Types of application permissions

Applies to: All deployment types

Administrators can use a set of application permissions to limit the activities of the various users and user groups that can access the IBM OpenPages® application. The application permissions reside under the SOX permissions heading and can be applied to OpenPages user groups.

Important: If the changes to application permissions result in changes to menus, the menu changes do not appear until users log out and then log back in to the application.

Users are granted applicable permissions by being assigned to role templates that include those permissions.

Administration permissions

When you create an administrative-level group, you must grant them Administration permissions.

Table 1. Administration application permissions
Permission Description
Application Text

Allows users and members of user groups to view and edit locale-specific application label values. For more information, see Localizing application text.

Ascent Feed

Allows users and members of user groups to configure the import of Ascent Reg Tech data by using the Ascent job in the Scheduler.

Bulk Update All Fields

Allows users to use the Bulk Update feature on all fields in grid views. For more information, see Designing a Grid View.

Calculation

Allows users and members of user groups to create, delete, and modify calculation definitions by usingOpen Administration menu Administration menu > Solution Configuration > Calculations. For more information, see Configuring GRC Calculations.

Currencies

Allows users and members of user groups to administer currencies.

For more information, see Modifying currency exchange rates.

Custom Machine Learning Models

Allows users and members of user groups to use the Open Administration menu Administration menu > Integrations > Custom Machine Learning Models menu item.

Dashboards

Allows administrators to create and manage dashboards by using Open Administration menu Administration menu > Solution Configuration > Dashboards.

For more information, see Dashboards

Data Export Allows administrators to configure data exports by using the Open Administration menu Administration menu > Integrations > Data Export menu item.
Encryption Keystore

Applies to: On premises

Allows administrators to configure the encryption keystore by using Open Administration menu Administration menu > Users and Security > Encryption Keystore.

For more information, see Encryption.

ExportConfiguration

Allows users to access the environment migration tool to export configuration items for import into another system. Read and write access to the Migration Documents folder is also required.

For more information, see Migrating OpenPages environments.

FastMap

Allows a user to import object data and to view imports performed by other users.

Import allows users to import object data and to see their import history using the FastMap Import menu item.

View all history allows users to view imports performed by other users. When a user has this permission, the Created By column is added to the grid on the FastMap Import tab.

For more information, see Importing object data into OpenPages with FastMap.

Field Groups

Allows users and members of user groups to view and manage the configuration of field groups through the Open Administration menu Administration menu > Solution Configuration > Object Types menu item and the Field Groups section.

ImportConfiguration

Allows users to access the environment migration tool to import configuration items that are exported from another system. Read and write access to the Migration Documents folder is also required. For more information, see Migrating OpenPages environments.

LDAP Server

Applies to: On premises

Allows Super Administrators to configure the LDAP server for user provisioning. For more information, see LDAP and user provisioning.

Locales Allows users and members of user groups to configure locales by using the Open Administration menu Administration menu > System Configuration > Locales menu item.
Logs

Allows users to view and manage the application server log files by using the Open Administration menu Administration menu > Other > Logs menu item. Read and write access to the LogCollector Documents folder is also required.

Notification Manager

Applies to: On premises

Allows Super Administrators and users to run the Notification Manager tool. For more information, see The Notification Manager.

Oauth2

Allows users and members of user groups to access the Open Administration menu Administration menu > Users and Security > OAuth 2.0 Configuration menu item.

Object Commenting

Allows users and members of user groups to configure object commenting. When a user clicks the Open Administration menu Administration menu > Solution Configuration > Object Commenting menu item, they can enable object commenting, select the types of object that they want to allow commenting on, and provide text that is displayed in the Comments panel.

For more information, see Configuring object commenting.

Object Profiles

Allows users and members of user groups to view and manage profiles, which include object types, through the Open Administration menu Administration menu > Solution Configuration > Profiles menu item.

Object Reset

Allows users and members of user groups to reset objects for a new reporting period. For information on governing reset behavior, see Reporting periods, object resets, and rulesets.

Object Text

Allows users and members of user groups to view and edit locale-specific object label values. For more information, see Localizing object text

Object Types

Allows users and members of user groups to view and manage object types through the Open Administration menu Administration menu > Solution Configuration > Object Types menu item.

Allows users and members of user groups to view and manage solution schema visualizations, through the Open Administration menu Administration menu > Solution Configuration > Solutions menu item.

Questionnaire Template Authoring

Allows users and members of user groups to create, edit, and configure questionnaire templates in the UI. Users without this permission will not see the Editor tab in Questionnaire Templates.

RapidRatings Feed

Allows users and members of user groups to configure and run the RapidRatings job in the Scheduler. The job imports data from RapidRatings.

RegTrack Feed

Allows users and members of user groups to configure the import of Reg-Track data through the Configure icon on the Compliance Assessments > Reg-Track Regulatory Events page.

Reporting Framework

Allows users and members of user groups to generate and manage the reporting framework. For more information, see Generating the reporting framework.

Reporting Framework Configuration

Allows users and members of user groups to administer and configure the reporting framework. See Configuring and generating the reporting framework.

Reporting Periods

Allows users and members of user groups to work with reporting periods through the Open Administration menu Administration menu > System Configuration > Reporting Periods menu item.

For more information, see Reporting periods, object resets, and rulesets.

Reporting Schema

Allows users and members of user groups to manage the Reporting Schema. See Managing the reporting schema.

RiskRecon Feed

Allows users and members of user groups to configure and run the RiskRecon job in the Scheduler. The job imports data from RiskRecon.

Role Templates

Allows users and members of user groups to view, add, and manage roles through the Open Administration menu Administration menu > Users and Security > Role Templates menu item. .

Rules Engine

Allows users and members of user groups to view, create, and manage rules through the Open Administration menu Administration menu > Solution Configuration > Regulatory Event Rules menu item.

If you are using the Thomson Reuters connector, users access the Rules Engine through the TRRI Rules Engine link on the Compliance Assessments > TRRI Regulatory Events page.

If you are using the Wolters Kluwer connector, users access the Rules Engine through the Wolters Kluwer Rules Engine link on the Compliance Assessments > WK Regulatory Events page.

Run Rules Engine Allows users and members of user groups to re-run rules on regulatory events by clicking Run rules engine in the regulatory events grid view.
SageMaker Allows users and members of user groups to configure and manage connections to Amazon SageMaker through the Open Administration menu Administration menu > Integrations > Amazon SageMaker menu item.
Scheduler

Allows users and members of user groups to create and manage scheduled jobs through the Open Administration menu Administration menu > Solution Configuration > Scheduler menu item.

Search

Allows users and members of user groups to manage and maintain global search operations through the Open Administration menu Administration menu > System Configuration > Global Search menu item.

For more information, see Optimizing global search.

Security Rules

Allows users and members of user groups to manage and maintain security rules.

For more information, see Security rules.

Security Scorecard Feed

Allows users and members of user groups to configure and run the SecurityScorecard job in the Scheduler. The job imports data from SecurityScorecard.

Settings

Allows users and members of user groups to view and manage settings. For more information, see Viewing the Configuration and Settings page.

Solutions

Allows users and members of user groups to use the Open Administration menu Administration menu > Solution Configuration > Solutions menu item.

Allows users and members of user groups to use the Open Administration menu Administration menu > Solution Configuration > Themes menu item.

Tagging

Allows users and members of user groups to enable and disable the Tagging feature, and create, edit, and disable tags.

This permission controls whether the Open Administration menu Administration menu > Solution Configuration > Tags menu item is displayed.

Task Focused UI

Allows users and members of user groups to create and manage views in the View Designer. For more information, see Defining and publishing views with the View Designer.

This permission also controls whether the Open Administration menu Administration menu > Other > Display Debug Info menu item is displayed.

TRRI Feed

Allows users and members of user groups to configure the import of Thomson Reuters Regulatory Intelligence (TRRI) data through the Configure icon on the Compliance Assessments > TRRI Regulatory Events page.

Note: Not applicable in IBM OpenPages as a Service.
Watson Assistant

Allows users and members of user groups to use the Open Administration menu Administration menu > Integrations > Watson Assistant menu item.

Watson Language Translator

Allows users and members of user groups to use the Open Administration menu Administration menu > Integrations > OpenPages Translation Services menu item.

Watson Mapping and Taxonomy Suggestions

Allows users and members of user groups to use the Open Administration menu Administration menu > Integrations > Mapping and Taxonomy Suggestions menu item.

watsonx.governance

Allows users and members of user groups to configure and manage connections to watsonx.governance through the Open Administration menu Administration menu > Integrations > watsonx.governance menu item.

WK Feed

Allows users and members of user groups to configure the import of Wolters Kluwer data through the Configure icon on the Compliance Assessments > WK Regulatory Events page.

Workflow

Allows users and members of user groups to create workflow definitions and terminate workflow instances through the Open Administration menu Administration menu > Solution Configuration > Workflows menu item.

For more information, see Configuring Workflows.

Audit Trail permission

The Audit Trail application permission allows users and members of user groups to view historical information about object for the selected Reporting Period.

Users can access the Activity tab in Task Views.

For more information, see Reporting period interactions and the IBM OpenPages User Guide.
Note:
  • When you copy objects, change histories are not copied with the object. The copy of the object has no change history because it is a new object.
  • When you add new fields to an object type, the OpenPages administrator might see a blank to blank change in the change history because the fields were not previously available.

CommandCenter Studios permissions

This application permission allows users and members of user groups to access IBM Cognos Analytics from IBM OpenPages.

Note: Not applicable in IBM OpenPages as a Service.
Table 2. IBM Command Center Studio permission
Permission Description
Cognos Analytics

This application permission enables access to IBM Cognos Analytics through the Analytics link in the primary menu.

Use IBM Cognos Analytics to access your Cognos software and corporate data. Depending on your access permissions, you can create, update, run, and distribute reports, dashboards, stories, and cubes, create and run agents, or schedule entries.

Issues permission

This application permission allows users and members of user groups to view the list of Issues through the Issues menu item on the Remediation menu.

Note: This application permission is in effect only for customers who upgraded or migrated and who have not yet migrated their access controls to the role-based security model. For new, first-time installations, this permission is not honored.

Object Commenting permission

If an administrator has enabled object commenting, users with the All Permissions > SOX > Object Commenting permission can comment on objects when they are on the Task or Admin tab of an object instance page.

User Interfaces - Watson permissions

  • Watson Assistant UI: Users with this permission have access to the user interface that enables them to interact with IBM watsonx Assistant in OpenPages.
  • Watson Language Translator UI: Users with this permission can use IBM Watson® Language Translator to view translated text in Task Views by clicking TranslateTranslate icon. It also allows access to the Auto Translate icon button from administrator tasks.

View Admin tab

Users with the View Admin tab permission can see Admin views on the Admin tab of an object instance page.

View Locks permission

Users with the View Locks permission can view the existing locks on objects. The View Locks permission does not grant the right to lock or unlock an object - for that you need either the Lock permission or the Unlock permission.