User role requirements

Certain administrative user roles are required for the integration.

Note: For single sign-on information, see the related topic links.

DASH user roles

The following DASH roles are required for access to the Netcool Configuration Manager wizards and clients that are launched from within DASH.

Either create a DASH user with the same name as an existing Netcool Configuration Manager user who already has the IntellidenUser role, or use an appropriate Network Manager user, such as itnmadmin, who is already set up as a DASH user.

If you use the Network Manager user, create a corresponding new Netcool Configuration Manager user with the same name (password can differ), and assign the ‘IntellidenUser' role to this new user.
Important:

If a DASH user is being created on Network Manager with the same name as an existing Netcool Configuration Manager user, then they also need to be added to an appropriate Network Manager user group.

Alternatively, they must be granted any required Network Manager roles manually.

Additionally, assign the following roles to your DASH user:
  • ncp_rest_api
  • ncmConfigChange
  • ncmConfigSynch
  • ncmIDTUser
  • ncmPolicyCheck
  • ncmActivityViewing
  • ncmConfigViewing
  • ncmConfigEdit
  • ncmDashService
The following table cross-references security requirements between user interfaces, DASH roles, Netcool Configuration Manager functionality, and Netcool Configuration Manager realm content permissions. Use this information to assign DASH roles and define realm content permissions.
Table 1. UI security by DASH roles, Netcool Configuration Manager functionality, and realm content permissions
Access DASH role Functionality Realm content permissions
Apply Modelled Command Set ncmConfigChange Execute Configuration Change View, Execute
Apply Native Command Set ncmConfigChange Execute Configuration Change, Apply Native Command Sets View, Execute
Synchronize (ITNCM to Device) ncmConfigSynch Execute Configuration Synchronization View, Execute
Submit Configuration ncmConfigChange Execute Configuration Change View, Execute
Apply Policy ncmPolicyCheck Execute Compliance Policy View
View Configuration ncmConfigViewing n/a View
Edit Configuration ncmConfigEdit n/a View, Modify
Compare Configuration ncmConfigViewing n/a View
IDT Automatic ncmIDTUser IDT Access, IDT Allow Auto Login View
IDT Manual ncmIDTUser IDT Access, IDT Allow Manual Login View
Find Device n/a n/a View
View UOW Log n/a n/a n/a
View IDT Log n/a n/a View
Activity Viewer ncmActivityViewing n/a n/a
Device Synchronization ncp_rest_api n/a n/a
Access DASH services (through right-click menus) ncmDashServices n/a n/a

Tivoli Common Reporting user roles

Tivoli Common Reporting and the Netcool Configuration Manager default reports are installed together with the DASH components.

Any user who needs to access reports requires the following permissions:
  • The relevant Tivoli Common Reporting roles for accessing the Reporting node in the DASH console. Assign these roles to enable users to run reports to which they are authorized from the Tivoli Common Reporting GUI.
  • The authorization to access the report set, and the relevant Tivoli Common Reporting roles for working with the reports. Assign these permissions to enable users to run Netcool Configuration Manager reports from Network Manager topology displays, the Active Event List, and the Tivoli Common Reporting GUI.
For information about authorizing access to a report set and assigning roles by user or group, go to the IBM®Tivoli® Systems Management Information Center at http://www-01.ibm.com/support/knowledgecenter/SS3HLM/welcome, locate the Tivoli Common Reporting documentation node, and search for authorization and user roles.

Other user roles

To configure the Alerts menu in the Web GUI, the ncw_admin role is required.