Permissions - CMDB

For an explanation of the symbols, please visit Permissions. In the register Schemes / Zones, permissions will be set in general and for each schema and zone separate. To alter the permissions for a new or an existing CI import you have the same-named tab available in this selection. In order to allow members of a user group to work in the CMDB, the following permissions have to be configured on the CMDB tab in the User Management.

 

Chapters:

  1. CI import

  2. Schemes/Zones

  3. Individual Schema

  4. Zone Schemas

  5. Individual Zones

  6. Distinctive Features of the Zone Authorization

  7. Life cycles

 


  1. CI import

If CI import is selected in the view, then the first row is responsible for setting the default permissions for a new CI import. Already existing imports are listed below. Their permissions can be altered for users and groups in this overview. The following rights are available:

446 settings user management permissions cmdb ci import

  1. Administrate Rights: If activated, the group members of the current group can pass on permissions to other groups via the User Management (see also User/Group).

  2. Change Settings: Defines if the user is allowed to change the settings for a CI import. Additionally, to configure the CI zones and schemas, he needs the required view permissions for those models.

  3. Execute import: Decides if the user is allowed to execute the CI import. These permissions are also depending on whether the user has the appropriate zone and schema rights. The following rule set will be applied for that:

    1. A CI schema is only visible to a user if the permissions for the individual schema contains at least one tab with the key Allowed for the value View and the schema itself does have the permission Allowed within View CI.

    2. A CI zone scheme is only visible to a user if the permissions for the individual zone schema contains at least one tab with the key Allowed for the value View.

    3. A ci zone is only visible to a user if the user has the rights to view the zone.

  4. View: Defines if the CI import is shown to the user or the group.

 

Whether CI import tasks are available to the user in the settings or not, depends on the correct assignment of permissions.

The availability of individual tasks

New import: The user is in need of the right Change Settings for the permission CMDB \ Import within General (see also Description of the individual rights).

Edit import: The user is in need of the right to change the settings of the import. Additionally, he needs view permissions for the configured CI zone and the CI scheme.

Execute import: The user is in need of the right to execute the import. Additionally, he needs view permissions for the configured CI zone and the CI scheme.

Queue: No special permissions are required but only those CI imports will be displayed where the user has the permission to execute the import.

Manage conflicts: This option is only available to those users who have the permission to execute CI import.

 

  1. Schemes/Zones

If only Schemas is selected in the tree, the following options will be available:

446 settings user management permissions cmdb schemes zones

  1. Administrate rights: If activated, the group members of the current group can pass on permissions to other groups via the User Management (see also User/Group).
  2. Create schema: Group members have the option to create schemas.
  3. Delete schema: Group members can delete existing schemas.

 

  1. Individual Schema

If an individual schema is selected, the following configuration options will appear:

  1. Administrate rights: If this permission is enabled, all members of the group can pass on permissions to other groups via the User Management (see also User/Group).
  2. Delete dynamic fields: Dynamic fields can be deleted.
  3. Create configuration item: New CIs can be created within the schema.
  4. Create dynamic fields: Dynamic fields can be created for a schema.
  5. View configuration item: CIs will be displayed within the schema.
  6. Create master fields: Master fields can be created within a schema.
  7. Delete master fields: Master fields can be deleted.
  8. Edit schema: Schemas can be edited, and their settings can be changed.
  9. Add schema: Members of the current group can add their own schemas to the CMDB.
  10. Move schema: Schemas can be moved within the hierarchy of the CMDB.
  11. Follow CI: This permission determines whether a user is allowed to follow a CI.

 

The following permissions do not refer to the entire schema, but only to individual fields and tabs:

  1. Administrate rights: Users in the current group can pass on permissions to other groups via the User Management.
  2. Edit master field: Fields created as master fields can be edited later.
  3. Edit dynamic field: Members of the current group can edit dynamic fields.
  4. Edit dynamic field value: Members of the current group can fill in dynamic fields.
  5. View: The field or tab will be displayed to the user.

 

  1. Zone Schemas

If Zones is selected in the tree view, the following permissions can be configured:

  1. Administrate rights: If this permission is enabled, members of the current group can pass on zone permissions to other groups via the User Management (see also User/Group).
  2. Create master fields: Master fields can be created within the zone schema.
  3. Create dynamic fields: Dynamic fields can be created for a zone schema. This can be executed for zone schemas in general as well as for every existing zone schema (e.g. campus, building, floor, etc.) individually.
  4. Delete dynamic fields: Dynamic fields can be deleted.
  5. Delete master fields: Master fields can be deleted within the zone schema.
  6. Create zones: Zones with this schema can be created by members of the group.

The following permissions refer to tabs and fields of individual zone schemas:

  1. Administrate rights: The following permissions can be passed on to other groups via the User Management.
  2. Edit master field: Master fields of zone schemas can be edited by group members.
  3. Edit dynamic field: Members of the current group can edit dynamic fields of zone schemas.
  4. View: Fields or tabs will be displayed to group members.

 

  1. Individual Zones

If only a single zone is selected, the following configuration options will be available:

  1. Administrate rights: With this permission, the group can pass on permissions to other groups via the User Management (see also User/Group).
  2. Delete zone: Users can delete the zone and its sub-zones.
  3. Add zone: Users of the group have the option to add new sub-zones.
  4. Edit zone: Group members can edit the existing zone as well as its sub-zones.
  5. Move zone: Users can move the zone and its sub-zones.
  6. Add configuration item: Group members gain the right to add CIs within the zone.
  7. Delete configuration item: Group members can delete existing CIs.
  8. Move CI: CIs can be moved from the zone and its sub-zones.
  9. View: If this option is not activated, the entire zone will not be displayed. Therefore, the options 2-9 cannot be used.
  10. Display Configuration Item in ticket: The configuration items can be displayed in the ticket.

Note:

If only the Zones node is selected in the tree, no options will be available. Zones can only be created, edited, and deleted by root administrators. These permissions cannot be assigned to other groups.

 

  1. Distinctive Features of the Zone Authorization

In creating permissions for zones, the inheritance leads to a distinct display within the permissions configuration. Zones, on which permissions have been set explicitly, will be displayed in boldface. This indicates that a so-called security tag has been created for this zone. It has been introduced in order to facilitate the determination of permissions in the CMDB. Moreover, one can see at first glance, on which zones permissions have been set explicitly (similar to the key icon in the User Management).

These permissions will be passed onto all hierarchically lower zones. This inheritance stops at a zone that has been assigned with rights explicitly. From this zone on, only its permissions will be passed on.

446 settings user management permissions top zones explicit

In the figure above, permissions have been explicitly assigned to the zone top. The permissions assigned to the zone top are passed on to the zone CiZone_Test. The zone Testzone has been assigned with permissions on its own (indicated by the boldface). At this point, the inheritance of permissions from the zone top stops; i.e. the zone Untertestzone 1 underneath Testzone1 inherits its permissions from Testzone1 and not from top.

Note:

If the permission Change settings or higher has not been activated under System Settings > CMDB\Schemas, the options on the CMDB tab will not have any impact.

 

  1. Life cycles

In order to edit the status permissions of configuration items you have to choose a life cycle first.

446 user management permissions cmdb life cycles

Administrative rights: If activated, the group members of the current group can pass on permissions to other groups via the User Management (see also User/Group).

View: Setting this key alters the visibility of configuration items with a specific status for members of the group.