Inheriting permissions by using hierarchical groups
Why to use hierarchical groups
BMC Helix ITSM uses the hierarchical group structure across companies and within companies::
Across companies—In a multi-tenant BMC Helix ITSM environment that contains multiple companies, some users might require access to ticket data of multiple companies. For example, if your organization opened new branches or if there is any other change in your organization, you must modify the user's access for each company, which might result in performance issues or maintenance challenges. By giving access to all the companies in a multi-tenant environment, you do not need to modify the user's access every time there is a change.
Hierarchical groups enable you to structure the companies hierarchically and assign the users to the required groups to provide them relevant ticket data access.
Within a company—In BMC Helix ITSM, ticket data access is managed at the support group level. There might be a need to extend this ticket data access to the support groups across your company. You can extend the ticket data access by creating a parent group and then defining the required support groups as children.
Before you begin
A user with Contact Administrator permissions can configure hierarchical groups across companies or support groups.
To configure hierarchical groups
To configure hierarchical groups, select Application Administration Console > Foundation > Advanced Options > Hierarchical Group Configuration and update the required information on the Hierarchical Group Configuration form. By using this form, you can add or remove a parent group for a company or a support group.
- You can simplify permission management by assigning a parent group to a group for which you want to give access to the data belonging to different groups.
- To create a parent-child hierarchy and maintain ticket data access efficiently between various support groups or companies, you must configure the required support group or company as a parent of the support groups or companies.
To unlink a parent group
Due to organizational restructuring or other reasons specific to your organization, you might have to remove the parent-child relationship between support groups or companies. When you remove the parent group of a company or support group, the parent group is no longer associated with the child group and hence cannot access the data of the child group.
- On the Hierarchical Group Configuration form, select the Parent Group For field, and then select the Company or Support Group option.
A list of companies or support groups is displayed.
- Select the required company or support group from the list.
- In the Parent Group Name field, select the Set as Blank check box to remove the parent group.
- Click Save.
The Parent Group Name column is displayed blank for the selected company or support group.
To correct or delete invalid parent groups
If duplicate and invalid entries with the same parent group, support group, or permission group ID exist in the CTM:SYS-Access Permission Grps or Group form, you might encounter an error when upgrading BMC Helix ITSM to a higher version. The upgrade might also fail due to the invalid and duplicate entries.
- Run the Configuration Check utility before upgrade, which verifies whether any duplicate and invalid entries exist in the CTM:SYS-Access Permission Grps or Group form.
- If duplicate and invalid entries exist in the CTM:SYS-Access Permission Grps or Group form, correct or delete them.