{"id":37842,"date":"2023-01-10T12:02:39","date_gmt":"2023-01-10T04:02:39","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=37842"},"modified":"2024-07-04T16:39:36","modified_gmt":"2024-07-04T08:39:36","slug":"how-roles-work","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/","title":{"rendered":"How Roles Work"},"content":{"rendered":"\n<p class=\"left-bar\">This article applies to versions 4.9.1 and later of IFS OI Explorer. For more, see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/#Release_History\">Release History.<\/a><\/p>\n<p class=\"overview\">IFS OI Explorer uses roles to assign privileges to a user. All users with a particular role will inherit the privileges assigned to that role.\u00a0<\/p>\n<p class=\"intro-text\">In order to be able to assign roles, a user must be a Security administrator.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-security-works\/\">How Security Works<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/create-a-role-with-privileges\/\">Create a Role with Privileges<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/change-a-roles-privileges\/\">Change a Role's Privileges<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Default Roles<\/h2>\n<p class=\"intro-text\">When IFS OI Explorer is first installed, there are two default roles: <strong>Administrators<\/strong> and <strong>Everyone.<\/strong>\u00a0<\/p>\n<ul class=\"intro-text\">\n<li>By default all users are assigned to the <strong>Everyone<\/strong> role, which has read access to all resources.<br \/>\n\u00a0<\/li>\n<li>Only the default admin user is initially assigned to the <strong>Administrators<\/strong> role, which provides administration privileges over all modules. Even though these privileges are added by default, they can be changed and deleted without affecting the functionality of IFS OI Explorer.<\/li>\n<\/ul>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/add-an-administrator\/\">Add an Administrator<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/default-security-for-everyone\/\">Default Security for Everyone<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Resource Role Privileges Matrix<\/h2>\n<p class=\"intro-text\">When we talk about role privileges as seen on the <strong>Role Privileges page<\/strong> in Server Management, we are specifically talking about <strong>module<\/strong> and <strong>resource<\/strong> level privileges and that is what this article will focus on.<\/p>\n<p class=\"left-bar\">Related: Object privileges are also granted via roles (see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/\">How Object Access Works<\/a>)<\/p>\n<p class=\"intro-text\">Module level privileges provide administrative access to all resources and objects for a particular module. A module is the part of the software that allows IFS OI Explorer to provide various capabilities. For example:<\/p>\n<ul class=\"intro-text\">\n<li><strong>Server:<\/strong> Makes the Data Dictionary and administrative functions available to other modules.<\/li>\n<li><strong>Explorer:<\/strong> Provides page and trend visualisations of live and historical data.<\/li>\n<li><strong>Sentinel:<\/strong> Makes Sentinel events available for analysis.<\/li>\n<li><strong>Commentary:<\/strong> Provides commentary capability to IFS OI Explorer.<\/li>\n<li><strong>Shift Log:<\/strong> Captures shift based operational information.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-58255 size-medium\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df-600x275.png\" alt=\"\" width=\"600\" height=\"275\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df-600x275.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df-768x352.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df-150x69.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df-48x22.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_200f5df.png 828w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p class=\"intro-text\">A <strong>resource<\/strong> is a collection of a particular type of object, such as workspaces. Each module has a set of resources that represent discrete objects within a module. E.g. The Explorer module has forms, styles, workbooks and workspaces resources.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-58263\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-600x577.png\" alt=\"\" width=\"1000\" height=\"962\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-600x577.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-768x739.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-150x144.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-1080x1039.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-1280x1231.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637-48x46.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_5963637.png 1308w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p class=\"intro-text\">The type of privilege that can be applied to a resource depends on the module - e.g. most resources have <strong>View<\/strong> privileges, but only the Sentinel module provides the <strong>Re-Run<\/strong> privilege on its workspaces resource.<\/p>\n<h3>Assigning Module Privileges<\/h3>\n<p class=\"intro-text\">When you assign a module level privilege - i.e. an Admin privilege - the corresponding resources in that module all inherit all of the privileges. The resource privileges show a blue circle with a dot. You cannot further refine the resource privileges because the module privilege overrides the resource privilege.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-58481\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01-600x519.png\" alt=\"\" width=\"750\" height=\"648\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01-600x519.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01-768x664.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01-150x130.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01-48x41.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_191fdd01.png 810w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h3>Assigning Resource Privileges<\/h3>\n<p class=\"intro-text\">You can assign resource privileges without a module level privilege by directly clicking the privilege against the resource. Note that privileges cascade here too, with the highest level privilege generally on the right, and the lowest on the left. When you assign a high level privilege, such as <strong>Delete,<\/strong> lower level privileges are also automatically granted when that privilege is required to perform the action. This is shown by a green circle with a dot.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-58484\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17-600x183.png\" alt=\"\" width=\"750\" height=\"228\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17-600x183.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17-768x234.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17-150x46.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17-48x15.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/01\/Snag_19403d17.png 1008w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h3>What the Colours Mean<\/h3>\n<p class=\"intro-text\">The privileges matrix is colour-coded to indicate the cascading nature of privileges. The colours are:<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-grey.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37926\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-grey.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Grey: Privilege not granted<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green.png\" rel=\"lightbox-5\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37927\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Green tick: Privilege is explicitly granted, associated privileges will also be automatically granted. <br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green-dot.png\" rel=\"lightbox-6\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37931\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green-dot.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Green dot: Privilege is granted because a higher level privilege has been granted on the resource.<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-blue.png\" rel=\"lightbox-7\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37928\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-blue.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a> Blue: Privilege is granted because it is inherited from a module privilege.<\/p>\n<hr \/>\n<h2>Release History<\/h2>\n<ul class=\"intro-text\">\n<li class=\"overview\">How Roles Work (this release, 4.9.1):\n<ul class=\"overview\">\n<li>Shift Log Administration Module<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"intro-text\">\n<li><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/how-roles-work-4-6\/\">How Roles Work (4.6)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A role defines a set of privileges for accessing a module's features. Privileges define the access levels for resources and their objects. When users and user groups are assigned to a role, they will be granted the privileges associated with that role. This page explains the relationship between roles and privileges, and how they apply to resources and objects.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":37843,"parent":3652,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[4],"tags":[637,634,636,633,196],"class_list":["post-37842","page","type-page","status-publish","has-post-thumbnail","hentry","category-explainer","tag-modules","tag-privileges","tag-resources","tag-roles","tag-security","Version-4-9-1","Product-ex"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=37842"}],"version-history":[{"count":10,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37842\/revisions"}],"predecessor-version":[{"id":67804,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37842\/revisions\/67804"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/37843"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=37842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=37842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=37842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}