Default task profiles
A System Administrator, by default, has the following task rights:
•
Appset•
DefineSecurity•
DefineDrillThroughA Primary Administrator, by default, has the following task rights:
•
AdminDataLock•
Application•
BusinessRules•
DefineSecurity•
DefineSecurity•
Dimensions•
InsightAdmin•
Lockings•
ManageAudit•
ManageBook•
ManageBPF•
ManageComments•
ManageTemplates•
UpdateToCompanyFolderA Secondary Administrator, by default, has the following task rights:
•
Dimensions•
eAnalyze•
ManageBPFTask profile descriptions
The following table describes the available tasks. (The shading is for visual purposes only.)
Interface Task Can be assigned to Description
Application Only the primary
administrator (default) Can create, modify, and delete applications in this application set, make changes to dimensions and add dimensions, and optimize applications.
Appset System administrator,
by default, but can be assigned to primary administrator
Can enable and disable Insight, create new application sets, modify application sets, and set application set parameters (in Web Admin Tasks). Business Rules Primary administrator,
by default, but can be assigned to secondary administrator
Can define business rules.
Dimension Only primary and
secondary administrators (default)
Create, modify, process, and delete dimensions and members.
Lockings Primary administrator, by default, but can be assigned to secondary administrator
Set up and edit concurrent locks, and define and edit work status codes. Administration
Misc Primary administrator,
by default, but can also be assigned to system and secondary administrators.
Can manage and validate custom menus and view application set status.
eAnalyze Anyone Can access, manage and
edit ad hoc and audit reports, and access and save to the report library. AnalysisCollection
ManageTemplate Primary administrator, by default, but can be assigned to secondary administrator
Can manage the company report library, access and save templates from the library, restrict workbook
Interface Task Can be assigned to Description custom menus.
SubmitData Anyone Can access the schedule
library, build input schedules, send data. Can use spread, weight, and trend options. Can post documents with application context to the Content Library.
Audit ManageAudit Only primary
administrators (default)
Can manage activity and data auditing.
BPFExecution Anyone Can run BPFs from BPC for
Office or BPC Web. BusinessProcessFlow
ManageBPF Primary and
secondary
administrators only (default)
Can create and edit BPFs.
ManageDistributor Only primary
administrator (default) This user or team can use the Offline Distributor. Collaboration
PublishOffline Anyone This user or team collects changes to offline input schedules and sends data to a database.
AddComment Anyone This user or team can add
comments. Comments
ManageComments Primary administrator (by default), but can be assigned to system and secondary administrators.
This user or team can remove comments.
Interface Task Can be assigned to Description
Execute Anyone This user or team can
manage Data Manager packages:
•
Data upload•
Data download•
Data Preview•
Clear saved prompts•
View status based on user ID•
View schedule status based on user ID•
Run Specific package•
Run user package•
Validate & Process conversion files for company•
Validate & Process transformation files for company•
Maintain status based on user ID•
View status GeneralAdmin Primary, system andsecondary administrators. (No default assignment)
This user or team can perform tasks such as:
•
New Transformation•
Test transformation with data•
New Conversion•
New Conversion Sheet•
Save Transformation•
Save Transformation As•
Save Conversion•
Save Conversion As DMPrimaryAdmin Primary, system and secondary
administrators. (No default assignment)
Can perform default PrimaryAdmin tasks such as:
•
Manage transformation files for company and Validate & Process•
Manage conversion files for company and Validate & Process•
Packages that against the fact table directly are limited to admin•
Manage team package access•
Organize package list•
Maintain status regardless of user IDInterface Task Can be assigned to Description TeamLeadAdmin Primary, system and
secondary administrators. (No default assignment) Can:
•
Manage Transformation for non-company files and Validate & Process•
Manage Conversion for non-company files and Validate & Process•
Data Preview team folder•
Validate & Process conversion files for team•
Validate & Process transformation files for team•
Data upload team folder•
Data download team folderFileAccess UpdateToCompanyFolder Secondary administrator, by default, but can be assigned to primary administrators.
Can add files to the Company folder.
Analysis Anyone Has the following access
rights to Insight:
•
View Dashboard•
Define KPI•
View KPI Variance Analysis•
Define KPI Alerts•
Design KPI Charts•
View KPI Radar•
View KPI Predictions•
Create KPI report (flash)•
Perform KPI on- demand predictions•
Comment viewing based on variance context results•
Action Manager viewing•
Add new and update actions based on owner•
Edit actions regardless of owner•
Insert KPI intoWord/PowerPoint/Excel Insight
InsightAdmin Primary administrator (by default), but can be assigned to secondary administrators.
Interface Task Can be assigned to Description AdminJournal Primary, system and
secondary administrators. (No default assignment)
Can manage journals:
•
Create and maintain journal templates•
Clear journal tables•
Create JournalCreateJournal Anyone Can create or modify
journal entries.
PostJournals Anyone Can post journals.
ReviewJournals Anyone Can review journals
Journal
UnpostJournals Anyone Can unpost journal entries.
ManageBook Primary administrator (No default
assignment)
This user or team can delete books in BPC Administration.
PublishBook Primary administrator (No default
assignment)
This user or team can publish a book of reports. Publish
PublishFile Primary administrator (No default
assignment)
Can post files to the Content Library or in BPC Web.
Security DefineSecurity Only system and
primary
administrators (by default).
Can manage users, task and member access profiles.
AuditReport Anyone This user or team can
create audit reports.
BPFReport Anyone This user or team can
define Business Process Flow reports.
CommentReport Anyone This user or team can run a
comment report.
JournalReport Anyone This user or team can run a
journal report. ViewSystemReport
Workstatus report Anyone This user or team can run a work status report.
Interface Task Can be assigned to Description
WorkStatus SetWorkStatus Anyone This user or team creates
work status on a data region.
AccessContentLib Anyone This user or team can access, filter, and sort, and add pages to the Content Library in BPC Web.
CreateWebPage Anyone This user or team can
create new web pages in BPC Web.
LiveReport Anyone This user or team can
access live reports in BPC Web.
ManageContentLib Primary administrator (by default), but can be assigned to system and secondary administrators.
Can manage all items in the Content Library.
ManageLiveReport Primary administrator (by default), but can be assigned to secondary administrators.
This user or team allows you to manage live reports using drag & drop in BPC Web.
ZFP
WebAdmin Primary administrator (by default), but can be assigned to secondary administrators.
Can do the following in Web Admin Tasks:
•
Edit drill through tables•
Set application parameters•
Manage dimensions (make changes to existing dimensions based on dimension)•
Publish Reports•
Manage document types and subtypes•
Use Bulk Collaboration•
Publish Non-BPC reportsAdding member access profiles
Member Access profiles determine the specific applications to which users have Read access, Write access or no access. In addition to application you can restrict access for the profile by dimension and member. After creating a Member Access profile, you assign it to multiple users, as needed.
When defining access to a secured dimension that has one or more hierarchies defined, security is applied to the member and all its children. For example, if you grant access to a member that has 10 children, users with access to the parent member also have access to all ten children. In addition, access is applied across levels in BPC . This means if you grant access to a member that is at level two (2) in the hierarchy, that user also has access to all members at level two of the hierarchy for branches on which they are granted access at all.
To add member access profiles
1. From the Admin Console, expand Security , then select Member Access Profiles. The Member