Initial access permissions for capabilities
In IBM® Cognos® Analytics, when Content Manager initializes a content store, it creates basic structures and security information. These structures include initial access permissions for the capabilities.
The capabilities are also referred to as secured functions and secured features.
Permission levels
There are five types of access permissions that can be assigned to a group or role: Read, Write, Execute, Set policy, and Traverse. For a description of the permitted actions that are available for each permission type, see Access permissions for an entry.
In addition, combinations of access permissions are granted for each capability. These combinations are defined as permission levels, as shown in the following table:
Permission level |
Access permissions granted |
---|---|
Access |
Execute and Traverse |
Assign | Traverse and Set Policy |
Manage | Execute, Traverse, and Set Policy |
Custom | Any other combination not listed above. |
Capability names
This section lists all the Cognos Analytics capabilities. Click a capability to expand it to see which groups or roles can initially access the capability, as well as the access permissions that they were granted.
Adaptive Analytics capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level |
Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Administration capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level |
Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Manage | |||||
Library Administrators |
Access | |||||
Mobile Administrators |
Access | |||||
Modelers | Access | |||||
Portal Administrators |
Access | |||||
PowerPlay® Administrators |
Access | |||||
Report Administrators |
Access | |||||
Server Administrators |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Adaptive Analytics Administration |
Adaptive Analytics Administrators |
||||||
Directory Administrators |
Assign | ||||||
Administration tasks |
Server Administrators |
Access | |||||
Report Administrators |
Access | ||||||
Directory Administrators |
Assign | ||||||
PowerPlay Administrators |
Access | ||||||
Collaboration Administration | Directory Administrators | Manage | |||||
Configure and manage the system |
Server Administrators |
Access | |||||
Directory Administrators |
Assign | ||||||
Controller Administration |
Directory Administrators |
Assign | |||||
Data Sources Connections |
Directory Administrators |
Manage | |||||
Modelers | Access | ||||||
Distribution Lists and Contacts |
Directory Administrators |
Manage | |||||
Manage Visualizations | Directory Administrators | Assign | |||||
Library Administrators | Access | ||||||
Metric Studio Administration | Directory Administrators | Assign | |||||
Mobile Administration |
Directory Administrators |
Assign | |||||
Mobile Administrators |
Access | ||||||
Planning Administration |
Directory Administrators |
Assign | |||||
PowerPlay Servers |
Directory Administrators |
Assign | |||||
PowerPlay Administrators |
Access | ||||||
Printers |
Directory Administrators |
Manage | |||||
Query Service Administration |
Directory Administrators |
Assign | |||||
Server Administrators |
Access | ||||||
Run activities and schedules |
Report Administrators |
Access | |||||
Directory Administrators |
Assign | ||||||
PowerPlay Administrators |
Access | ||||||
Set capabilities and manage UI profiles |
Directory Administrators |
Manage | |||||
Styles and portlets |
Portal Administrators |
Access | |||||
Directory Administrators |
Manage | ||||||
Library Administrators |
Access | ||||||
Users, Groups, and Roles |
Directory Administrators |
Manage |
AI capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers |
Access | |||||
Analytics Users |
Access | |||||
Directory Administrators | Assign |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Learning |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Directory Administrators |
Assign | ||||||
Use Assistant |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Directory Administrators |
Assign |
Analysis Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Attach outputs capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Cognos Analytics for Mobile capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers |
Access | |||||
Analytics Users |
Access | |||||
Analytics Viewers | Access | |||||
Directory Administrators | Assign | |||||
Report Administrators | Access |
Cognos Insight capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Cognos Viewer capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users |
Access | |||||
Authors | Access | |||||
Consumers | Access | |||||
Directory Administrators |
Assign | |||||
Analytics Viewers |
Access | |||||
Modelers |
Access | |||||
PowerPlay Administrators |
Access | |||||
PowerPlay Users |
Access | |||||
Query Users |
Access | |||||
Readers |
Access | |||||
Report Administrators |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Context Menu Selection Toolbar |
Report Administrators |
Access | |||||
Authors |
Access | ||||||
Consumers |
Access | ||||||
Query Users |
Access | ||||||
Analysis Users |
Access | ||||||
Readers |
Access | ||||||
Directory Administrators |
Assign | ||||||
Analytics Viewers | Access | ||||||
Modelers | Access | ||||||
PowerPlay Administrators |
Access | ||||||
PowerPlay Users |
Access | ||||||
Run With Options |
Report Administrators |
Access | |||||
Authors |
Access | ||||||
Consumers |
Access | ||||||
Query Users |
Access | ||||||
Analysis Users |
Access | ||||||
Directory Administrators |
Assign | ||||||
Modelers | Access | ||||||
PowerPlay Administrators |
Access | ||||||
PowerPlay Users |
Access |
Collaborate capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users |
Access | |||||
Authors |
Access | |||||
Consumers |
Access | |||||
Directory Administrators |
Assign | |||||
Modelers | Access | |||||
PowerPlay Administrators |
Access | |||||
PowerPlay Users |
Access | |||||
Query Users |
Access | |||||
Report Administrators |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Allow collaboration features Launch collaboration tools |
Analysis Users |
Access | |||||
Authors |
Access | ||||||
Consumers |
Access | ||||||
Directory Administrators |
Assign | ||||||
Modelers | Access | ||||||
PowerPlay Administrators |
Access | ||||||
PowerPlay Users |
Access | ||||||
Query Users |
Access | ||||||
Report Administrators |
Access |
Controller Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Dashboard capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers |
Access | |||||
Analytics Users |
Access | |||||
Analytics Viewers | Access | |||||
Directory Administrators | Assign |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Data Manager capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Data sets capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Desktop Tools capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Detailed Errors capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Develop Visualizations capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Drill Through Assistant capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Email capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers |
Access | |||||
Analytics Users |
Access | |||||
Analytics Viewer | Access | |||||
Directory Administrators | Assign |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Email Delivery Option |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Directory Administrators |
Assign | ||||||
Include link in email |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Analytics Viewer | Access | ||||||
Directory Administrators |
Assign | ||||||
Share using email |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Analytics Viewer | Access | ||||||
Directory Administrators |
Assign | ||||||
Type in external email |
Analytics Explorers |
Access | |||||
Analytics Users |
Access | ||||||
Analytics Viewer | Access | ||||||
Directory Administrators |
Assign |
Event Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Execute Indexed Search capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users Authors Consumers Analytics Viewers Modelers PowerPlay Administrators PowerPlay Users Query Users Readers Report Administrators |
Access | |||||
Directory Administrators |
Assign |
Executive Dashboard capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users |
Access | |||||
Authors |
Access | |||||
Consumers | Access | |||||
Directory Administrators |
Assign | |||||
Analytics Viewers | Custom |
Permission Denied |
Permission Denied |
|||
Modelers | Access | |||||
PowerPlay Administrators |
Access | |||||
PowerPlay Users |
Access | |||||
Query Users |
Access | |||||
Readers | Access | |||||
Report Administrators |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Use Advanced Dashboard Features Use Interactive Dashboard Features |
Authors |
Access | |||||
Directory Administrators |
Assign | ||||||
Analytics Viewers | Custom | ||||||
Modelers | Access | ||||||
Query Users |
Access | ||||||
Report Administrators |
Access |
Exploration capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
External Repositories capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign | |||||
Everyone |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Manage repository connections |
Directory Administrators |
Assign | |||||
View external documents |
Directory Administrators |
Assign | |||||
Everyone |
Access |
Generate CSV Output
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Generate PDF Output capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Generate XLS Output capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Generate XML Output capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Glossary capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Hide Entries capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Import relational metadata capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Job capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Lineage capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Manage content capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Library Administrators Mobile Administrators Portal Administrators PowerPlay Administrators Report Administrators Server Administrators |
Access | |||||
Directory Administrators |
Manage |
Manage own data source signons capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Metric Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers | Access | |||||
Directory Administrators |
Assign |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Mobile capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Notebook capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Planning Contributor capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
PowerPlay Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Query Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Authors |
Access | |||||
Directory Administrators |
Assign | |||||
Modelers | Access | |||||
Query Users |
Access | |||||
Report Administrators |
Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Create Advanced |
Authors |
Access | |||||
Modelers | Access | ||||||
Query Users |
Access | ||||||
Report Administrators |
Access | ||||||
Directory Administrators |
Assign |
Report Studio capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Authors |
Access | |||||
Directory Administrators |
Assign | |||||
Library Administrators | Access | |||||
Modelers | Access | |||||
Report Administrators |
Access |
The secured features in the following table are children of the Reporting capability.
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Bursting HTML Items in Report User Defined SQL Create/Delete |
Authors |
Access | |||||
Library Administrators | Access | ||||||
Modelers | Access | ||||||
Report Administrators |
Access | ||||||
Directory Administrators |
Assign | ||||||
Allow External Data |
Directory Administrators |
Assign | |||||
Library Administrators | Access |
Save to Cloud capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analytics Explorers |
Access | |||||
Analytics Users |
Access | |||||
Directory Administrators | Assign | |||||
Report Administrators | Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Scheduling capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users | Access | |||||
Authors |
Access | |||||
Consumers | Custom | |||||
Directory Administrators |
Assign | |||||
Modelers | Access | |||||
PowerPlay Administrators |
Access | |||||
PowerPlay Users |
Access | |||||
Query Users | Access | |||||
Report Administrators | Access |
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Secured feature |
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
|||
Schedule by day Schedule by hour Schedule by minute Schedule by month Schedule by trigger Schedule by week Schedule by year |
Analysis Users |
Access | |||||
Authors |
Access | ||||||
Consumers |
Custom (Except for Schedule by day, where permission level = Access) |
||||||
Directory Administrators |
Assign | ||||||
Modelers | Access | ||||||
Query Users |
Access | ||||||
Report Administrators |
Access | ||||||
PowerPlay Administrators |
Access | ||||||
PowerPlay Users |
Access | ||||||
Scheduling Priority |
Report Administrators |
Access | |||||
Directory Administrators |
Assign | ||||||
PowerPlay Administrators |
Access |
Self Service Package Wizard capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Manage |
Set Entry-Specific Capabilities capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Share Pin Board
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Snapshots capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Specification Execution capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Directory Administrators |
Assign |
Upload files capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Visualization Alerts capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Watch Rules capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.
Group or role |
Permission level | Permission type | ||||
---|---|---|---|---|---|---|
Read
|
Write
|
Execute
|
Set policy
|
Traverse
|
||
Analysis Users |
Access | |||||
Authors |
Access | |||||
Consumers | Access | |||||
Directory Administrators |
Assign | |||||
Modelers | Access | |||||
PowerPlay Administrators |
Access | |||||
PowerPlay Users |
Access | |||||
Query Users |
Access | |||||
Report Administrators |
Access |
Web-based modeling capability
In the following table, a checkmark () indicates that a permission is granted to a group or role for an object.