Managing authorizations

In the Authorization tab, you can grant or revoke permission to a subject, which can be a user or a group of users. You can assign a pre-configured resource type to a subject that enables the subject to access resources (or features) in IBM Process Mining. If you assign a resource type, such as Multi Tenant Administration in User administration, to a user, the user gets access to the multi-tenant resources in IBM Process Mining. However, the authorized permissions determine the activities that a subject can perform in an assigned resource.

In the Dashboard page of the Authorizations tab, you can see the Authorization table which gives details of all the assigned permissions (see Figure 1. Authorization Dashboard).

Authorizations

Table 1 Authorizations fields explanation

Field Description
Subject Type Can be User or Group
Subject Name of User or Group
Resource Type Resources in IBM Process Mining that a subject can access.
Resource Name of resources in IBM Process Mining
Type Status of permission, can be Granted or Revoked
Permissions Permissions that are granted or revoked

See the following topics to learn more about Permissions and the tasks you can perform in the Authorization tab:

Permissions in Authorization

See the following table to learn more about the different types of permissions in the Authorization tab.

User administration

Table 2. User administration permissions

Resource type Permission Action permissions
Multi Tenant administration write Edit permission
Tenant administration write Edit permission
Administration write Edit permission

Analytics

Table 3. Analytics permissions

Resource type Permission Action permissions
Dashboard read Open dashboard, Apply filters
  write Add or remove widgets, Edit widget configuration
  create Create new dashboards
  share Share analytics with people outside the organization

Business repository

Table 4. Business repository permissions

Resource type Permission Action permissions
Application landscape read List and open application landscapes
  write Edit application landscapes
  create Create new application landscapes
  share Share application landscapes with people outside the organization
Attachments read List and open attachments
  write Edit documents that are attached to Business repository models
  create Add or remove documents
BPMN model read List and open BPMN models
  write Edit BPMN models
  create Create BPMN models
  share Share BPMN models with people outside the organization
DMN read List and open DMN models
  write Edit DMN models
  create Create DMN models
Derived BPMN model read List and open derived BPMN model
  write Modify derived BPMN models
  create Create derived BPMN models
Organization landscape read List and open organization landscapes
  write Edit organization landscapes
  create Create organization landscapes
  share Share organization landscapes with people outside the organization
Process landscape read List and open process landscapes
  write Edit process landscapes
  create Create process landscapes
  share Share process landscapes with people outside the organization
Settings read List and open Settings
  write Edit Settings
  create Create Settings
Simulations read List and open Simulations
  write Edit Simulations
  create Create Simulations

Core

Table 5. Core permissions

Module Permission Description
Monitor read Access to projects that belong to the organization or tenant
  write Edit projects in organization or tenant, append data to a project
Organization read Access to projects that belong to the organization or tenant
  write Edit projects in organization or tenant, append data to a project
  create Create or remove projects in organization or tenant
  share Invite new members to the organization or tenant (not available for single projects)
  filter Apply filters to an IBM Process Mining project
  configure Change project settings
  datasource Change project mapping
  refmodel Upload a reference model
  create package Create a deployment package
  deploy package Apply or publish the deployment package
  dashboard Enable access to IBM Process Mining dashboard
  Social net Enable access to Social net
  Activity map Enable access to Activity map
  Conformance check Enable Conformance check
  Export BPMN Enable export BPMN
  Diff Analysis Enable access to Diff analysis
  Simulation Enable access to Simulation
  Business Rule Mining Enable access to Business rule mining
  View Organization members Enable view of the organization members
Prescriptive Process Mining PPM Report Config Enable the creation and configuration of Prescriptive Process Mining reports
  PPM Report Delete Enable the deletion of Prescriptive Process Mining reports
Project read Access to projects that belong to the organization or tenant
  write Edit projects in organization or tenant, append data to a project
  create Create or remove projects in organization or tenant
  filter Apply filters to an IBM Process Mining project
  configure Change project settings
  Data source Change project mapping
  refmodel Upload a reference model
  create package Create a deployment package
  deploy package Apply or publish the deployment package
  dashboard Enable access to IBM Process Mining dashboard
  Social net Enable access to Social net
  Activity map Enable access to Activity map
  Conformance check Enable Conformance check
  Export BPMN Enable export BPMN
  Diff Analysis Enable access to Diff analysis
  Simulation Enable access to Simulation
  Business Rule Mining Enable access to Business rule mining
Tenant read Access to projects that belong to the organization or tenant
  write Edit projects in organization or tenant, append data to a project
  create Create or remove projects in organization or tenant
  share Invite new members to the organization or tenant (not available for single projects)
  filter Apply filters to an IBM Process Mining project
  configure Change project settings
  datasource Change project mapping
  refmodel Upload a reference model
  create package Create a deployment package
  deploy package Apply or publish the deployment package
  dashboard Enable access to IBM Process Mining dashboard
  Social net Enable access to Social net
  Activity map Enable access to Activity map
  Conformance check Enable Conformance check
  Export BPMN Enable export BPMN
  Diff Analysis Enable access to Diff analysis
  Simulation Enable access to Simulation
  Business Rule Mining Enable access to Business rule mining
  View Organization members Enable view of the organization members
  Process Apps Enable access to Process App
  Custom Process Apps Enable access to Custom Process App
  Monitor Enable access to Monitor

Suite access

Table 6. Suite access permissions

Module Permission Description
Analytics read View Analytics tabs
Business repository read View Business repository tabs
IBM Process Mining read View IBM Process Mining tabs
Monitor and Action read View Monitor tabs

Taskminer

Table 7. Taskminer permissions

Module Permission Description
Classification read View the task classification performed for a Task Mining project
  write Create or change the task classification for a Task Mining project
Decrypt read Download chunks from the audit logs and decrypt them for identifying errors by using the Decryptor tool
Monitoring list read Download and read the monitoring list from the server
  write Edit a new monitoring list and update it to the server for all users
Obfuscation read View the obfuscation and anonymization settings performed for a Task Mining project
  write Edit the obfuscation and anonymization configurations for a Task Mining project
Project read View the project configuration performed for a Task Mining project
  write Edit or change the project settings for a Task Mining project
  create Create or remove projects in organization or tenant
  create package Create a deployment package
  deploy package Apply or publish the deployment package
RPA Script read View the RPA Script settings for automating IBM Task Mining and IBM Process Mining integration
  write Edit or change the RPA Script settings

Adding an Authorization

To add an authorization, perform the following steps:

  1. Click Add button to access the Edit authorization dialog. Edit authorization

Figure 2. Edit Authorization dialog

  1. In the Edit authorization dialog, enter the required information. See Table 1. and Table 2. for more information.

  2. In the Target resources field select one of the following options:

    All tenant resources
    Select this option if you want to apply the permission to all resources in IBM Process Mining.
    Resources descendants of
    Select this option if you want to apply the permission to the descendants of any existing Parent organization. You can select the parent organization from the list of organizations in the Parent organization field.
    Specific resource
    Select Specific resource if you want to apply the permission to any specific resource in IBM Process Mining. You can select the specific resource from the list in the Resource field.

Editing Authorizations

To edit the permission of a group or user, click the Edit icon Edit authorization in the selected row of the Authorization table. You can then add or remove the permissions in the Permissions field in the Edit Authorization dialog.

Deleting Authorizations

To delete an authorization, click the Delete icon Delete authorization in the selected row of the Authorization table.