Types of application permissions
Administrators can use a set of application permissions to limit the activities of the various users and user groups that can access the IBM OpenPages® application. The application permissions reside under the SOX permissions heading and can be applied to OpenPages user groups.
Users are granted applicable permissions by being assigned to role templates that include those permissions.
Administration permissions
When you create an administrative-level group, you must grant them Administration permissions.
| Permission | Description |
|---|---|
| Application Text |
Allows users and members of user groups to view and edit locale-specific application label values. For more information, see Localizing application text. |
| Ascent Feed |
Allows users and members of user groups to configure the import of Ascent Reg Tech data by using the Ascent job in the Scheduler. |
| Bulk Update All Fields |
Allows users to use the Bulk Update feature on all fields in grid views. For more information, see Designing a Grid View. |
| Calculation |
Allows users and members of user groups to create, delete, and modify calculation definitions by using. For more information, see Configuring GRC Calculations. |
| Currencies |
Allows users and members of user groups to administer currencies. For more information, see Modifying currency exchange rates. |
| Custom Machine Learning Models |
Allows users and members of user groups to use the menu item. |
| Dashboards |
Allows administrators to create and manage dashboards by using . For more information, see Dashboards |
| Data Export | Allows administrators to configure data exports by using the menu item. |
| Encryption Keystore |
Allows administrators to configure the encryption keystore by using . For more information, see Encryption. |
| ExportConfiguration |
Allows users to access the environment migration tool to export configuration items for import into another system. Read and write access to the Migration Documents folder is also required. For more information, see Migrating OpenPages environments. |
| FastMap |
Allows a user to import object data and to view imports performed by other users. Import allows users to import object data and to see their import history using the FastMap Import menu item. View all history allows users to view imports performed by other users. When a user has this permission, the Created By column is added to the grid on the FastMap Import tab. For more information, see Importing object data into OpenPages with FastMap. |
| Field Groups |
Allows users and members of user groups to view and manage the configuration of field groups through the menu item and the Field Groups section. |
| ImportConfiguration |
Allows users to access the environment migration tool to import configuration items that are exported from another system. Read and write access to the Migration Documents folder is also required. For more information, see Migrating OpenPages environments. |
| LDAP Server |
Allows Super Administrators to configure the LDAP server for user provisioning. For more information, see LDAP and user provisioning. |
| Locales | Allows users and members of user groups to configure locales by using the menu item. |
| Logs |
Allows users to view and manage the application server log files by using the menu item. Read and write access to the LogCollector Documents folder is also required. |
| Notification Manager |
Allows Super Administrators and users to run the Notification Manager tool. For more information, see The Notification Manager. |
| Oauth2 |
Allows users and members of user groups to access the menu item. |
| Object Commenting |
Allows users and members of user groups to configure object commenting. When a user clicks the menu item, they can enable object commenting, select the types of object that they want to allow commenting on, and provide text that is displayed in the Comments panel. For more information, see Configuring object commenting. |
| Object Profiles |
Allows users and members of user groups to view and manage profiles, which include object types, through the menu item. |
| Object Reset |
Allows users and members of user groups to reset objects for a new reporting period. For information on governing reset behavior, see Reporting periods, object resets, and rulesets. |
| Object Text |
Allows users and members of user groups to view and edit locale-specific object label values. For more information, see Localizing object text |
| Object Types |
Allows users and members of user groups to view and manage object types through the menu item. Allows users and members of user groups to view and manage solution schema visualizations, through the menu item. |
| Questionnaire Template Authoring |
Allows users and members of user groups to create, edit, and configure questionnaire templates in the UI. Users without this permission will not see the Editor tab in Questionnaire Templates. |
| RapidRatings Feed |
Allows users and members of user groups to configure and run the RapidRatings job in the Scheduler. The job imports data from RapidRatings. |
| RegTrack Feed |
Allows users and members of user groups to configure the import of Reg-Track data through the |
| Reporting Framework |
Allows users and members of user groups to generate and manage the reporting framework. For more information, see Generating the reporting framework. |
| Reporting Framework Configuration |
Allows users and members of user groups to administer and configure the reporting framework. See Configuring and generating the reporting framework. |
| Reporting Periods |
Allows users and members of user groups to work with reporting periods through the menu item. For more information, see Reporting periods, object resets, and rulesets. |
| Reporting Schema |
Allows users and members of user groups to manage the Reporting Schema. See Managing the reporting schema. |
| RiskRecon Feed |
Allows users and members of user groups to configure and run the RiskRecon job in the Scheduler. The job imports data from RiskRecon. |
| Role Templates |
Allows users and members of user groups to view, add, and manage roles through the menu item. . |
| Rules Engine |
Allows users and members of user groups to view, create, and manage rules through the menu item. If you are using the Thomson Reuters connector, users access the Rules Engine through the TRRI Rules Engine link on the page. If you are using the Wolters Kluwer connector, users access the Rules Engine through the Wolters Kluwer Rules Engine link on the page. |
| Run Rules Engine | Allows users and members of user groups to re-run rules on regulatory events by clicking Run rules engine in the regulatory events grid view. |
| SageMaker | Allows users and members of user groups to configure and manage connections to Amazon SageMaker through the menu item. |
| Scheduler |
Allows users and members of user groups to create and manage scheduled jobs through the menu item. |
| Search |
Allows users and members of user groups to manage and maintain global search operations through the menu item. For more information, see Optimizing global search. |
| Security Rules |
Allows users and members of user groups to manage and maintain security rules. For more information, see Security rules. |
| Security Scorecard Feed |
Allows users and members of user groups to configure and run the SecurityScorecard job in the Scheduler. The job imports data from SecurityScorecard. |
| Settings |
Allows users and members of user groups to view and manage settings. For more information, see Viewing the Configuration and Settings page. |
| Solutions |
Allows users and members of user groups to use the menu item. Allows users and members of user groups to use the menu item. |
| Tagging |
Allows users and members of user groups to enable and disable the Tagging feature, and create, edit, and disable tags. This permission controls whether the menu item is displayed. |
| Task Focused UI |
Allows users and members of user groups to create and manage views in the View Designer. For more information, see Defining and publishing views with the View Designer. This permission also controls whether the menu item is displayed. |
| TRRI Feed |
Allows users and members of user groups to configure the import of Thomson Reuters Regulatory
Intelligence (TRRI) data through the Note: Not applicable in IBM
OpenPages as a Service.
|
| Watson Assistant |
Allows users and members of user groups to use the menu item. |
| Watson Language Translator |
Allows users and members of user groups to use the menu item. |
| Watson Mapping and Taxonomy Suggestions |
Allows users and members of user groups to use the menu item. |
| watsonx.governance |
Allows users and members of user groups to configure and manage connections to watsonx.governance through the menu item. |
| WK Feed |
Allows users and members of user groups to configure the import of Wolters Kluwer data through the |
| Workflow |
Allows users and members of user groups to create workflow definitions and terminate workflow instances through the menu item. For more information, see Configuring Workflows. |
Audit Trail permission
The Audit Trail application permission allows users and members of user groups to view historical information about object for the selected Reporting Period.
Users can access the Activity tab in Task Views.
- When you copy objects, change histories are not copied with the object. The copy of the object has no change history because it is a new object.
- When you add new fields to an object type, the OpenPages administrator might see a blank to blank change in the change history because the fields were not previously available.
CommandCenter Studios permissions
This application permission allows users and members of user groups to access IBM Cognos Analytics from IBM OpenPages.
| Permission | Description |
|---|---|
| Cognos Analytics |
This application permission enables access to IBM Cognos Analytics through the Analytics link in the primary menu. Use IBM Cognos Analytics to access your Cognos software and corporate data. Depending on your access permissions, you can create, update, run, and distribute reports, dashboards, stories, and cubes, create and run agents, or schedule entries. |
Issues permission
This application permission allows users and members of user groups to view the list of Issues through the Issues menu item on the Remediation menu.
Object Commenting permission
If an administrator has enabled object commenting, users with the permission can comment on objects when they are on the Task or Admin tab of an object instance page.
User Interfaces - Watson permissions
- Watson Assistant UI: Users with this permission have access to the user interface that enables them to interact with IBM watsonx Assistant in OpenPages.
- Watson Language Translator UI: Users with this permission
can use IBM Watson® Language
Translator to view translated text in Task Views by
clicking Translate
. It also
allows access to the
button from
administrator tasks.
View Admin tab
Users with the View Admin tab permission can see Admin views on the Admin tab of an object instance page.
View Locks permission
Users with the View Locks permission can view the existing locks on objects. The View Locks permission does not grant the right to lock or unlock an object - for that you need either the Lock permission or the Unlock permission.