FAP user groups
You specify the permissions levels in Controller using Maintain > Rights > User. The access restrictions that you define in IBM Cognos Controller also apply in TM1. The access to one or more dimensions is determined by the Security Group limitations.
If an Initial Publish was performed in a previous Cognos Controller release, all users from the previous release will still exist on the TM1 server. If it is no longer required that some of those users be active in the TM1 server, the TM1 administrator must delete them.
The IBM Cognos Controller User group
IBM Cognos Controller User group members can use Controller and the IBM Cognos Controller Link for Microsoft Excel.
The IBM TM1 User group
IBM Cognos TM1 User group members can use TM1.
User names assigned to the IBM Cognos TM1 User group are copied over when you publish to the IBM Cognos Controller Financial Analytics Publisher.
IBM Cognos TM1 User group members can access Controller data in a published FAP cube in TM1 if they were granted access to the cube. An Initial Publish transfers all active TM1 users to the TM1 server. Inactive TM1 Users and inactive IBM Cognos Controller Users are not transferred to the TM1 Server.
The User Group Administrator group
User Group Administrator group members can use both Controller and TM1.
A member of the User Group Administrator group can change permissions for other users in his group, but not for the group itself. This type of user cannot change permissions for users on a higher level in the hierarchy than his own group. This option is not available for users who are assigned only to the IBM Cognos TM1 User group.