FAP user groups

You can assign permission levels to a Financial Analytics Publisher (FAP) user by adding them to one or more of the following user groups: 1) IBM® Cognos® Controller User, 2) IBM TM1® User, or 3) User Group Administrator.

You specify the permissions levels in Controller using Maintain > Rights > User. The access restrictions that you define in IBM Cognos Controller also apply in TM1. The access to one or more dimensions is determined by the Security Group limitations.

If an Initial Publish was performed in a previous Cognos Controller release, all users from the previous release will still exist on the TM1 server. If it is no longer required that some of those users be active in the TM1 server, the TM1 administrator must delete them.

Note: If any unwanted users/clients were not deleted from TM1, those users' rights are removed after a publish from FAP 10.2. However, the users remain visible when you view Client Security.

The IBM Cognos Controller User group

IBM Cognos Controller User group members can use Controller and the IBM Cognos Controller Link for Microsoft Excel.

Note: If a user is assigned only to the IBM Cognos Controller User group, they cannot use IBM Cognos TM1.

The IBM TM1 User group

IBM Cognos TM1 User group members can use TM1.

Note: If a user is assigned only to the IBM TM1 User group, they cannot use IBM Cognos Controller or the IBM Cognos Controller Link for Microsoft Excel.

User names assigned to the IBM Cognos TM1 User group are copied over when you publish to the IBM Cognos Controller Financial Analytics Publisher.

IBM Cognos TM1 User group members can access Controller data in a published FAP cube in TM1 if they were granted access to the cube. An Initial Publish transfers all active TM1 users to the TM1 server. Inactive TM1 Users and inactive IBM Cognos Controller Users are not transferred to the TM1 Server.

The User Group Administrator group

User Group Administrator group members can use both Controller and TM1.

A member of the User Group Administrator group can change permissions for other users in his group, but not for the group itself. This type of user cannot change permissions for users on a higher level in the hierarchy than his own group. This option is not available for users who are assigned only to the IBM Cognos TM1 User group.

Note: After you upgrade a Controller database from an earlier version of IBM Cognos Controller, all users are members of the User Group Administrator group by default. Therefore, if you do not want certain users to access FAP cubes, you must move them to the IBM Cognos Controller User group before you run an Initial Publish.