{"id":45089,"date":"2020-01-07T15:17:41","date_gmt":"2020-01-07T07:17:41","guid":{"rendered":"https:\/\/oihelp.corporate.ifs.com\/help\/?page_id=45089"},"modified":"2024-09-10T20:29:43","modified_gmt":"2024-09-10T12:29:43","slug":"sentinel-security","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/sentinel-security\/","title":{"rendered":"Sentinel Security"},"content":{"rendered":"\n<p class=\"intro-text\">Sentinel\u2019s security is managed in the IFS OI Server Management Security module.\u00a0<\/p>\n<h2 class=\"page-subheading\">Accessing Security<\/h2>\n<p class=\"intro-text\">To access the IFS OI Server Management, find out the URL for the IFS OI Explorer instance that Sentinel is using. This could be something like: <em>https:\/\/[P2 Server machine name]\/P2.Server.Management\/<\/em><\/p>\n<p class=\"intro-text\">You will need <strong>Security Administrator<\/strong> privileges to access the Security module.\u00a0<\/p>\n<p class=\"intro-text\">To open IFS OI Security, click the padlock icon on the left menu bar.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"672\" height=\"436\" class=\"wp-image-45091\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image.png 672w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-600x389.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-150x97.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-48x31.png 48w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\" \/><\/p>\n<h2 class=\"page-subheading\">Privileges<\/h2>\n<p class=\"intro-text\">The three sections of Security that are used for managing Sentinel\u2019s privileges are:<\/p>\n<ul class=\"intro-text\">\n<li><strong>Security Admin<\/strong>:\u00a0Used for managing Sentinel\u2019s (and other module\u2019s) users and roles, and for setting Sentinel privileges. Essentially all security functions are accessible to anyone with security Admin privileges.<\/li>\n<li><strong>Sentinel Admin Privileges<\/strong>:\u00a0The highest level of Sentinel security. The Sentinel Admin privilege encompasses several features, plus it cascades into all of Sentinel Resource level privileges.<\/li>\n<li><strong>Sentinel Resource Privileges<\/strong>:\u00a0More granular privileges are set here. For example, a particular Sentinel role can have the single privilege of <strong>User<\/strong> <strong>Processes<\/strong> <strong>Edit<\/strong> set at this level.<\/li>\n<\/ul>\n<p class=\"intro-text\">Details of these three sections are described below.<\/p>\n<h3>Security Admin Privilege<\/h3>\n<p class=\"intro-text\">Sentinel\u2019s security can only be updated by a user with the <strong>Security Admin<\/strong> privilege. For example, anyone with the default Administrators role, which has this privilege. (Note that a new role can also be created with the Security Admin privilege.)<\/p>\n<p class=\"intro-text\">Note that the default <strong>Administrators<\/strong> role also has <strong>Module<\/strong> <strong>Privileges<\/strong> for all modules, including the <strong>Sentinel Admin<\/strong> privilege.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"231\" class=\"wp-image-45092\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-1.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-1.png 428w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-1-150x81.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-1-48x26.png 48w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/p>\n<h3>Sentinel Admin Privilege<\/h3>\n<p class=\"note\">If you want a user to be able to import workspaces, folders, monitors and user processes, you need to assign them to a role that includes the <strong>Sentinel<\/strong> <strong>Admin<\/strong> module privilege.<\/p>\n<p class=\"intro-text\">The <strong>Sentinel Admin<\/strong> module privilege is located near the top of the privileges panel for the different roles.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"1250\" height=\"421\" class=\"wp-image-45093\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2.png 1250w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2-600x202.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2-1080x364.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2-150x51.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2-768x259.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-2-48x16.png 48w\" sizes=\"auto, (max-width: 1250px) 100vw, 1250px\" \/><\/p>\n<p class=\"intro-text\">The <strong>Sentinel Admin<\/strong> module privilege allows the following functionality to all roles that have this privilege:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Area of Functionality<\/strong><\/td>\n<td><strong>Privileges to\u2026<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Private Workspaces<\/td>\n<td>\n<ul>\n<li>View private workspaces<\/li>\n<li>Set Security Roles in workspaces<\/li>\n<li>Set Approvers in workspaces (where Change Management is enabled)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Delete<\/td>\n<td>\n<ul>\n<li>Delete workspaces<\/li>\n<li>Delete folders<\/li>\n<li>Delete monitors<\/li>\n<li>Delete event views<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Import and Export<\/td>\n<td>\n<ul>\n<li>Import workspace, folder, monitor, user processes, Bulk Import<\/li>\n<li>Export workspace, folder, monitor, user processes, Bulk Export<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Sentinel Resource Privileges<\/h3>\n<p class=\"note\">If you want a user to be able to Re-run monitors, you need to assign them to a role that includes the Sentinel <strong>Workspaces<\/strong> <strong>Re-Run<\/strong> resource privilege.<\/p>\n<p class=\"intro-text\">Sentinel privileges at the resource level are also located in the Privileges page, for the different roles.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"725\" height=\"356\" class=\"wp-image-45095\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-4.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-4.png 725w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-4-600x295.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-4-150x74.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-4-48x24.png 48w\" sizes=\"auto, (max-width: 725px) 100vw, 725px\" \/><\/p>\n<p class=\"intro-text\">The <strong>Sentinel Admin<\/strong> module privilege allows the following functionality to all roles that have this privilege:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Sentinel<\/strong><\/td>\n<td><strong>View<\/strong><\/td>\n<td><strong>Edit<\/strong><\/td>\n<td><strong>Delete<\/strong><\/td>\n<td><strong>Approve<\/strong><\/td>\n<td><strong>Re-Run<\/strong><\/td>\n<td><strong>Clear Messages<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Events<\/strong><\/td>\n<td>-<\/td>\n<td>Edit events<\/td>\n<td>Delete events<\/td>\n<td>-<\/td>\n<td>-<\/td>\n<td>-<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>User Processes<\/strong><\/td>\n<td>-<\/td>\n<td>Add or Edit user processes<\/td>\n<td>Delete user processes<\/td>\n<td>-<\/td>\n<td>-<\/td>\n<td>-<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Workspaces<\/strong><\/td>\n<td>\n<ul>\n<li>View workspaces<\/li>\n<li>View events<\/li>\n<li>View event views<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>Add or Edit workspaces<\/li>\n<li>Add or Edit folders<\/li>\n<li>Add or Edit monitors<\/li>\n<li>Submit monitors for approval<\/li>\n<li>Unsubmit monitors<\/li>\n<li>Add or Edit event views<\/li>\n<\/ul>\n<\/td>\n<td>-<\/td>\n<td>Approve submitted monitors<\/td>\n<td>Re-Run monitors<\/td>\n<td>Clear messages<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>Workspace View Privileges<\/h4>\n<p class=\"intro-text\">If you want to set workspace view privileges at the workspace level for a particular role, then you can edit the workspace and select that role in the Security Settings list for that workspace. Follow the instructions in the IFS OI Sentinel User\u2019s Guide, in the <strong>Workspace Security Roles<\/strong> section.<\/p>\n<p class=\"intro-text\">To grant a role privileges at this level, you should ensure that the <strong>Workspace View<\/strong> privilege is deselected at the Sentinel resource level, for that role, otherwise the role will have view privileges for each and every public workspace, regardless of individual workspace settings.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"667\" height=\"150\" class=\"wp-image-45096\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76c840.png\" alt=\"C:\\Users\\gxl1129\\AppData\\Local\\Temp\\SNAGHTML76c84073.PNG\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76c840.png 667w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76c840-600x135.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76c840-150x34.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76c840-48x11.png 48w\" sizes=\"auto, (max-width: 667px) 100vw, 667px\" \/><\/p>\n<p class=\"note\">Note: To set workspace view privilege at the workspace level in Sentinel, you need the <strong>Sentinel<\/strong> <strong>Admin<\/strong> privilege.<\/p>\n<h4>Approve Privileges<\/h4>\n<p class=\"intro-text\">If you want to set workspace approver privileges at the workspace level for a particular role, then you can edit the workspace and select that role in the Approvers list for that workspace. Follow the instructions in the IFS OI Sentinel User\u2019s Guide, in the <strong>Workspace Approvers<\/strong> section.<\/p>\n<p class=\"intro-text\">To grant a role privileges at this level, you should ensure that the <strong>Workspace Approve<\/strong> privilege is deselected at the Sentinel resource level, for that role, otherwise the role will have approve privileges for each and every public workspace, regardless of individual workspace settings.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"667\" height=\"150\" class=\"wp-image-45097\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76ca66.png\" alt=\"C:\\Users\\gxl1129\\AppData\\Local\\Temp\\SNAGHTML76ca669f.PNG\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76ca66.png 667w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76ca66-600x135.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76ca66-150x34.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/c-users-gxl1129-appdata-local-temp-snaghtml76ca66-48x11.png 48w\" sizes=\"auto, (max-width: 667px) 100vw, 667px\" \/><\/p>\n<p class=\"note\">Note: To set workspace approve privilege at the workspace level in Sentinel, you need the <strong>Sentinel<\/strong> <strong>Admin<\/strong> privilege.<\/p>\n<h3>Server Entities View Privilege<\/h3>\n<p class=\"intro-text\">The Server Entities <strong>View<\/strong> privilege relates to entities in Server, and can be assigned at the resource level (Server Entities View). Roles with this privilege allow Case editing and viewing for all entities. Roles with View privileges assigned at entity level allow Case editing and viewing for those entities only.<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"645\" height=\"314\" class=\"wp-image-45098\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-5.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-5.png 645w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-5-600x292.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-5-150x73.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-5-48x23.png 48w\" sizes=\"auto, (max-width: 645px) 100vw, 645px\" \/><\/p>\n<h3>Comparing Security Roles in Sentinel 4.6 versus Sentinel 4.1.7<\/h3>\n<p class=\"intro-text\">In Sentinel 4.1.7 and earlier, privileges were defined in the <strong>SentinelConfig<\/strong> file, with default roles allocated to them.<\/p>\n<ul style=\"list-style-type: none;\">\n<li>&lt;Param Key=\"SecurityRolesWorkspaceAdd\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesWorkspaceDelete\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesWorkspaceEdit\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesFolderAdd\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesFolderDelete\" Value=\"Sentinel Administrators,Sentinel Deleters\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesFolderEdit\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesMonitorAdd\" Value=\"Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesMonitorDelete\" Value=\"Sentinel Administrators,Sentinel Deleters\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesMonitorEdit\" Value=\"Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesMonitorReRun\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesEventEdit\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesEventDelete\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesEventViewAdd\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesEventViewEdit\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesEventViewView\" Value=\"Sentinel Administrators,Sentinel Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesMonitorStatusReportClearMessages\" Value=\"Sentinel Administrators\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesImport\" Value=\"Sentinel Importers\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesExport\" Value=\"Sentinel Exporters\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesUserProcessEdit\" Value=\"Sentinel Administrators,Sentinel Process Editors\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesUserProcessDelete\" Value=\"Sentinel Administrators,Sentinel Deleters\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesCaseViewer\" Value=\"Case Viewer\" \/&gt;<\/li>\n<li>&lt;Param Key=\"SecurityRolesCaseEditor\" Value=\"Case Editor\" \/&gt;<\/li>\n<\/ul>\n<p class=\"intro-text\">The table below shows the default privileges for Sentinel 4.1.7 and earlier (on the left), compare against the privileges in Sentinel 4.6 and later. Refer to this table when configuring the new security roles and privileges.<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Privilege in Sentinel 4.1.7 and Earlier<\/strong><\/td>\n<td><strong>Permission To\u2026<\/strong><\/td>\n<td><strong>Default Roles in 4.1.7 and Earlier<\/strong><\/td>\n<td><strong>Privilege in Sentinel 4.6 and Later<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesWorkspaceDelete<\/td>\n<td>Delete workspaces<\/td>\n<td>Sentinel Administrators<\/td>\n<td rowspan=\"5\">Sentinel Admin<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesFolderDelete<\/td>\n<td>Delete folders<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Deleters<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesMonitorDelete<\/td>\n<td>Delete monitors<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Deleters<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesImport<\/td>\n<td>&gt;Import workspaces, folders, monitors (includes bulk import)<\/td>\n<td>Sentinel Importers<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesExport<\/td>\n<td>Export workspaces, folders, monitors (includes bulk export)<\/td>\n<td>Sentinel Exporters<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesWorkspaceAdd<\/td>\n<td>Add workspaces<\/td>\n<td>Sentinel Administrators<\/td>\n<td rowspan=\"8\">Workspaces Edit<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesWorkspaceEdit<\/td>\n<td>Edit workspaces<\/td>\n<td>Sentinel Administrators<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesFolderAdd<\/td>\n<td>Add folders<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Editors<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesFolderEdit<\/td>\n<td>Edit folders<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Editors<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesMonitorAdd<\/td>\n<td>Add monitors<\/td>\n<td>Sentinel Editors<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesMonitorEdit<\/td>\n<td>Edit monitors<\/td>\n<td>Sentinel Editors<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesEventViewAdd<\/td>\n<td>Add event views<\/td>\n<td>Sentinel Administrators,<\/p>\n<p>Sentinel Editors<\/p>\n<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesEventViewEdit<\/td>\n<td>Edit event views<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Editors<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesMonitorReRun<\/td>\n<td>Re-run monitors<\/td>\n<td>Sentinel Administrators<\/td>\n<td>Workspaces Re-Run<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesEventViewView<\/td>\n<td>View event views<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Editors<\/td>\n<td>Workspaces View<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesMonitorStatusReportClearMessages<\/td>\n<td>Clear monitor status messages<\/td>\n<td>Sentinel Administrators<\/td>\n<td>Workspaces Clear Messages<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesUserProcessEdit<\/td>\n<td>Edit user processes<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Process Editors<\/td>\n<td>User Processes Edit<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesUserProcessDelete<\/td>\n<td>Delete user processes<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Deleters<\/td>\n<td>User Processes Delete<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesEventEdit<\/td>\n<td>Edit events<\/td>\n<td>Sentinel Administrators,<br \/>\nSentinel Editors<\/td>\n<td>Events Edit<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesEventDelete<\/td>\n<td>Delete events<\/td>\n<td>Sentinel Administrators<\/td>\n<td>Events Delete<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesCaseViewer<\/td>\n<td>View cases<\/td>\n<td>Case Viewer<\/td>\n<td rowspan=\"2\">* Server Entities View<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>SecurityRolesCaseEditor<\/td>\n<td>Edit cases<\/td>\n<td>Case Editor<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"intro-text\"><em>*Server Entities View privileges are set for Server\u2019s security. This is also in IFS OI Server Management. Refer to the section Server Entities View Privilege (above), for more information on this privilege.<\/em><\/p>\n<h2 class=\"page-subheading\">Security Roles<\/h2>\n<p class=\"intro-text\">There are two default roles in Security:<\/p>\n<p class=\"intro-text\"><strong>Administrators<\/strong>:\u00a0A default administrator role that has all privileges assigned.<\/p>\n<p class=\"intro-text\"><strong>Everyone<\/strong>: A default role that represents all authenticated users. When a new user is added to Security, the Everyone role is assigned to them.<\/p>\n<p class=\"intro-text\">In order to change anything in Security, you will need the <strong>Security Admin<\/strong> privilege. This comes with the <strong>Administrators<\/strong> role, or you can use any other role with this privilege.<\/p>\n<p class=\"intro-text\">All other roles need to be added. There might already be roles intended for the other modules (such as Explorer and Commentary), and there may be roles for Sentinel that have already been added by another Security Admin user.<\/p>\n<p class=\"intro-text\">We recommend adding some basic Sentinel roles, preferably prefixed by the word \u2018Sentinel\u2019, for example:<\/p>\n<ul>\n<li class=\"intro-text\">Sentinel Administrators<\/li>\n<li class=\"intro-text\">Sentinel Workspaces Administrator<\/li>\n<li class=\"intro-text\">Sentinel Viewer<\/li>\n<li class=\"intro-text\">Sentinel Process Editors<\/li>\n<li class=\"intro-text\">Sentinel Process Deleters<\/li>\n<\/ul>\n<h3>Creating a Role<\/h3>\n<p class=\"intro-text\">In our example, we will create a new Sentinel role for Sentinel Process Editors.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/create-a-role-with-privileges\/\">How to create a role<\/a><\/p>\n<p class=\"intro-text\"><strong>Example<\/strong>:<\/p>\n<ul>\n<li class=\"intro-text\">In the Security section, in IFS OI Server Management, click the <strong>Roles<\/strong> menu button, then create and save a new role called <strong>Sentinel Process Editor<\/strong>, with the description: <em>Sentinel Process Editors will be able to add and edit processes in Sentinel Studio.<\/em><\/li>\n<\/ul>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"1340\" height=\"567\" class=\"wp-image-45100\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7.png 1340w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-600x254.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-1080x457.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-150x63.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-768x325.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-1280x542.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-7-48x20.png 48w\" sizes=\"auto, (max-width: 1340px) 100vw, 1340px\" \/><\/p>\n<h3>Assigning Privileges<\/h3>\n<p class=\"intro-text\">Roles are assigned one or more privileges, which then get allocated to users with that role.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/change-a-roles-privileges\/\">How to update privileges for a role<\/a><\/p>\n<p class=\"intro-text\"><strong>Example<\/strong>:\u00a0Following the previous example, we will assign the <strong>Sentinel User Processes Edit<\/strong> privilege to the new Sentinel Process Editor.<\/p>\n<ul>\n<li class=\"intro-text\">In the Security section, in IFS OI Server Management, click the <strong>Privileges<\/strong> menu button, then edit the <strong>Sentinel Process Editor <\/strong>role, giving it the <strong>User Processes, Edit<\/strong> privilege.<\/li>\n<\/ul>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" width=\"1339\" height=\"943\" class=\"wp-image-45101\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8.png 1339w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-600x423.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-1080x761.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-150x106.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-768x541.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-1280x901.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-8-48x34.png 48w\" sizes=\"auto, (max-width: 1339px) 100vw, 1339px\" \/><\/p>\n<p class=\"intro-text\"><strong>Sentinel Privileges<\/strong><\/p>\n<p class=\"intro-text\">The Sentinel privileges are close to the bottom of the privileges panel. Locate the <strong>User<\/strong> <strong>Processes<\/strong> row, and the <strong>Edit<\/strong> column, and click the button in the intersecting position.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"667\" height=\"143\" class=\"wp-image-45102\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-9.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-9.png 667w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-9-600x129.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-9-150x32.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-9-48x10.png 48w\" sizes=\"auto, (max-width: 667px) 100vw, 667px\" \/><\/p>\n<p class=\"intro-text\">Before the privilege is set, it is a grey circle with a cross, indicating that this privilege has not been set<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"654\" height=\"144\" class=\"wp-image-45103\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-10.png\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-10.png 654w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-10-600x132.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-10-150x33.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-10-48x11.png 48w\" sizes=\"auto, (max-width: 654px) 100vw, 654px\" \/><\/p>\n<p class=\"intro-text\">After clicking, the grey circle turns to a green circle with a tick, indicating that the privilege has been set<\/p>\n<h4>Privilege Settings<\/h4>\n<p class=\"intro-text\">In Security, some of the privilege buttons are disabled, and cannot be reset. Others can be clicked on or off. Each privilege button is represented by a symbol, as explained below:<\/p>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Symbol<\/strong><\/td>\n<td>&nbsp;<\/td>\n<td><strong>Meaning<\/strong><\/td>\n<td><strong>Example<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Grey Cross (can click)<\/td>\n<td><img loading=\"lazy\" decoding=\"async\" width=\"20\" height=\"20\" class=\"wp-image-45104\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-11.png\" \/><\/td>\n<td>Privilege not granted<\/td>\n<td>The <strong>Workspaces<\/strong> <strong>Re<\/strong>-<strong>Run<\/strong> privilege has not been granted to this role.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Green Tick (can click)<\/td>\n<td><img loading=\"lazy\" decoding=\"async\" width=\"20\" height=\"20\" class=\"wp-image-45105\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-12.png\" \/><\/td>\n<td>Privilege is explicitly granted, and associated privileges will be automatically granted<\/td>\n<td>The <strong>Workspaces<\/strong> <strong>Approve<\/strong> privilege has been granted for this role.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Green Dot (cannot click)<\/td>\n<td><img loading=\"lazy\" decoding=\"async\" width=\"20\" height=\"20\" class=\"wp-image-45106\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-13.png\" \/><\/td>\n<td>Privilege is granted because a higher level privilege has been granted on the same resource<\/td>\n<td>The <strong>User Process Edit<\/strong> privilege is implied by the <strong>User Process Delete<\/strong> privilege, which has been granted for this role.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Blue (cannot click)<\/td>\n<td><img loading=\"lazy\" decoding=\"async\" width=\"20\" height=\"20\" class=\"wp-image-45107\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2020\/01\/word-image-14.png\" \/><\/td>\n<td>Privilege is granted because it is inherited from a module privilege (the <strong>Sentinel Admin<\/strong> privilege)<\/td>\n<td>The <strong>Sentinel Admin<\/strong> privilege has been granted for this role. This cascades into all of the Sentinel resource privileges.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Adding Sentinel Users<\/h3>\n<p class=\"intro-text\">In order to be able to add users, a user must be a Security administrator (someone with a role that has the <strong>Security<\/strong> <strong>Admin<\/strong> privilege). There are two ways to add a new user:<\/p>\n<p class=\"intro-text\"><strong>Adding Users with Active Directory<\/strong><\/p>\n<p class=\"intro-text\">Many of the users will be added automatically, using AD Sync. The AD Sync tool will automatically add all users in Active Directory that are configured to have access to IFS OI Explorer. For instructions on running the AD Sync tool, refer to the IFS OI Explorer Installation Guide.<\/p>\n<p class=\"intro-text\"><strong>Adding Users Manually<\/strong><\/p>\n<p class=\"intro-text\">You can manually add a user who can access IFS OI Explorer, using either their domain credentials or a user name and password.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/add-a-new-user\/\">How to add a user<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article describes how to manage Sentinel\u2019s security using the IFS OI Server Management Security module.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/sentinel-security\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":67943,"parent":3652,"menu_order":42,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[4],"tags":[196],"class_list":["post-45089","page","type-page","status-publish","has-post-thumbnail","hentry","category-explainer","tag-security","Product-sen"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/45089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=45089"}],"version-history":[{"count":23,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/45089\/revisions"}],"predecessor-version":[{"id":67824,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/45089\/revisions\/67824"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/67943"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=45089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=45089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=45089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}