Configuring security by using the Case administration client wizard

Draft comment:
This topic only applies to BAW, and is located in the BAW repository. Last updated on 2025-03-13 12:15
In the production environment, you configure security on the case management objects that are controlled by Content Platform Engine. You must also configure security on Content Platform Engine process services queues, rosters, and application spaces. For Case Client, you configure view and edit access to pages.

About this task

You can assign permissions to different users, groups, and roles to determine what areas and objects of a solution in a Content Cortex object store that these users can access. A set of permissions is called a security configuration. You can use the Case administration client to create a security configuration for a solution. You can also transfer that security configuration from a user-acceptance testing environment or a staging environment into a production environment. The Case administration client simplifies the process of setting up security for objects, users, groups, and roles.

To create or make changes to a security configuration by using the Case administration client, you must have administrator privileges. When you first create a security configuration, the administrators window in the security wizard is automatically populated with an entry, which is the current user who created the security configuration. This entry in the administrators window cannot be removed and is required to apply the configuration.

Attention: Add all users and groups that are required to administer solution deployment, security configuration, and audit configuration. Only the users and groups that you add as administrators with full control will be able to redeploy the solution, and reapply a security or audit configuration to the solution in the future.

Use the Case administration client in a test environment before you add those changes to a production environment. When you have applied and tested the security configuration in the test environment, migrate those changes to the production environment. Using the Case administration client in the test environment, export the security configuration. Then, in the production environment, use the Case administration client to import the security configuration.

Attention: Any changes that you make by using the Case administration client will overwrite existing security configurations.

The available settings in the wizard are the results of the solution design. The case types and roles that are displayed were created by the business analyst in Case Builder during the design of the solution. Based on the security plan for the solution, you use the wizard to assign permissions for each type of case worker. For example, you might want the case worker role to have permission to view and update cases. You might grant another role, case auditor, permissions to view cases only.

When you apply a security configuration for a solution, the following user permissions for the case operations (ICM_Operations) user are applied to the solution.

  • Case type class definition: Read, Create instance, Read permissions (this object only)
  • Deployed case type folder: Write (this object only). On this object and all children: View all properties, Modify all properties, File in folder/Annotate, Unfile from folder, Create subfolder, Delete, Read permissions, Modify permissions, Modify owner, Change state
  • Deployed solution folder: Read (this object only)

Procedure

Configuring security for case solutions (workflow projects)

Procedure

  1. Start the IBM® Workflow Center. Enter the following URL in the browser:
    Enter the following URL in a browser:
    http://server:port/WorkflowCenter
    where server is the Workflow Center IP address or fully qualified server name, and
    port is the Workflow Center port number.
  2. Open the menu for the case solution (workflow project) that you want to apply the security configuration to. Click Advanced.
  3. On the Solutions page, select the solution for which to configure security.
  4. Click Actions > Manage > Security Configuration and complete the wizard steps.

Configuring security for legacy case solutions

Procedure

  1. Start the IBM Case Manager administration client.
    Enter the following URL in the browser:
    http://server:port/navigator/?desktop=bawadmin, where server is the IBM Content Navigator IP address or fully qualified server name, and
    port is the IBM Content Navigator port number.
  2. In the navigation tree, select a design object store and click Solutions.
  3. On the Solutions page, select the solution for which to configure security.
  4. Click Actions > Manage > Security Configuration and complete the wizard steps.