{"id":26640,"date":"2017-05-02T12:31:00","date_gmt":"2017-05-02T04:31:00","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=26640"},"modified":"2024-06-10T10:38:00","modified_gmt":"2024-06-10T02:38:00","slug":"application-and-global-roles","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/application-and-global-roles\/","title":{"rendered":"Application and Global Roles"},"content":{"rendered":"\n<p class=\"left-bar-yellow\">This article applies to P2 Explorer versions 4.3.0-4.5.5 ONLY. For the latest version, see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/\">Security<\/a>.<\/p>\n<p class=\"intro-text\">There are two types of roles in P2\u00a0Security: <em>Application Roles<\/em> and <em>Global Roles<\/em>. It's important to know the difference between the two in order to grant users access to advanced functionality (e.g. administrator access) in P2 applications.\u00a0<\/p>\n<p class=\"intro-text\"><strong>Application Roles<\/strong>\u00a0are roles that are automatically provided by an application, that combine several privileges on objects within that system, into a single role. \u00a0E.g.\u00a0The '<em>Explorer Administrator'<\/em>\u00a0role\u00a0in P2 Explorer allows access to the Settings page in P2 Explorer, as well as viewing audit logs and publishing directly to a workspace.<\/p>\n<p class=\"intro-text\">While Application Roles are specific to a single application, <strong>Global\u00a0Roles<\/strong> are more focused around the business. \u00a0Global Roles\u00a0exist across different applications, and map to the types of role that people perform in their business. \u00a0E.g. You may set up Accounting, Engineering, Management, IT etc.<\/p>\n<p class=\"intro-text\">Users are <strong>assigned<\/strong> to Global Roles, and the Global Roles can be <strong>mapped<\/strong> to the Application Roles, which transfers those application access privileges to users with that Global Role.\u00a0<\/p>\n<p class=\"note\">Note: Users belonging to a global role which has had a mapping change will need to log out and then log in again to notice any changes to their privileges.<\/p>\n<h2 class=\"page-subheading\">Application Roles<\/h2>\n<p class=\"intro-text\">An Application Role is created by an application such as P2 Explorer. These may vary from version to version as new features are added.<\/p>\n<h3>P2 Security<\/h3>\n<p class=\"intro-text\">P2 Security provides the following application roles:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Administration Inspector<\/strong><\/td>\n<td>Provides the ability to view all items in P2 Security Connect, however users with this role are unable to add, edit, or delete anything in P2 Security Connect.\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Administrator<\/strong>\u00a0<\/td>\n<td>Provides the ability to view, add, edit, and delete all items in P2 Security Connect.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>P2 Server<\/h3>\n<p class=\"intro-text\">P2 Server\u00a0provides the following application roles:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Editor<\/strong><\/td>\n<td>Allows users to view,\u00a0add, edit, and delete all items in P2 Server Management.\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Image Editor<\/strong><\/td>\n<td>Allows users in P2 Explorer to upload images via the Image Gallery, and store them in P2 Server. This role does not provide access to P2 Server Management.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Tag Editor<\/strong><\/td>\n<td>Allows users in P2 Explorer to save new calculations to P2 Server.\u00a0This role does not provide access to P2 Server Management.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>P2 Explorer<\/h3>\n<p class=\"intro-text\">P2 Explorer\u00a0provides the following application roles:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Explorer Administrator<\/strong><\/td>\n<td>\n<p>Allows users to import\/export pages and trends, view audit logs, publish directly to a workspace, and access the <em>Settings<\/em> function in P2 Explorer for administration of home pages.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6849\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings.png\" alt=\"\" width=\"238\" height=\"121\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings.png 238w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings-150x76.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings-24x12.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings-36x18.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/settings-48x24.png 48w\" sizes=\"auto, (max-width: 238px) 100vw, 238px\" \/><\/a><\/p>\n<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Explorer Style Administrator\u00a0<\/strong><\/td>\n<td>Allows users to create and modify styles in P2 Explorer.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Explorer Workspace Administrator<\/strong><\/td>\n<td>Allows users to create workspaces, approve submitted pages, and publish pages directly to a non-private workspace (i.e. any workspace other than \u2018My Workspace\u2019).<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/explorer-admin\/\">Setting Up an Explorer Administrator<\/a><\/p>\n<h3>Custom Applications<\/h3>\n<p class=\"intro-text\">Consuming applications are able to integrate their own custom configuration files with P2 Security. Custom applications can create their own application roles to enable user access to that system. The Application Roles for a custom application will be specific to that application.\u00a0<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Global Roles<\/h2>\n<p class=\"intro-text\">Global Roles are created by Security administrators. The point of a Global Role is to bundle access permissions for users and user groups with that role.<\/p>\n<p class=\"intro-text\">Global Roles can be used to represent specific categories of users in the business (e.g. Engineering, Operations, Management, IT). You can then associate one or more Application Roles with the Global Role. For example, you may want all users in the IT Global Role to have 'Explorer Administrator' (a <em>P2 Explorer<\/em> application role) privileges as well as 'Editor' (a <em>P2\u00a0Server<\/em> application role) privileges.<\/p>\n<h3>'Everyone' Default Global Role<\/h3>\n<p class=\"intro-text\">By default, the 'Everyone' Global Role is included in all P2 Explorer installations, and all users are automatically assigned to this role. The role\u00a0allows all users read and modify\u00a0access to all of P2 Explorer.<\/p>\n<p class=\"note\">Note: All users are automatically assigned to the 'Everyone' Global Role, even if that role does not exist. If this role is deleted or otherwise does not exist, you can create it manually to enable the ability to secure items and applications against this role.<\/p>\n<p class=\"intro-text\">The 'Everyone' role also allows administrators to specify a different global setting for anyone who accesses an application. For example, the Everyone role can be used to allow all users to view specific pages in P2 Explorer, but not edit them.<\/p>\n<p class=\"intro-text\">If you want to start restricting access to certain workspaces, pages, or trends, then you need to explicitly specify permissions in the\u00a0roles for the objects\u00a0you are securing.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Example Role Mapping Exercise<\/h2>\n<p class=\"intro-text\">Here is an example of a Super Administrator global role, that has all the application roles mapped. All users with the Super Administrator role will also have all of the mapped application roles. After the role mapping is done, you can go ahead and <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/user-management\/#Tutorial_1_Granting_Users_Permissions\">add users<\/a> to the global roles.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-26683\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings.png\" alt=\"\" width=\"523\" height=\"584\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings.png 523w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings-134x150.png 134w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings-21x24.png 21w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings-32x36.png 32w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/Example-role-mappings-43x48.png 43w\" sizes=\"auto, (max-width: 523px) 100vw, 523px\" \/><\/a><\/p>\n<p class=\"intro-text\">To map these roles, you will need to first add the global role, and then map the application roles.<\/p>\n<h3>Adding a Global Role<\/h3>\n<p class=\"intro-text\">1. In P2 Security, click <strong>Global Roles<\/strong> (under Administration on the left).<\/p>\n<p class=\"intro-text\">2. In the top right of the blue toolbar, click the Add <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3222 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/addbutton.png\" alt=\"addbutton\" width=\"18\" height=\"18\" \/>\u00a0button . \u00a0<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-26690\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create.png\" alt=\"\" width=\"1291\" height=\"362\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create.png 1291w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-768x215.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-150x42.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-1280x359.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-24x7.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-36x10.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-create-48x13.png 48w\" sizes=\"auto, (max-width: 1291px) 100vw, 1291px\" \/><\/a>\u00a0<\/p>\n<p class=\"intro-text\">3. In the <strong>Add Global Role<\/strong> dialog box, type the name and description for the new global role, and then click <strong>OK<\/strong>.<\/p>\n<p class=\"intro-text\">Note that Internal Name is required, and it must be unique and contain no spaces.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-26686 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1.png\" alt=\"\" width=\"500\" height=\"174\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1.png 500w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1-150x52.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1-24x8.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1-36x13.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/global-role-super-admin1-48x17.png 48w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p class=\"intro-text\">\u00a0The new global role 'Super Administrator' is created.<\/p>\n<p>&nbsp;<\/p>\n<h3>Mapping an Application Role to a Global Role<\/h3>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-26687\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin.png\" alt=\"\" width=\"1291\" height=\"686\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin.png 1291w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-768x408.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-150x80.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-1280x680.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-24x13.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-36x19.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2017\/05\/role-mapping-super-admin-48x26.png 48w\" sizes=\"auto, (max-width: 1291px) 100vw, 1291px\" \/><\/a>\u00a0<\/p>\n<p class=\"intro-text\">1. In P2 Security, click <strong>Role Mappings<\/strong> on the left.<\/p>\n<p class=\"intro-text\">2. In the <strong>Applications\u00a0<\/strong>box on the left, click the name of the\u00a0application containing the application roles you want to map (e.g. P2 Explorer).\u00a0You may need to wait a few seconds for the rest of the screen to refresh with the roles for the chosen application.<\/p>\n<p class=\"intro-text\">3. In the <strong>Application roles<\/strong> box on the right, click the application role you want to map (e.g. Explorer Administrator).<\/p>\n<p class=\"intro-text\">4. In the <strong>Other global roles<\/strong> box on the right, click the Global Role you just created (<strong>Super<\/strong>\u00a0<strong>Administrator<\/strong>).<\/p>\n<p class=\"intro-text\">5. Click the left arrow <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6873 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/securityleftarrow.png\" sizes=\"auto, (max-width: 26px) 100vw, 26px\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/securityleftarrow.png 26w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/securityleftarrow-24x24.png 24w\" alt=\"securityleftarrow\" width=\"26\" height=\"26\" \/>\u00a0button to add the selected application role to this global role.<\/p>\n<p class=\"intro-text\"><em>Repeat steps 2-5 to add more application roles to the global role.<\/em><\/p>\n<p class=\"intro-text\">6. Once all\u00a0roles have been mapped, click the <strong>Save<\/strong> button.\u00a0<\/p>\n<p class=\"note\">Now you can go ahead and <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/user-management\/#Tutorial_1_Granting_Users_Permissions\">add users<\/a> to the Super Administrator Global Role.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article explains the application roles in P2 Explorer, P2 Server, and P2 Security.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/application-and-global-roles\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":26641,"parent":26597,"menu_order":1,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[680],"tags":[196],"class_list":["post-26640","page","type-page","status-publish","has-post-thumbnail","hentry","category-security-4-3-0-4-5-5","tag-security","Version-4-5-0","Product-ex"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=26640"}],"version-history":[{"count":4,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26640\/revisions"}],"predecessor-version":[{"id":67102,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26640\/revisions\/67102"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26597"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/26641"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=26640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=26640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=26640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}