot submit or modify change requests. |
---|---|
Best practice | Grant this permission to users who need read-only access to view change requests. Typically, this permission should be given to most BMC Helix ITSM applications users (that is, users who do not already have the Master, User, or Submitter permissions), so that they will be able to access information about changes being made to their infrastructure. This permission is also required to perform quick searches on existing changes. |
Application user license type? | None |
Infrastructure Change Config
Users with the Infrastructure Change Config permission can perform all change administration functions that include the following four components:
Component | Functions |
---|---|
Change Management Configuration |
|
Foundation |
|
Requestor Console |
|
Task Management System |
|
Change Management Dashboard User
Users with Change Management Dashboard User permission can view the Change Management Dashboard form.