

Identifying case management users
When you identify the Content Platform Engine object stores that are
used for case management, you must identify the users that have access to these object stores. Your
users must have the appropriate access permissions on the object stores. The permissions that are
required vary depending on the user roles.
About this task
The groups or roles that are described in this task cover the main case management functions. If you are extending your system, you might need to create or designate more groups or roles.
Be
aware of the following best practices:
- Assign permissions to LDAP groups rather than individual users. How you assign users and groups can vary based on the directory service provider in your environment. Use the documentation that is provided for your directory server to identify case management groups.
- Create a case management master group to use for assigning access to object stores when you create the object store. Give this group Use object store permission. With this method, you can grant new users access to the object store by adding them to the master group. This approach can prevent issues with changing security on an established object store. For development environments, the master group can be #AUTHENTICATED-USERS. For a production environment, more controlled security is needed.
- Add the user associated with the ECM Technical User (EmbeddedECMTechnicalUser) role, as a member of the Solution administrators user group. The project and solution migration process configures this user as the owner of solution artifacts. For more information about the ECM Technical User (EmbeddedECMTechnicalUser) role, see Business Automation Workflow security roles. For more information about the Solution administrators group, see Planning for security in the development environment .
Procedure
To assign groups: