5 Replies Latest reply on Sep 15, 2017 8:10 PM by 70Charger

    Privileges for Self-Service Role on SS Dashboard

    Apprentice

      Is there a document that explains what permissions to set to prevent self-service users from being able to modify the SS dashboard?

       

      My test accounts are not able to move gadgets around on my TEST instance (good), but in LIVE they are able to (not good). I've compared the privilege differences the best I can, but apparently I'm missing something.

       

      I would like to give them the ability to modify the default color scheme if they wish, but I don't see a privilege for that. Please let me know if you have ideas or experience with this.

        • 1. Re: Privileges for Self-Service Role on SS Dashboard
          LegoGuy SupportEmployee

          I don't know what permissions those would be. But I use the following script to search for permissions.

           

          select i2.md_title as 'Parent', i.md_name as 'permission FQDN name/area', i.md_title as 'permission name' from md_privileged_item i

          inner join md_privileged_item i2 on i.md_parent_guid = i2.md_guid

          where i.md_title like '%permissionYourLookingFor%'

           

           

          Then I would try searching for dashboard, personalize, customize, color. One of those might show you a privilege that you missed.

          • 2. Re: Privileges for Self-Service Role on SS Dashboard
            Apprentice

            Thanks, but unfortunately we're using SDaaS and don't have access to the database to run scripts.

            • 3. Re: Privileges for Self-Service Role on SS Dashboard
              LegoGuy SupportEmployee

              It's not the prettiest thing to look at, but here is what I got when I ran it against my database. Take a look at these places and see if you notice a mismatch between test and live.

               

               

              Parent Level item  Permission section or Child Level Object or FQDN                                            Permission to look for

              --------------          ---------------------------------------------------------------                                   -----------------------

              User Interface      UserInterface.PersonalisedDashboard                                                             Personalised Dashboard

              Designers             SystemPrivilege.Root.Configuration.Designers.MaintainPersonalDashboard Maintain Personal Dashboard

              Designers             SystemPrivilege.Root.Configuration.Designers.PersonaliseDashboard           Personalise Dashboard

              User Interface      UserInterface.DashboardGroup                                                                       Dashboard Group

              User Interface      UserInterface.PersonalisedDashboard                                                             Personalised Dashboard

              User Interface      UserInterface.DashboardUser                                                                            Dashboard User

              Designers            SystemPrivilege.Root.Configuration.Designers.MaintainPersonalDashboard    Maintain Personal Dashboard

              User Interface      UserInterface.Dashboard                                                                                 Dashboard

              Designers            SystemPrivilege.Root.Configuration.Designers.MaintainSystemDashboard      Maintain System Dashboard

              User Interface      UserInterface.DashboardRole                                                                           Dashboard Role

              Designers            SystemPrivilege.Root.Configuration.Designrs.PublishSystemDashboard           Publish System Dashboard

              Designers            SystemPrivilege.Root.Configuration.Designers.PersonaliseDashboard           Personalise Dashboard

              Workspaces        SystemPrivilege.Root.Configuration.Workspaces.DashboardDesigner           Dashboard Designer

              User Interface      UserInterface.DashboardContent                                                                       Dashboard Content

              • 4. Re: Privileges for Self-Service Role on SS Dashboard
                Apprentice

                Thanks very much for these! I'll go through them later today/tomorrow and if I still can't lock it down I'll open a ticket. Thanks, again.

                • 5. Re: Privileges for Self-Service Role on SS Dashboard
                  Apprentice

                  UPDATE: I found the issue was that I was not looking at the privileges for the groups the user belonged to as well. I was only looking at the self-service role. Once I modified the group privileges to match the role, the dashboard gadgets are now locked in place.