Getting authorized to manage data permissions

You want to be able to assign permissions to teams so that users of these teams can access monitoring source data to create or visualize charts.

About this task

Zen UI permissions allow users to access Business Performance Center functions. Typically, to access the Data permissions tab, you need to have the Manage data access Zen permission through a Zen role.

Business Teams Service is used by Business Performance Center to retrieve the list of teams that you want to work with. To see teams in Business Performance Center, you need to have the permission to add or remove users from those teams in Business Teams Service.

When the parameter business_performance_center.all_users_access is set to true, all users are granted access to all data in the dashboards:
  • For production deployments, the parameter is set to false in the custom resource (CR).
  • For starter deployments, the parameter is set to true in the custom resource.
This parameter is documented in Business Performer Center parameters.

You retrieve teams definitions from Business Teams Service, and then you define permissions in the Zen authentication system.

Retrieving teams from Business Teams Service

About this task

To manage data access in Business Performance Center, you need to be in a Zen role with the Manage data access permission.

Results

Users can associate the available teams that they are allowed to administer in Business Teams Service (BTS) by adding or removing users. For more information, see the Business Teams Service External link opens a new window or tab documentation.
Note: Teams that are retrieved from Business Teams Service for a given user are cached for 15 minutes. As a consequence, that user might need to wait for up to 15 minutes to see the changes in Business Performance Center.

Assigning permissions by using Zen

About this task

For more information about Zen roles, see Managing roles External link opens a new window or tab page of the Cloud Pak Platform UI documentation.

Procedure

  1. Create a Zen role and assign the Manage data access Zen permission to that role.

    Alternatively, instead of creating a new role, you can use the Automation Developer Zen role, which already has the Manage data access Zen permission assigned to it.

    Users with this permission are allowed to manage access to data by associating teams with relevant monitoring sources from the Data permissions tab of the Business Performance Center graphical user interface.
    Tip: After you change a user's permission, make sure that you log out and then log back in.
  2. Assign users or user groups with that Zen role.

What to do next

You can now grant and restrict team access to chart business data by associating teams with relevant monitoring sources.