{"id":68904,"date":"2025-03-17T13:41:22","date_gmt":"2025-03-17T05:41:22","guid":{"rendered":"https:\/\/oihelp.corporate.ifs.com\/help\/?page_id=68904"},"modified":"2025-03-19T11:27:33","modified_gmt":"2025-03-19T03:27:33","slug":"securing-tags","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/securing-tags\/","title":{"rendered":"Securing Tags"},"content":{"rendered":"\n<p class=\"left-bar\">This article applies to versions 4.19 and later of IFS OI Explorer. For more, see <a href=\"#Release_History\">Release History<\/a>.<\/p>\n<p class=\"note\"><strong>Note<\/strong>: Changing security for individual tags requires Server administrator privileges.<\/p>\n<p class=\"intro-text\">There are several options for securing tags.\u00a0<\/p>\n<ul class=\"intro-text\">\n<li>Security can be inherited from a <strong>Datasource<\/strong>. For tags added to the system via Tag Discovery, privileges can be applied at the datasource level, which will then be inherited by the tags from that datasource.\u00a0Additionally, more specific privileges can be applied to individual tags from that datasource.<\/li>\n<li>For tags not originating from a datasource (e.g. calculations), privileges are applied directly to the <strong>individual tags<\/strong>.<\/li>\n<li>Individual tags can also be added to <strong>Tag Groups<\/strong>, and secured at that level.\u00a0<\/li>\n<\/ul>\n<p class=\"intro-text\">These options are described below.<\/p>\n<h2 class=\"page-subheading\">Note on Inheritance<\/h2>\n<p class=\"intro-text\">Default object security provides the\u00a0<strong>Everyone<\/strong>\u00a0role with\u00a0<em>implicit<\/em>\u00a0view privileges for all objects in the system. When securing a Server object, you will need to remove the View privilege from the\u00a0<strong>resource,<\/strong>\u00a0as well as default\u00a0<strong>object<\/strong>\u00a0privileges for other roles.<\/p>\n<p class=\"intro-text\">When applying object-level privileges, it is important to remember the\u00a0<strong>cascading nature of privileges<\/strong>\u00a0applied at the resource-level. If a role has\u00a0<em>explicit<\/em>\u00a0View privileges (or higher) on the\u00a0<strong>resource<\/strong>, all users with that role can view all objects for that resource.\u00a0<\/p>\n<p class=\"left-bar-yellow\"><strong>TIP:<\/strong> If you intend on changing security for specific tags, avoid explicitly setting privileges on the relevant datasource, as it can result in over-complicated security scenarios.<\/p>\n<p class=\"left-bar-blue\">Related:\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-security-works\/\">How Security Works<\/a>,\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/\">How Roles Work<\/a>,\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/\">How Object Access Works<\/a>,\u00a0\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/add-an-administrator\/\">Add an Administrator<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">What the Privileges Mean<\/h2>\n<p class=\"intro-text\">Each resource may have different privileges. This is a list of the privileges for each resource, and what they mean.<\/p>\n<h3>Calculation Tags<\/h3>\n<p class=\"intro-text\">These privileges apply to calculation tags. They are independent of a datasource.<\/p>\n<table style=\"width: 100%;\">\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.7708%;\"><strong>Privilege<\/strong><\/td>\n<td style=\"width: 88.1251%;\"><strong>What it means<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.7708%;\">View<\/td>\n<td style=\"width: 88.1251%;\">See the calculation tag in Server Management and Explorer.\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.7708%;\">Edit<\/td>\n<td style=\"width: 88.1251%;\">Modify the calculation tag in Server Management and Explorer.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.7708%;\">Delete\u00a0<\/td>\n<td style=\"width: 88.1251%;\">Delete the calculation tag from Server Management.\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Datasources<\/h3>\n<p class=\"intro-text\">These privileges apply to the datasource, and are inherited by any tags associated with the datasource.<\/p>\n<table>\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Privilege<\/strong><\/td>\n<td><strong>What it means<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>View<\/td>\n<td>See the datasource and associated tags or datasets, in both Server Management and Explorer.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Write<\/td>\n<td>Write to the tags or datasets associated with a datasource, from Explorer.<\/p>\n<p><strong>Note<\/strong>: The Write flag on the datasource must be enabled for this to take effect. If the flag is not enabled, this privilege will have no effect.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Edit<\/td>\n<td>Modify the datasource and associated tags or datasets, in Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Delete\u00a0<\/td>\n<td>Modify the datasource and associated tags or datasets, from Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Dataset Tags<\/h3>\n<p class=\"note\"><strong>Note<\/strong>: Dataset tags cannot be added to a Tag Group.<\/p>\n<p class=\"intro-text\">These privileges apply to the datasource, and are inherited by any tags associated with the datasource.<\/p>\n<table style=\"width: 100%;\">\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.6666%;\"><strong>Privilege<\/strong><\/td>\n<td style=\"width: 88.3334%;\"><strong>What it means<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"width: 11.6666%;\">View<\/td>\n<td style=\"width: 88.3334%;\">See the dataset, in both Server Management and Explorer.\u00a0\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Timeseries Tags<\/h3>\n<p class=\"intro-text\">These privileges apply to tags from a Tag datasource. Depending on the datasource used, some privileges may not be available.<\/p>\n<table>\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Privilege<\/strong><\/td>\n<td><strong>What it means<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>View<\/td>\n<td>See the datasource and associated tags or datasets, in both Server Management and Explorer.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Write<\/td>\n<td>Write to the tags or datasets associated with a datasource, from Explorer.<\/p>\n<p><strong>Note<\/strong>: The Write flag on the datasource must be enabled for this to take effect. If the flag is not enabled, this privilege will have no effect.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Edit<\/td>\n<td>Modify the datasource and associated tags, in Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Delete\u00a0<\/td>\n<td>Modify the datasource and associated tags, from Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Tag Group<\/h3>\n<p class=\"intro-text\">These privileges apply to the tags in the group. Only timeseries and calculation tags can be added to a group.<\/p>\n<table>\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Privilege<\/strong><\/td>\n<td><strong>What it means<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>View<\/td>\n<td>See the datasource and associated tags or datasets, in both Server Management and Explorer.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Write<\/td>\n<td>Write to the tags or datasets associated with a datasource, from Explorer.<\/p>\n<p><strong>Note<\/strong>: If this is a Datasource Tag, the Write flag on the datasource must be enabled for this to take effect. If the flag is not enabled, this privilege will have no effect.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Edit<\/td>\n<td>Modify the datasource and associated tags, in Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td>Delete\u00a0<\/td>\n<td>Modify the datasource and associated tags, from Server Management.\u00a0\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>What the Colours Mean<\/h3>\n<p class=\"intro-text\">The privileges matrix is colour-coded to indicate the cascading nature of privileges. The colours are:<\/p>\n<p class=\"intro-text\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-37926 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-grey.png\" alt=\"\" width=\"20\" height=\"20\" \/> Grey: Privilege not granted.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-37927 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green.png\" alt=\"\" width=\"20\" height=\"20\" \/>\u00a0Green tick: Privilege is explicitly granted, associated privileges will also be automatically granted.\u00a0<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-37931 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green-dot.png\" alt=\"\" width=\"20\" height=\"20\" \/>\u00a0Green dot: Privilege is granted because a higher level privilege has been granted on the object.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-37928 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-blue.png\" alt=\"\" width=\"20\" height=\"20\" \/>\u00a0Blue: Privilege is granted because it is inherited by a resource privilege.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Tutorial 1. Securing a Datasource<\/h2>\n<p class=\"intro-text\">1. In Server Management, open the datasource for which you want to change the privileges.\u00a0<\/p>\n<p class=\"intro-text\">2. For each role, click the relevant privileges you want to assign.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-69986\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e.png\" alt=\"Screenshot showing privileges for a tag datasource\" width=\"1906\" height=\"1016\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e.png 1906w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-768x409.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-1536x819.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-150x80.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-600x320.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-1080x576.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-1280x682.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2de11e-48x26.png 48w\" sizes=\"auto, (max-width: 1906px) 100vw, 1906px\" \/><\/a><\/p>\n<ul class=\"intro-text\">\n<li>To\u00a0<strong>remove<\/strong> a privilege, click the green check icon. This will change to a grey cross icon.\u00a0<br \/>\n\u00a0<\/li>\n<li>To\u00a0<strong>grant<\/strong> a privilege, click the grey icon. This will change to a green check icon. Remember that privileges cascade from higher to lower levels, so a role with Edit privileges will also have View privileges.\u00a0<br \/>\n\u00a0<\/li>\n<li>Blue icons indicate an inherited\u00a0<em>Role Privilege<\/em>, which you cannot change from here.<\/li>\n<\/ul>\n<p class=\"intro-text\">3. When you have finished, click <strong>Save.<\/strong><\/p>\n<p class=\"intro-text\">All tags in this datasource will inherit these privileges.<\/p>\n<p class=\"left-bar-blue\">Related:\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/change-a-roles-privileges\/\">Changing a Role's Privileges<\/a>,\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/locking-down-an-object\/\">Locking Down an Object<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Tutorial 2. Individual Tags<\/h2>\n<p class=\"intro-text\">This applies to datasource tags and calculation tags which can be secured individually.<\/p>\n<p class=\"intro-text\">1. In Server Management, open the datasource for which you want to change the privileges.\u00a0<\/p>\n<p class=\"intro-text\">2. For each role, click the relevant privileges you want to assign.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-69987\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e.png\" alt=\"Screenshot showing privileges for a tag \" width=\"1906\" height=\"1008\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e.png 1906w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-768x406.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-1536x812.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-150x79.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-600x317.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-1080x571.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-1280x677.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_2e703e-48x25.png 48w\" sizes=\"auto, (max-width: 1906px) 100vw, 1906px\" \/><\/a><\/p>\n<ul class=\"intro-text\">\n<li>To\u00a0<strong>remove<\/strong> a privilege, click the green check icon. This will change to a grey cross icon.\u00a0<br \/>\n\u00a0<\/li>\n<li>To\u00a0<strong>grant<\/strong> a privilege, click the grey icon. This will change to a green check icon. Remember that privileges cascade from higher to lower levels, so a role with Edit privileges will also have View privileges.\u00a0<br \/>\n\u00a0<\/li>\n<li>Blue icons indicate an inherited\u00a0<em>Role Privilege<\/em>, which you cannot change from here.<\/li>\n<\/ul>\n<p class=\"intro-text\">3. When you have finished, click <strong>Save.<\/strong><\/p>\n<p class=\"intro-text\">These privileges will override those set at the datasource level.<\/p>\n<p class=\"left-bar-blue\">Related:\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/change-a-roles-privileges\/\">Changing a Role's Privileges<\/a>,\u00a0<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/locking-down-an-object\/\">Locking Down an Object<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Tutorial 3. Tag Groups<\/h2>\n<p class=\"intro-text\">A Tag Group is a collection of tags which all have the same View, Edit, Delete, and Write security privileges.<\/p>\n<p class=\"left-bar-yellow\"><strong>Note<\/strong>: Tag Groups must be explicitly enabled in the <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/explorer-admin\/serverconfig-xml\/\">ServerConfig.xml<\/a> file by setting <strong>TagGroupSecurityEnabled<\/strong> to true.<\/p>\n<p class=\"intro-text\">When Tag Groups are enabled, tags must be added to groups and the groups secured. Tags would not be able to be individually secured.<\/p>\n<p class=\"note\"><strong>Note<\/strong>: Tag Groups are only available for calculations and timeseries tags.<\/p>\n<p class=\"intro-text\">All tags are automatically added to a default \u201cAll Tags\u201d group, which can be assigned privileges as appropriate.<\/p>\n<p class=\"intro-text\">To further refine tag security via Tag groups:<\/p>\n<h3><strong>Create a Tag Group and Assign Tags in Bulk<\/strong><\/h3>\n<p class=\"intro-text\">Tag Groups are created in the Configuration <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6523 \" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/09\/configurationicon.png\" alt=\"\" width=\"20\" height=\"19\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/09\/configurationicon.png 30w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/09\/configurationicon-24x24.png 24w\" sizes=\"auto, (max-width: 20px) 100vw, 20px\" \/> section of Server Management.<\/p>\n<p class=\"intro-text\">1. Click <strong>Create New Tag Group<\/strong>, or click an existing group to edit it.\u00a0<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"border-image alignnone wp-image-69990 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271.png\" alt=\"Screenshot showing a list of tag groups\" width=\"1653\" height=\"942\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271.png 1653w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-768x438.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-1536x875.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-150x85.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-600x342.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-1080x615.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-1280x729.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4e2271-48x27.png 48w\" sizes=\"auto, (max-width: 1653px) 100vw, 1653px\" \/><\/a><\/p>\n<p class=\"intro-text\">2. Fill in the <strong>Name<\/strong> and <strong>Description<\/strong> for the tag group.<\/p>\n<p class=\"intro-text\">3. In the <strong>Assigned Tags<\/strong> section, move tags from the left to the right to add them to the tag group.<\/p>\n<p class=\"intro-text\">You can use the <strong>Filter by Datasource<\/strong> list to find all the tags in a specific datasource (including Calculations).<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-69991\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46.png\" alt=\"Screenshot showing the configuration of a tag group\" width=\"2706\" height=\"1319\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46.png 2706w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-768x374.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-1536x749.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-2048x998.png 2048w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-150x73.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-600x292.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-1080x526.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-1280x624.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_4eef46-48x23.png 48w\" sizes=\"auto, (max-width: 2706px) 100vw, 2706px\" \/><\/a><\/p>\n<p class=\"intro-text\">4. In the <strong>Tag Group Tag Privileges<\/strong> panel on the right, select the role privileges you want for this tag group.<\/p>\n<h3><strong>Assign a Datasource to\u00a0a Tag Group<\/strong><\/h3>\n<p class=\"intro-text\">You can assign a Datasource to a Tag Group. The advantage in doing this is that when new tags are discovered for the datasource, they will automatically be added to the tag group.<\/p>\n<p class=\"intro-text\">On the Datasource page in Server Management, the Tag Group Security option is located below the Tags list.<\/p>\n<p class=\"intro-text\">Choose one or more Tag Groups for the Datasource. The privileges specified for the Tag Group will apply to all tags from the datasource.\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-70006\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd.png\" alt=\"Datasource tag group security\" width=\"2487\" height=\"1250\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd.png 2487w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-768x386.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-1536x772.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-2048x1029.png 2048w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-150x75.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-600x302.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-1080x543.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-1280x643.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240802bd-48x24.png 48w\" sizes=\"auto, (max-width: 2487px) 100vw, 2487px\" \/><\/a><\/p>\n<h3><strong>Assign Individual Calculation Tags to a Tag Group<\/strong><\/h3>\n<p class=\"intro-text\">You can assign calculations of type Tag, to a Tag Group. You cannot assign dataset calculations to a tag group.<\/p>\n<p class=\"intro-text\">On the Calculation Configuration page in Server Management, the Tag Group Security option is located below the Type option.<\/p>\n<p class=\"intro-text\">Choose one or more Tag Groups for the calculation. The privileges specified for the Tag Group will apply to this calculation.\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da.png\" rel=\"lightbox-5\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-70007\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da.png\" alt=\"Calculation Tag Group security\" width=\"1832\" height=\"950\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da.png 1832w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-768x398.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-1536x797.png 1536w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-150x78.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-600x311.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-1080x560.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-1280x664.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_240ad9da-48x25.png 48w\" sizes=\"auto, (max-width: 1832px) 100vw, 1832px\" \/><\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Troubleshooting<\/h2>\n<p class=\"intro-text\">The following messages may appear in Server Management.<\/p>\n<h3>Tag Groups<\/h3>\n<p class=\"intro-text\">If you don't have sufficient privileges to create a Tag Groups, the Tag Groups page will display the message:<\/p>\n<p class=\"code-fragment\">There are no tag groups configured in the system.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106.png\" rel=\"lightbox-6\"><img loading=\"lazy\" decoding=\"async\" class=\"border-image alignnone wp-image-70016 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106.png\" alt=\"Tag Groups no tags configured\" width=\"1080\" height=\"285\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106-768x203.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106-150x40.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106-600x158.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242dd106-48x13.png 48w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/a><\/p>\n<h3>Entity Overview<\/h3>\n<p class=\"intro-text\">If a tag you don't have permissions to see is assigned to an entity that you <em>can<\/em> see, the Entity page will display the message:<\/p>\n<p class=\"code-fragment\">This page is read-only as you do not have sufficient privileges to edit this entity.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044.png\" rel=\"lightbox-7\"><img loading=\"lazy\" decoding=\"async\" class=\"border-image alignnone wp-image-70015 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044.png\" alt=\"Entity overview insufficient privileges\" width=\"1011\" height=\"344\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044.png 1011w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044-768x261.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044-150x51.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044-600x204.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2025\/03\/Snag_242d2044-48x16.png 48w\" sizes=\"auto, (max-width: 1011px) 100vw, 1011px\" \/><\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Release History<\/h2>\n<ul class=\"intro-text\">\n<li>Securing Tags 4.19.0\n<ul class=\"intro-text\">\n<li>Assign Calculation to a Tag Group Directly<\/li>\n<li>Tag Group Filter by Datasource<\/li>\n<\/ul>\n<\/li>\n<li>Securing Tags 4.17.1\n<ul class=\"intro-text\">\n<li>Initial release of group-based tag security<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This article describes the different ways in which tags can be secured.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/securing-tags\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":37939,"parent":3652,"menu_order":38,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[11],"tags":[1173,196,1261,1262],"class_list":["post-68904","page","type-page","status-publish","has-post-thumbnail","hentry","category-tutorial","tag-groups","tag-security","tag-tag-groups","tag-tag-security","Version-4-17-1","Version-4-19","Product-srv"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/68904","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=68904"}],"version-history":[{"count":52,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/68904\/revisions"}],"predecessor-version":[{"id":70034,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/68904\/revisions\/70034"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/37939"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=68904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=68904"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=68904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}