User role requirements
Certain administrative user roles are required for the integration.
Note: For single sign-on information, see the related topic links.
Dashboard Application Services Hub user roles
The following Dashboard Application Services Hub roles are required for access to the Netcool® Configuration Manager components that are launched from within Dashboard Application Services Hub, such as the Netcool Configuration Manager Wizards and the Netcool Configuration Manager - Base and Netcool Configuration Manager - Compliance clients.
Either create a Dashboard Application
Services Hub user with the same name as an existing Netcool Configuration Manager user who already has
the ‘IntellidenUser' role, or use an appropriate Network Manager user, such as itnmadmin, who
is already set up as a Dashboard Application
Services Hub user. If you use the
Network Manager user, create a
corresponding new Netcool Configuration Manager user with the same
name (password can differ), and assign the ‘IntellidenUser' role to this new user.
Important: If a Dashboard Application
Services Hub user is being created on
Network Manager with the same name
as an existing Netcool Configuration Manager user. then they also need to be added to an appropriate Network Manager user group, or alternatively
be granted any required Network Manager roles manually.
Additionally, assign the following roles
to your Dashboard Application
Services Hub user:
- ncp_rest_api
- ncmConfigChange
- ncmConfigSynch
- ncmIDTUser
- ncmPolicyCheck
- ncmActivityViewing
- ncmConfigViewing
- ncmConfigEdit
- ncmDashService
The following table cross-references security requirements
between user interfaces, Dashboard Application
Services Hub roles, Netcool Configuration Manager functionality,
and Netcool Configuration Manager realm
content permissions. Use this information to assign Dashboard Application
Services Hub roles
and define realm content permissions.
Access | Dashboard Application Services Hub role | Functionality | Realm content permissions |
---|---|---|---|
Apply Modelled Command Set | ncmConfigChange | Execute Configuration Change | View, Execute |
Apply Native Command Set | ncmConfigChange | Execute Configuration Change, Apply Native Command Sets | View, Execute |
Synchronize (ITNCM to Device) | ncmConfigSynch | Execute Configuration Synchronization | View, Execute |
Submit Configuration | ncmConfigChange | Execute Configuration Change | View, Execute |
Apply Policy | ncmPolicyCheck | Execute Compliance Policy | View |
View Configuration | ncmConfigViewing | n/a | View |
Edit Configuration | ncmConfigEdit | n/a | View, Modify |
Compare Configuration | ncmConfigViewing | n/a | View |
IDT Automatic | ncmIDTUser | IDT Access, IDT Allow Auto Login | View |
IDT Manual | ncmIDTUser | IDT Access, IDT Allow Manual Login | View |
Find Device | n/a | n/a | View |
View UOW Log | n/a | n/a | n/a |
View IDT Log | n/a | n/a | View |
Activity Viewer | ncmActivityViewing | n/a | n/a |
Device Synchronization | ncp_rest_api | n/a | n/a |
Access Dashboard Application Services Hub services (through right-click menus) | ncmDashServices | n/a | n/a |
Tivoli Common Reporting user roles
Tivoli® Common Reporting and the Netcool Configuration Manager default reports are installed together with the Dashboard Application Services Hub components.
Any user who needs to access reports requires the following permissions:
- The relevant Tivoli Common Reporting roles for accessing the Reporting node in the Dashboard Application Services Hub console. Assign these roles to enable users to run reports to which they are authorized from the Tivoli Common Reporting GUI.
- The authorization to access the report set, and the relevant Tivoli Common Reporting roles for working with the reports. Assign these permissions to enable users to run Netcool Configuration Manager reports from Network Manager topology displays, the Active Event List, and the Tivoli Common Reporting GUI.
Other user roles
To configure the Alerts menu in the Web GUI, the ncw_admin role is required.