System Roles and Privileges

Special system privilege

Viewer Analyst Creator Administrator

Manage all (Super Administrator)

Manage all (Super Administrator)

This system privilege includes all other system privileges and also the highest authorization level for all repositories and all their items, with the exception of the "write data" authorization level for objecttypes. The user is a super administrator.

Please note: This system privilege can only be assigned by a super administrator. The first super administrator of the installation must be defined via configuration.

Contained in no system role.

Administration

Viewer Analyst Creator Administrator

Manage interim status of workbooks in the Management Center

Manage all subscriptions (Requirement: "Use subscription function")

Access Management Center

Use Query Logger for workbooks

Export repositories

Import repositories

Create new repositories

Create new workbooks

Export and import workbooks

Manage user roles

Manage user groups

Import identity provider groups

View and select existing users

View and select existing user groups

Create and edit views with JasperReports report

Create new projects

Create new collective projects

Manage analytics extensions

Manage repository data sources

Manage cross-repository data sources

Manage links/drill-throughs to external content

Manage report layouts

Reactivate data protection contexts

Manage data protection contexts

Manage Location Finder

Manage map views

Define default map view

Manage system settings

~Use Management API

Manage interim status of workbooks in the Management Center

The user can manage interim statuses for all workbooks in the Management Center (access to the "Interim statuses" tab in the "Workbooks" section).

Contained in system role Administrator.

Used by Cadenza Feature: ~Interim States.

Manage all subscriptions (Requirement: "Use subscription function")

The user can monitor, edit, disable, and delete all subscriptions. The system privilege "Use subscription function" is also required. Only users with authorization for the corresponding workbook (authorization level "Edit and manage") and repository (authorization level "Edit content") can edit filters and the condition.

Contained in system role Administrator.

Used by Cadenza Feature: Subscriptions.

Access Management Center

The user can use the Management Center in principle. A requirement is that a repository database is connected.

Additional system privileges may be required for individual tasks within the Management Center.

Contained in system roles Analyst, Creator, Administrator.

Use Query Logger for workbooks

The user can analyze the database queries of views with the Query Logger.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: Query Logger.

Export repositories

The user can export a repository in the Management Center. Authorization for the repository is required.

Contained in system role Administrator.

Used by Cadenza Feature: ~Interactive Lifecycle Management.

Import repositories

The user can import a repository in the Management Center.

Contained in system role Administrator.

Used by Cadenza Feature: ~Interactive Lifecycle Management.

Create new repositories

The user can create a new repository in the Management Center.

Contained in system roles Creator, Administrator.

Create new workbooks

The user can create a new workbook. Authorization for a repository is required.

Contained in system roles Analyst, Creator, Administrator.

Export and import workbooks

The user can export and import workbooks. Additionally, the user can import new versions of existing workbooks. Authorization for the workbook is required.

These functions are also available in the Management Center.

Contained in system role Administrator.

Used by Cadenza Feature: ~Interactive Lifecycle Management.

Manage user roles

The user can manage user roles in the Management Center.

Contained in system role Administrator.

Manage user groups

The user can manage user groups in the Management Center.

Contained in system role Administrator.

Import identity provider groups

The user can import user groups from an identity provider.

Contained in system role Administrator.

View and select existing users

The user can view and select all users in user selection lists. Without this privilege, usernames can only be entered as text, and for security reasons there is no feedback on whether the users exist.

Contained in system roles Analyst, Creator, Administrator.

View and select existing user groups

The user can view and select all user groups in user group selection lists. Without this privilege, the names of user groups can only be entered as text, and for security reasons there is no feedback on whether a user or user group with the specified name exists.

Contained in system roles Analyst, Creator, Administrator.

Create and edit views with JasperReports report

The user can create and edit views in workbooks that include a report (JasperReports). Authorization for the workbook is required.

Contained in system role Administrator.

Used by Cadenza Feature: ~Jasper Reports.

Create new projects

The user can create a new project. Authorization for the repository is required. The project feature must be enabled in the repository.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: Cadenza Projects.

Create new collective projects

The user can create a new collective project in the Management Center. The repository must have authorization, and the project function must be enabled.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: Cadenza Projects.

Manage analytics extensions

The uer can register and manage analytics extensions in the Management Center.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: Analytics Extensions.

Manage repository data sources

The user can manage repository data sources in the Management Center. Authorization for a repository is required.

Contained in system roles Creator, Administrator.

Manage cross-repository data sources

The user can manage cross-repository data sources in the Management Center.

Contained in system role Administrator.

The user can manage base links and their link extensions in the Management Center. Authorization for a repository is required.

Contained in system roles Creator, Administrator.

Manage report layouts

The user can create and manage report layouts in the Management Center. For creation, authorization for a repository is required. For management, authorization for the report layout is required.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: ~Reports.

Reactivate data protection contexts

The user can view the section containing inactive data protection contexts in the data protection context overview.

This section includes data protection contexts whose deletion date has been reached or that were manually deleted before the date was reached, but which are still within the configured grace period (data protection contexts with the status “deleted”).

They can also reactivate inactive data protection contexts. Authorization for the data protection context is required.

In the repository, the “Extended data security” function must be enabled with the “Data protection contexts” security mode.

Contained in system role Administrator.

Used by Cadenza Feature: Data Protection.

Manage data protection contexts

The user can view the “Data protection contexts” section in the Management Center and create, edit, share, and delete data protection contexts there. Authorizations are required for data protection contexts. (The system privilege is not required to create a data protection context while creating an objecttype, a workbook, or a project.) In the repository, the “Extended data security” function must be enabled with the “Data protection contexts” security mode.

Contained in system roles Creator, Administrator.

Used by Cadenza Feature: Data Protection.

Manage Location Finder

The user can manage search sources and other settings for the Location Finder in the section "System settings" of the Management Center. As an alternative, the system privilege “Manage system settings” is required.

Contained in system role Administrator.

Manage map views

The user can manage the map views of repositories in the Management Center. Authorization for the map view and its repository is required.

Contained in system roles Creator, Administrator.

Define default map view

The user can define one of the map views from the repositories as default in the Management Center. This setting applies Cadenza-wide. Authorization for the map view and its repository is required. Additionally, the system privilege "Manage map views" is required.

Contained in system role Administrator.

Manage system settings

The user can manage system settings in the Management Center. To manage the Location Finder, the system privilege "Manage Location Finder" is additionally required.

Contained in system role Administrator.

~Use Management API

The user can use the Management API.

Contained in system role Administrator.

Used by Cadenza Feature: ~Management Api.

Data import/export

Viewer Analyst Creator Administrator

Import archive files

Import GeoJSON data as a layer (via Cadenza API only)

Import Excel, ODS and CSV files

Export data as Excel, ODS and CSV file

Import GeoPackage files

Export data as GeoPackage file

Import KML files

Export data as KML file

Import shapefiles

Export data as shapefile

Import GPX files

Export data as GPX file

Import archive files

The user can import archive files (ZIP, KMZ).

Contained in system roles Analyst, Creator, Administrator.

Import GeoJSON data as a layer (via Cadenza API only)

Contained in system role Administrator.

Used by Cadenza Feature: GeoJSON Import.

Import Excel, ODS and CSV files

Der Benutzer kann Excel-, ODS- und CSV-Dateien importieren.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Features: CSV Import, Excel Import, ODS Import.

Export data as Excel, ODS and CSV file

The user can export tables to Excel, ODS and CSV files.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Features: CSV Export, Excel Export, ODS Export.

Import GeoPackage files

The user can add GeoPackage layers to a map view.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: GeoPackage Import.

Export data as GeoPackage file

The user can export tables and map layers to GeoPackage files.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Feature: GeoPackage Export.

Import KML files

The user can add KML layers to a map view.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: KML Import.

Export data as KML file

The user can export map layers as a KML file.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Feature: KML Export.

Import shapefiles

The user can import shapefiles.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Shapefile Import.

Export data as shapefile

The user can export map layers as a shapefile.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Shapefile Export.

Import GPX files

The user can import GPS Exchange Format (GPX) files.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: GPX Import.

Export data as GPX file

The user can export GPS Exchange Format (GPX) files.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Feature: GPX Export.

Features

Viewer Analyst Creator Administrator

Manage personal interim status in the workbook

Add layer from geodata services to the map

Use geocoding services for IP addresses

Provide objecttypes as a template for data acquisition in the map

Visualize and analyze movement data in an interactive 3D view

Configure map animations and allow playback

Create and edit spatial filters

Create new objecttypes from templates for data acquisition in the map

Create, update and delete data

Play map animations

Create and edit signature libraries

Create sketch layers (Requirement: "Edit sketch layers")

Edit sketch layers

Use subscription function

Create and edit function attributes

Enrich objecttypes with data

Copy data from a data source to the workbook (workbook-internal copy)

Edit advanced layer settings

Move workbook-internal data to the data catalog

Add empty map views

Couple map views

Share anonymous workbook interim status

Create empty objecttypes

Manage personal interim status in the workbook

The user can save the current status of the open workbook and thus retain an overall picture of their work by saving the current snapshot.

Note: This system privilege particularly enables users without authorization to save or copy the workbook to retain their settings.

Contained in system role Viewer.

Used by Cadenza Feature: ~Interim States.

Add layer from geodata services to the map

The user can add layers from geodata services such as WMS and WMTS to map views.

Contained in system roles Analyst, Creator, Administrator.

Use geocoding services for IP addresses

The user can geocode IP addresses in their own data or in data of objecttypes for which they have the "write data" authorization. The function is available in workbooks in the Location Finder of the map view and via data import.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: IP Geocoding.

Provide objecttypes as a template for data acquisition in the map

The user can make objecttypes available as templates for data acquisition in the map in the Management Center ("Data acquisition" tab of the objecttype). Authorization for the objecttypes is required. The objecttype must meet certain requirements as a template for data acquisition for this function to be available.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: ~Data Acquisition in Maps.

Visualize and analyze movement data in an interactive 3D view

The user can display and analyze movement profiles in an interactive 3D view.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Movement Data Analysis.

Configure map animations and allow playback

The user can set up the animation of filter results on the map for individual workbook filters and enable playback of the animation.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Map Animation.

Create and edit spatial filters

The user can create spatial filters and edit existing spatial filters in workbooks.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Spatial Filtering.

Create new objecttypes from templates for data acquisition in the map

The user can create acquisition layers in workbooks. requirement: The user has at least the "Use (restricted)" authorization for at least one objecttype that has been made available as a template for data acquisition in the map.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: ~Data Acquisition in Maps.

Create, update and delete data

The user can acquire data for an objecttype in workbooks. requirement: The user has the "write data" authorization for at least one objecttype that has been made available as a template for data acquisition.

Contained in system roles Analyst, Creator, Administrator.

Play map animations

The user can animate the filter assignment in workbooks using the integrated player in the map.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Feature: Map Animation.

Create and edit signature libraries

The user can create and manage signature libraries while editing a sketch layer. Authorization for the repository where the signature library is to be stored is required.

Contained in system roles Creator, Administrator.

Create sketch layers (Requirement: "Edit sketch layers")

The user can add sketch layers to a map view. Additionally, the system privilege "Edit sketch layers" is required. Authorization for the workbook is required.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Sketch Layer.

Edit sketch layers

The user can edit sketch layers of a map view. Authorization for the workbook is required.

Contained in system roles Analyst, Creator, Administrator.

Used by Cadenza Feature: Sketch Layer.

Use subscription function

The user can subscribe to individual worksheets of a workbook and manage their own subscriptions.

Contained in system roles Viewer, Analyst, Creator, Administrator.

Used by Cadenza Feature: Subscriptions.

Create and edit function attributes

The user can create and edit function attributes for objecttypes.

With this privilege, the user gains the ability to generate far-reaching SQL statements. There are situations where this privilege is required, but at the same time it should be granted as rarely as possible and only in conjunction with clear instruction. If the privilege should not be available in principle, the feature must be disabled.

Contained in no system role.

Enrich objecttypes with data

The user can enrich objecttypes with data from other information sources. Authorizations for the objecttypes are required.

Contained in system roles Analyst, Creator, Administrator.

Copy data from a data source to the workbook (workbook-internal copy)

The user can copy objecttype data into the CDS and access it via an automatically created workbook-internal copy of the objecttype. Additionally, further requirements must be met.

Contained in system roles Analyst, Creator, Administrator.

Edit advanced layer settings

The user sees the button in the Designer that opens the dialog to edit advanced layer settings and can edit the settings.

Contained in system roles Analyst, Creator, Administrator.

Move workbook-internal data to the data catalog

The user can move self-service data that was previously only available internally within workbooks to the data catalog. The data and the associated objecttypes are thus also available outside the workbook and can be managed in the Management Center.

Contained in system roles Analyst, Creator, Administrator.

Add empty map views

The user can add empty map views to the workbook.

Contained in system roles Creator, Administrator.

Couple map views

The user can link map views of the same worksheet in order to synchronize their current map section. Also enables editing of overview map options.

Contained in system roles Analyst, Creator, Administrator.

Share anonymous workbook interim status

The user can copy a link to the current interim status of the workbook—including unsaved changes and filter assignments—to the clipboard. This system privilege also allows guest users to share their changes to the workbook.

Contained in no system role.

Used by Cadenza Feature: ~Interim States.

Create empty objecttypes

The user can create an empty objecttype in the Data Manager to enter data for its attributes, and he can create a new acquisition layer based on a selected geometry type (without an objecttype template).

Contained in system roles Analyst, Creator, Administrator.