Creating and managing security groups
You can either create security groups or manage users first. But by creating security groups before you manage users, you ensure that you can immediately assign user permissions based on their specific business role. Create your security groups either from scratch, or by using samples based on roles that best describe your business users.
Security groups
Security groups control user access to sites, applications, and data within Maximo® Application Suite as a Service. The suite comes with a few predefined security groups, such as MAXADMIN and USERMANAGEMENT. You can log in with a user that belongs to these security groups to get started with your initial administration and user management tasks, or you can create users and security groups that work for you.

Navigating the user interface
Be aware of the following common entry points and navigation behaviors as you work through creating your own security groups, or creating security groups by using the sample security groups.

- Applications
- The first column contains the applications that you want to authorize and grant the appropriate types of access to each.
- Permissions
- The second column is updated to reflect the permissions that are available to grant after you select an application.
- Permissions selected
- The third column is updated to reflect the total number of permissions granted in the applications. This value is continuously updated for you to review as you enter each application's permissions. This number also reflects permissions that are selected by default before you select your own.

When you have finished creating a security group, the final Next button switches to a Done button to complete the wizard steps.

Creating your own security groups
As a best practice, implement a layered security approach that uses three types of security groups. Site access, application access, and data access. This layered model provides granular control while remaining manageable. Security groups can be inherited from parent groups or defined independently. Design security groups with narrow, role-specific scopes, then assign users to multiple groups as needed to build complete permission sets. This approach is more maintainable than creating broad security groups that attempt to cover multiple roles.
After you have decided on your user roles and how they map to security groups, create them in Maximo Application Suite as a Service:
- Log in to Maximo Application Suite as a
Service with the maxadmin
user.
The maxadmin user contains the correct permissions to create users and security groups because it is a member of the Users and Security Groups security groups.
- From the side navigation menu, select and then click Create group.
- On the Identity tab, specify a name and a default application and click
Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
- On the Applications tab, select the applications that you want to
authorize and grant the appropriate types of access to each and click
Next.Tip: Each application must be granted READ permission so that it is visible in the side navigation menu.If you save and exit, you can continue adding security groups information. Search for the group name that you created and then click edit.
- On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections and click Next.
- On the Users tab, add users to the group and click Next.
- On the Operational dashboard tab, add a dashboard for the group.
- Save your changes.
Alternatively, to help get you up and running faster, consider creating sample security groups if they closely match your business needs.
Sample security groups
- Administrator
- A security group that represents a user role with full system access and configuration privileges in Maximo Application Suite as a Service. Admins can manage users, configure applications, set up security groups, define workflows, and control system-wide settings. This role has unrestricted access to all modules and administrative functions.
- Supervisor
- A security group that represents a user role with management and oversight responsibilities in Maximo Application Suite as a Service. Supervisors can assign work orders, approve requests, review technician work, manage schedules, and monitor team performance. This role has elevated permissions to coordinate work activities and make operational decisions.
- Technician
- A security group that represents a user role responsible for working on maintenance and repair work in Maximo Application Suite as a Service. Technicians can view assigned work orders, update work status, record labor hours, report materials used, and complete maintenance tasks. This role focuses on hands-on work execution and documentation.
- Requester
- A security group that represents a user role that can create and submit service requests and work orders in Maximo Application Suite as a Service. Requesters can report issues, request maintenance services, track the status of their requests, and view work order progress. This role contains limited access. It is focused on initiating and monitoring work requests.
- Inventory Clerk
- A security group that represents a user role responsible for managing inventory operations in Maximo Application Suite as a Service. Inventory Clerks can receive materials, issue items, perform stock counts, adjust inventory balances, and manage storeroom transactions. This role focuses on maintaining accurate inventory records and supporting material management processes.
Sample security groups cheat sheet
| Administrator | Supervisor | Technician | Requester | Inventory Clerk |
|---|---|---|---|---|
| Operational Dashboard | Operational Dashboard | Operational Dashboard | Service Requests | Operational Dashboard |
| Map Manager | Technician | Meters | View Service Requests | Item Master |
| Work Queue Manager | Calendars | Meter Groups | Create Service Request | Service Items |
| Scheduler Data Manager | Condition Monitoring | Condition Monitoring | Tools | |
| Push Notification Administration | Labor | Failure Codes | Inventory | |
| AI Configuration | Failure Codes | Asset Manager | Count Books | |
| Security Groups | People | Reliability Strategies | Issues and Transfers | |
| Security Groups (Manage) | Asset Manager | Labor Reporting | Inventory Counting | |
| Users | Crafts | Quick Reporting | Service Requests | |
| Users (Manage) | Reliability Strategies | Technician | View Service Requests | |
| System Properties | Crew Types | Service Requests | Create Service Request | |
| Logging | Job Plans | View Service Requests | ||
| Domains | Crews | Create Service Request | ||
| Database Configuration | Routes | Work Approvals | ||
| Communication Templates | Classifications | |||
| Escalations | Inspections | |||
| Instant Messaging Configuration | Service Address | |||
| Inspection Forms | ||||
| Work Queue Manager | ||||
| Graphical Work Week | ||||
| Scheduler Data Manager | ||||
| Preventative Maintenance | ||||
| Master PM | ||||
| KPI Viewer | ||||
| Service Requests | ||||
| View Service Requests | ||||
| Create Service Request | ||||
| Assets | ||||
| View Assets | ||||
| Assets & locations | ||||
| Work Orders | ||||
| Work Order Tracking | ||||
| Locations | ||||
| Labor Reporting | ||||
| Quick Reporting | ||||
| Meters | ||||
| Meter Groups | ||||
| Work Approvals |
Creating the sample security groups
- Log in to Maximo Application Suite as a Service with the maxadmin user.
Creating the sample Administrator group
- From the side navigation menu, select and then click Create group.
- On the Identity tab:
- Enter the group name Administrator.
- Enter a group description. For example, A sample security group for administrators.
- Click Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
The Applications tab opens automatically after you create the sample Administrator group.
- In the Applications column, search for and click Operational Dashboard to get started with the sample Administrator security group.
- In the Permissions column, select each permission that applies to your
administrator. As a sample, select each permission available to you, as you can always revoke them
later. At a minimum, each application must be granted READ permission so that it is visible in the
side navigation menu.
The Permissions selected column is automatically updated to reflect the application permissions that you have selected.
- Stay in the Applications tab.
After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Map Manager.
- Continue to add all of the following applications from the cheat sheet until you have selected
each application's permissions for the sample Administrator group:
- Operational Dashboard (already completed during this sample)
- Map Manager
- Work Queue Manager
- Scheduler Data Manager
- Push Notification Administration
- AI Configuration
- Security Groups
- Security Groups (Manage)
- Users
- Users (Manage)
- System Properties
- Logging
- Domains
- Database Configuration
- Communication Templates
- Escalations
- Instant Messaging Configuration
- After you finished adding all the application permissions, click Next to go to restrictions.
- On the Restrictions tab, you can add restrictions to restrict access to
objects, attributes, and collections.
For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.
- On the Users tab, you can add users to the group and click
Next.
For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.
- On the Operational dashboard tab, add a dashboard for the group.
- Click Done to save your changes. A success message confirms your group changes.
Creating the sample Supervisor group
- From the side navigation menu, select and then click Create group.
- On the Identity:
- Enter the group name Supervisor.
- Enter a group description. For example, A sample security group for supervisors.
- Click Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
The Applications tab opens automatically after you create the sample Supervisor group.
- In the Applications column, search for and click Operational Dashboard to get started with the sample Supervisor security group.
- In the Permissions column, select each permission that applies to your
supervisor. As a sample, select each permission available to you, as you can always revoke them
later. At a minimum, each application must be granted READ permission so that it is visible in the
side navigation menu.
The Permissions selected column is automatically updated to reflect the application permissions that you have selected.
- Stay in the Applications tab.
After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Technician.
- Continue to add all of the following applications from the cheat sheet until you have selected
each application's permissions for the sample Supervisor group:
- Operational Dashboard (already completed during this sample)
- Technician
- Calendars
- Condition Monitoring
- Labor
- Failure Codes
- People
- Asset Manager
- Crafts
- Reliability Strategies
- Crew Types
- Job Plans
- Crews
- Routes
- Classifications
- Inspections
- Service Address
- Inspection Forms
- Work Queue Manager
- Graphical Work Week
- Scheduler Data Manager
- Preventative Maintenance
- Master PM
- KPI Viewer
- Service Requests
- View Service Requests
- Create Service Request
- Assets
- View Assets
- Assets & locations
- Work Orders
- Work Order Tracking
- Locations
- Labor Reporting
- Quick Reporting
- Meters
- Meter Groups
- Work Approvals
- After you finished adding all the application permissions, click Next to go to restrictions.
- On the Restrictions tab, you can add restrictions to restrict access to
objects, attributes, and collections.
For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.
- On the Users tab, you can add users to the group and click
Next.
For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.
- On the Operational dashboard tab, add a dashboard for the group.
- Click Done to save your changes. A success message confirms your group changes.
Creating the sample Technician group
- From the side navigation menu, select and then click Create group.
- On the Identity tab:
- Enter the group name Technician.
- Enter a group description. For example, A sample security group for technicians.
- Click Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
The Applications tab opens automatically after you create the sample Technician group.
- In the Applications column, search for and click Operational Dashboard to get started with the sample Technician security group.
- In the Permissions column, select each permission that applies to your
technician. As a sample, select each permission available to you, as you can always revoke them
later. At a minimum, each application must be granted READ permission so that it is visible in the
side navigation menu.
The Permissions selected column is automatically updated to reflect the application permissions that you have selected.
- Stay in the Applications tab.
After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Meters.
- Continue to add all of the following applications from the cheat sheet until you have selected
each application's permissions for the sample Technician group:
- Operational Dashboard (already completed during this sample)
- Meters
- Meter Groups
- Condition Monitoring
- Failure Codes
- Asset Manager
- Reliability Strategies
- Labor Reporting
- Quick Reporting
- Technician
- Service Requests
- View Service Requests
- Create Service Request
- Work Approvals
- After you finished adding all the application permissions, click Next to go to restrictions.
- On the Restrictions tab, you can add restrictions to restrict access to
objects, attributes, and collections.
For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.
- On the Users tab, you can add users to the group and click
Next.
For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.
- On the Operational dashboard tab, add a dashboard for the group.
- Click Done to save your changes. A success message confirms your group changes.
Creating the sample Requester group
- From the side navigation menu, select and then click Create group.
- On the Identity tab:
- Enter the group name Requester.
- Enter a group description. For example, A sample security group for requesters.
- Click Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
The Applications tab opens automatically after you create the sample Requester group.
- In the Applications column, search for and click Service Requests to get started with the sample Technician security group.
- In the Permissions column, select each permission that applies to your
requester. As a sample, select each permission available to you, as you can always revoke them
later. At a minimum, each application must be granted READ permission so that it is visible in the
side navigation menu.
The Permissions selected column is automatically updated to reflect the application permissions that you have selected.
- Stay in the Applications tab.
After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, View Service Requests.
- Continue to add all of the following applications from the cheat sheet until you have selected
each application's permissions for the sample Requester group:
- Service Requests (already completed during this sample)
- View Service Requests
- Create Service Request
- After you finished adding all the application permissions, click Next to go to restrictions.
- On the Restrictions tab, you can add restrictions to restrict access to
objects, attributes, and collections.
For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.
- On the Users tab, you can add users to the group and click
Next.
For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.
- On the Operational dashboard tab, add a dashboard for the group.
- Click Done to save your changes. A success message confirms your group changes.
Creating the sample Inventory Clerk group
- From the side navigation menu, select and then click Create group.
- On the Identity tab:
- Enter the group name Inventory Clerk.
- Enter a group description. For example, A sample security group for inventory clerks.
- Click Create group.
After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.
The Applications tab opens automatically after you create the sample Inventory Clerk group.
- In the Applications column, search for and click Operational Dashboard to get started with the sample Technician security group.
- In the Permissions column, select each permission that applies to your
inventory clerk. As a sample, select each permission available to you, as you can always revoke them
later. At a minimum, each application must be granted READ permission so that it is visible in the
side navigation menu.
The Permissions selected column is automatically updated to reflect the application permissions that you have selected.
- Stay in the Applications tab.
After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Item Master.
- Continue to add all of the following applications from the cheat sheet until you have selected
each application's permissions for the sample Technician group:
- Operational Dashboard (already completed during this sample)
- Item Master
- Service Items
- Tools
- Inventory
- Count Books
- Issues and Transfers
- Inventory Counting
- Service Requests
- View Service Requests
- Create Service Request
- After you finished adding all the application permissions, click Next to go to restrictions.
- On the Restrictions tab, you can add restrictions to restrict access to
objects, attributes, and collections.
For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.
- On the Users tab, you can add users to the group and click
Next.
For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.
- On the Operational dashboard tab, add a dashboard for the group.
- Click Done to save your changes. A success message confirms your group changes.
Reviewing and verifying your security groups
- From the side navigation menu, select .
- Search for your security groups. If you used the sample security groups, search for them by
using the search term sample and press Enter.Your sample security groups are shown.

- Click each security group name and verify whether the permissions meet your business needs.
- If necessary, update permissions to more closely match what your business users do in their roles.