Creating and managing security groups

You can either create security groups or manage users first. But by creating security groups before you manage users, you ensure that you can immediately assign user permissions based on their specific business role. Create your security groups either from scratch, or by using samples based on roles that best describe your business users.

Tip: This topic provides step-by-step tasks for creating and managing sample security groups. You can complete this task at your own pace. Cheat sheets and logical stopping points are included so that you can pause and resume later, depending on which sample roles you require.

Security groups

Security groups control user access to sites, applications, and data within Maximo® Application Suite as a Service. The suite comes with a few predefined security groups, such as MAXADMIN and USERMANAGEMENT. You can log in with a user that belongs to these security groups to get started with your initial administration and user management tasks, or you can create users and security groups that work for you.

To review the predefined security groups, expand the side navigation menu and go to Suite > Security > Security Groups.
Security > Security Groups

Navigating the user interface

Be aware of the following common entry points and navigation behaviors as you work through creating your own security groups, or creating security groups by using the sample security groups.

The Applications tab opens automatically after you create each security group:
Security groups landing
Where you will be working with the following three columns to manage your security group permissions:
Applications
The first column contains the applications that you want to authorize and grant the appropriate types of access to each.
Permissions
The second column is updated to reflect the permissions that are available to grant after you select an application.
Permissions selected
The third column is updated to reflect the total number of permissions granted in the applications. This value is continuously updated for you to review as you enter each application's permissions. This number also reflects permissions that are selected by default before you select your own.
If you mistakenly click Next into the restrictions before adding each application's permissions, click the Applications tab to return to applications:
Applications tab
If you mistakenly click Save & exit, click the Edit icon to return to the editor:
Edit icon

When you have finished creating a security group, the final Next button switches to a Done button to complete the wizard steps.

Click Done to save your changes. A success message confirms your group changes. For example:
Done

Creating your own security groups

As a best practice, implement a layered security approach that uses three types of security groups. Site access, application access, and data access. This layered model provides granular control while remaining manageable. Security groups can be inherited from parent groups or defined independently. Design security groups with narrow, role-specific scopes, then assign users to multiple groups as needed to build complete permission sets. This approach is more maintainable than creating broad security groups that attempt to cover multiple roles.

After you have decided on your user roles and how they map to security groups, create them in Maximo Application Suite as a Service:

  1. Log in to Maximo Application Suite as a Service with the maxadmin user.

    The maxadmin user contains the correct permissions to create users and security groups because it is a member of the Users and Security Groups security groups.

  2. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  3. On the Identity tab, specify a name and a default application and click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

  4. On the Applications tab, select the applications that you want to authorize and grant the appropriate types of access to each and click Next.
    Tip: Each application must be granted READ permission so that it is visible in the side navigation menu.
    If you save and exit, you can continue adding security groups information. Search for the group name that you created and then click edit.
  5. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections and click Next.
  6. On the Users tab, add users to the group and click Next.
  7. On the Operational dashboard tab, add a dashboard for the group.
  8. Save your changes.

Alternatively, to help get you up and running faster, consider creating sample security groups if they closely match your business needs.

Sample security groups

To help get you up and running faster, consider creating the following sample security groups that best describe your business users.
Administrator
A security group that represents a user role with full system access and configuration privileges in Maximo Application Suite as a Service. Admins can manage users, configure applications, set up security groups, define workflows, and control system-wide settings. This role has unrestricted access to all modules and administrative functions.
Supervisor
A security group that represents a user role with management and oversight responsibilities in Maximo Application Suite as a Service. Supervisors can assign work orders, approve requests, review technician work, manage schedules, and monitor team performance. This role has elevated permissions to coordinate work activities and make operational decisions.
Technician
A security group that represents a user role responsible for working on maintenance and repair work in Maximo Application Suite as a Service. Technicians can view assigned work orders, update work status, record labor hours, report materials used, and complete maintenance tasks. This role focuses on hands-on work execution and documentation.
Requester
A security group that represents a user role that can create and submit service requests and work orders in Maximo Application Suite as a Service. Requesters can report issues, request maintenance services, track the status of their requests, and view work order progress. This role contains limited access. It is focused on initiating and monitoring work requests.
Inventory Clerk
A security group that represents a user role responsible for managing inventory operations in Maximo Application Suite as a Service. Inventory Clerks can receive materials, issue items, perform stock counts, adjust inventory balances, and manage storeroom transactions. This role focuses on maintaining accurate inventory records and supporting material management processes.

Sample security groups cheat sheet

The following table describes how to create each sample security group in Maximo Application Suite as a Service.
Table 1. Sample security groups cheat sheet
Administrator Supervisor Technician Requester Inventory Clerk
Operational Dashboard Operational Dashboard Operational Dashboard Service Requests Operational Dashboard
Map Manager Technician Meters View Service Requests Item Master
Work Queue Manager Calendars Meter Groups Create Service Request Service Items
Scheduler Data Manager Condition Monitoring Condition Monitoring   Tools
Push Notification Administration Labor Failure Codes   Inventory
AI Configuration Failure Codes Asset Manager   Count Books
Security Groups People Reliability Strategies   Issues and Transfers
Security Groups (Manage) Asset Manager Labor Reporting   Inventory Counting
Users Crafts Quick Reporting   Service Requests
Users (Manage) Reliability Strategies Technician   View Service Requests
System Properties Crew Types Service Requests   Create Service Request
Logging Job Plans View Service Requests    
Domains Crews Create Service Request    
Database Configuration Routes Work Approvals    
Communication Templates Classifications      
Escalations Inspections      
Instant Messaging Configuration Service Address      
  Inspection Forms      
  Work Queue Manager      
  Graphical Work Week      
  Scheduler Data Manager      
  Preventative Maintenance      
  Master PM      
  KPI Viewer      
  Service Requests      
  View Service Requests      
  Create Service Request      
  Assets      
  View Assets      
  Assets & locations      
  Work Orders      
  Work Order Tracking      
  Locations      
  Labor Reporting      
  Quick Reporting      
  Meters      
  Meter Groups      
  Work Approvals      

Creating the sample security groups

Create the sample security groups by using the cheat sheet as a reference.
  1. Log in to Maximo Application Suite as a Service with the maxadmin user.

Creating the sample Administrator group

Create the sample Administrator group:
  1. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  2. On the Identity tab:
    1. Enter the group name Administrator.
    2. Enter a group description. For example, A sample security group for administrators.
    3. Click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

    The Applications tab opens automatically after you create the sample Administrator group.

  3. In the Applications column, search for and click Operational Dashboard to get started with the sample Administrator security group.
  4. In the Permissions column, select each permission that applies to your administrator. As a sample, select each permission available to you, as you can always revoke them later. At a minimum, each application must be granted READ permission so that it is visible in the side navigation menu.

    The Permissions selected column is automatically updated to reflect the application permissions that you have selected.

  5. Stay in the Applications tab.

    After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Map Manager.

  6. Continue to add all of the following applications from the cheat sheet until you have selected each application's permissions for the sample Administrator group:
    • Operational Dashboard (already completed during this sample)
    • Map Manager
    • Work Queue Manager
    • Scheduler Data Manager
    • Push Notification Administration
    • AI Configuration
    • Security Groups
    • Security Groups (Manage)
    • Users
    • Users (Manage)
    • System Properties
    • Logging
    • Domains
    • Database Configuration
    • Communication Templates
    • Escalations
    • Instant Messaging Configuration
  7. After you finished adding all the application permissions, click Next to go to restrictions.
  8. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections.

    For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.

  9. On the Users tab, you can add users to the group and click Next.

    For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.

  10. On the Operational dashboard tab, add a dashboard for the group.
  11. Click Done to save your changes. A success message confirms your group changes.

Creating the sample Supervisor group

Create the sample Supervisor group:
  1. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  2. On the Identity:
    1. Enter the group name Supervisor.
    2. Enter a group description. For example, A sample security group for supervisors.
    3. Click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

    The Applications tab opens automatically after you create the sample Supervisor group.

  3. In the Applications column, search for and click Operational Dashboard to get started with the sample Supervisor security group.
  4. In the Permissions column, select each permission that applies to your supervisor. As a sample, select each permission available to you, as you can always revoke them later. At a minimum, each application must be granted READ permission so that it is visible in the side navigation menu.

    The Permissions selected column is automatically updated to reflect the application permissions that you have selected.

  5. Stay in the Applications tab.

    After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Technician.

  6. Continue to add all of the following applications from the cheat sheet until you have selected each application's permissions for the sample Supervisor group:
    • Operational Dashboard (already completed during this sample)
    • Technician
    • Calendars
    • Condition Monitoring
    • Labor
    • Failure Codes
    • People
    • Asset Manager
    • Crafts
    • Reliability Strategies
    • Crew Types
    • Job Plans
    • Crews
    • Routes
    • Classifications
    • Inspections
    • Service Address
    • Inspection Forms
    • Work Queue Manager
    • Graphical Work Week
    • Scheduler Data Manager
    • Preventative Maintenance
    • Master PM
    • KPI Viewer
    • Service Requests
    • View Service Requests
    • Create Service Request
    • Assets
    • View Assets
    • Assets & locations
    • Work Orders
    • Work Order Tracking
    • Locations
    • Labor Reporting
    • Quick Reporting
    • Meters
    • Meter Groups
    • Work Approvals
  7. After you finished adding all the application permissions, click Next to go to restrictions.
  8. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections.

    For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.

  9. On the Users tab, you can add users to the group and click Next.

    For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.

  10. On the Operational dashboard tab, add a dashboard for the group.
  11. Click Done to save your changes. A success message confirms your group changes.

Creating the sample Technician group

Create the sample Technician group:
  1. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  2. On the Identity tab:
    1. Enter the group name Technician.
    2. Enter a group description. For example, A sample security group for technicians.
    3. Click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

    The Applications tab opens automatically after you create the sample Technician group.

  3. In the Applications column, search for and click Operational Dashboard to get started with the sample Technician security group.
  4. In the Permissions column, select each permission that applies to your technician. As a sample, select each permission available to you, as you can always revoke them later. At a minimum, each application must be granted READ permission so that it is visible in the side navigation menu.

    The Permissions selected column is automatically updated to reflect the application permissions that you have selected.

  5. Stay in the Applications tab.

    After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Meters.

  6. Continue to add all of the following applications from the cheat sheet until you have selected each application's permissions for the sample Technician group:
    • Operational Dashboard (already completed during this sample)
    • Meters
    • Meter Groups
    • Condition Monitoring
    • Failure Codes
    • Asset Manager
    • Reliability Strategies
    • Labor Reporting
    • Quick Reporting
    • Technician
    • Service Requests
    • View Service Requests
    • Create Service Request
    • Work Approvals
  7. After you finished adding all the application permissions, click Next to go to restrictions.
  8. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections.

    For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.

  9. On the Users tab, you can add users to the group and click Next.

    For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.

  10. On the Operational dashboard tab, add a dashboard for the group.
  11. Click Done to save your changes. A success message confirms your group changes.

Creating the sample Requester group

Create the sample Requester group:
  1. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  2. On the Identity tab:
    1. Enter the group name Requester.
    2. Enter a group description. For example, A sample security group for requesters.
    3. Click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

    The Applications tab opens automatically after you create the sample Requester group.

  3. In the Applications column, search for and click Service Requests to get started with the sample Technician security group.
  4. In the Permissions column, select each permission that applies to your requester. As a sample, select each permission available to you, as you can always revoke them later. At a minimum, each application must be granted READ permission so that it is visible in the side navigation menu.

    The Permissions selected column is automatically updated to reflect the application permissions that you have selected.

  5. Stay in the Applications tab.

    After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, View Service Requests.

  6. Continue to add all of the following applications from the cheat sheet until you have selected each application's permissions for the sample Requester group:
    • Service Requests (already completed during this sample)
    • View Service Requests
    • Create Service Request
  7. After you finished adding all the application permissions, click Next to go to restrictions.
  8. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections.

    For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.

  9. On the Users tab, you can add users to the group and click Next.

    For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.

  10. On the Operational dashboard tab, add a dashboard for the group.
  11. Click Done to save your changes. A success message confirms your group changes.

Creating the sample Inventory Clerk group

Create the sample Inventory Clerk group:
  1. From the side navigation menu, select Suite > Security > Security groups and then click Create group.
  2. On the Identity tab:
    1. Enter the group name Inventory Clerk.
    2. Enter a group description. For example, A sample security group for inventory clerks.
    3. Click Create group.

    After the group is created with the identity information, you specify the applications, restrictions, users, and operational dashboard to associate with the group.

    The Applications tab opens automatically after you create the sample Inventory Clerk group.

  3. In the Applications column, search for and click Operational Dashboard to get started with the sample Technician security group.
  4. In the Permissions column, select each permission that applies to your inventory clerk. As a sample, select each permission available to you, as you can always revoke them later. At a minimum, each application must be granted READ permission so that it is visible in the side navigation menu.

    The Permissions selected column is automatically updated to reflect the application permissions that you have selected.

  5. Stay in the Applications tab.

    After you select the Operational Dashboard permissions, go to the Applications column again and search for the next application to add to your sample security group. For example, Item Master.

  6. Continue to add all of the following applications from the cheat sheet until you have selected each application's permissions for the sample Technician group:
    • Operational Dashboard (already completed during this sample)
    • Item Master
    • Service Items
    • Tools
    • Inventory
    • Count Books
    • Issues and Transfers
    • Inventory Counting
    • Service Requests
    • View Service Requests
    • Create Service Request
  7. After you finished adding all the application permissions, click Next to go to restrictions.
  8. On the Restrictions tab, you can add restrictions to restrict access to objects, attributes, and collections.

    For the purposes of this sample, click Next, unless you know of specific restrictions that you want to add.

  9. On the Users tab, you can add users to the group and click Next.

    For the purposes of this sample, click Next, as users are created later. Or, add users if you have already created users that you want to add.

  10. On the Operational dashboard tab, add a dashboard for the group.
  11. Click Done to save your changes. A success message confirms your group changes.

Reviewing and verifying your security groups

After you have created your security groups, you can review them to ensure that they meet your business needs.
  1. From the side navigation menu, select Suite > Security > Security groups.
  2. Search for your security groups. If you used the sample security groups, search for them by using the search term sample and press Enter.
    Your sample security groups are shown.
    Sample security groups
  3. Click each security group name and verify whether the permissions meet your business needs.
  4. If necessary, update permissions to more closely match what your business users do in their roles.