System Roles and Privileges
Special system privilege
| Viewer | Analyst | Creator | Administrator | |
|---|---|---|---|---|
Manage all (Super Administrator)
This system privilege includes all other system privileges and also the highest authorization level for all repositories and all their items, with the exception of the "write data" authorization level for objecttypes. The user is a super administrator.
Please note: This system privilege can only be assigned by a super administrator. The first super administrator of the installation must be defined via configuration.
Contained in no system role.
Administration
| Viewer | Analyst | Creator | Administrator | |
|---|---|---|---|---|
Manage all subscriptions (Requirement: "Use subscription function") |
||||
Manage interim status of workbooks in the Management Center
The user can manage interim statuses for all workbooks in the Management Center (access to the "Interim statuses" tab in the "Workbooks" section).
Contained in system role Administrator.
Used by Cadenza Feature: ~Interim States.
Manage all subscriptions (Requirement: "Use subscription function")
The user can monitor, edit, disable, and delete all subscriptions. The system privilege "Use subscription function" is also required. Only users with authorization for the corresponding workbook (authorization level "Edit and manage") and repository (authorization level "Edit content") can edit filters and the condition.
Contained in system role Administrator.
Used by Cadenza Feature: Subscriptions.
Access Management Center
The user can use the Management Center in principle. A requirement is that a repository database is connected.
Additional system privileges may be required for individual tasks within the Management Center.
Contained in system roles Analyst, Creator, Administrator.
Use Query Logger for workbooks
The user can analyze the database queries of views with the Query Logger.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: Query Logger.
Export repositories
The user can export a repository in the Management Center. Authorization for the repository is required.
Contained in system role Administrator.
Used by Cadenza Feature: ~Interactive Lifecycle Management.
Import repositories
The user can import a repository in the Management Center.
Contained in system role Administrator.
Used by Cadenza Feature: ~Interactive Lifecycle Management.
Create new repositories
The user can create a new repository in the Management Center.
Contained in system roles Creator, Administrator.
Create new workbooks
The user can create a new workbook. Authorization for a repository is required.
Contained in system roles Analyst, Creator, Administrator.
Export and import workbooks
The user can export and import workbooks. Additionally, the user can import new versions of existing workbooks. Authorization for the workbook is required.
These functions are also available in the Management Center.
Contained in system role Administrator.
Used by Cadenza Feature: ~Interactive Lifecycle Management.
Manage user roles
The user can manage user roles in the Management Center.
Contained in system role Administrator.
Manage user groups
The user can manage user groups in the Management Center.
Contained in system role Administrator.
Import identity provider groups
The user can import user groups from an identity provider.
Contained in system role Administrator.
View and select existing users
The user can view and select all users in user selection lists. Without this privilege, usernames can only be entered as text, and for security reasons there is no feedback on whether the users exist.
Contained in system roles Analyst, Creator, Administrator.
View and select existing user groups
The user can view and select all user groups in user group selection lists. Without this privilege, the names of user groups can only be entered as text, and for security reasons there is no feedback on whether a user or user group with the specified name exists.
Contained in system roles Analyst, Creator, Administrator.
Create and edit views with JasperReports report
The user can create and edit views in workbooks that include a report (JasperReports). Authorization for the workbook is required.
Contained in system role Administrator.
Used by Cadenza Feature: ~Jasper Reports.
Create new projects
The user can create a new project. Authorization for the repository is required. The project feature must be enabled in the repository.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: Cadenza Projects.
Create new collective projects
The user can create a new collective project in the Management Center. The repository must have authorization, and the project function must be enabled.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: Cadenza Projects.
Manage analytics extensions
The uer can register and manage analytics extensions in the Management Center.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: Analytics Extensions.
Manage repository data sources
The user can manage repository data sources in the Management Center. Authorization for a repository is required.
Contained in system roles Creator, Administrator.
Manage cross-repository data sources
The user can manage cross-repository data sources in the Management Center.
Contained in system role Administrator.
Manage links/drill-throughs to external content
The user can manage base links and their link extensions in the Management Center. Authorization for a repository is required.
Contained in system roles Creator, Administrator.
Manage report layouts
The user can create and manage report layouts in the Management Center. For creation, authorization for a repository is required. For management, authorization for the report layout is required.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: ~Reports.
Reactivate data protection contexts
The user can view the section containing inactive data protection contexts in the data protection context overview.
This section includes data protection contexts whose deletion date has been reached or that were manually deleted before the date was reached, but which are still within the configured grace period (data protection contexts with the status “deleted”).
They can also reactivate inactive data protection contexts. Authorization for the data protection context is required.
In the repository, the “Extended data security” function must be enabled with the “Data protection contexts” security mode.
Contained in system role Administrator.
Used by Cadenza Feature: Data Protection.
Manage data protection contexts
The user can view the “Data protection contexts” section in the Management Center and create, edit, share, and delete data protection contexts there. Authorizations are required for data protection contexts. (The system privilege is not required to create a data protection context while creating an objecttype, a workbook, or a project.) In the repository, the “Extended data security” function must be enabled with the “Data protection contexts” security mode.
Contained in system roles Creator, Administrator.
Used by Cadenza Feature: Data Protection.
Manage Location Finder
The user can manage search sources and other settings for the Location Finder in the section "System settings" of the Management Center. As an alternative, the system privilege “Manage system settings” is required.
Contained in system role Administrator.
Manage map views
The user can manage the map views of repositories in the Management Center. Authorization for the map view and its repository is required.
Contained in system roles Creator, Administrator.
Define default map view
The user can define one of the map views from the repositories as default in the Management Center. This setting applies Cadenza-wide. Authorization for the map view and its repository is required. Additionally, the system privilege "Manage map views" is required.
Contained in system role Administrator.
Manage system settings
The user can manage system settings in the Management Center. To manage the Location Finder, the system privilege "Manage Location Finder" is additionally required.
Contained in system role Administrator.
~Use Management API
The user can use the Management API.
Contained in system role Administrator.
Used by Cadenza Feature: ~Management Api.
Data import/export
| Viewer | Analyst | Creator | Administrator | |
|---|---|---|---|---|
Import archive files
The user can import archive files (ZIP, KMZ).
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Features: CSV Import, Excel Import, GPX Import, GeoPackage Import, KML Import, ODS Import, Shapefile Import.
Import GeoJSON data as a layer (via Cadenza API only)
Contained in system role Administrator.
Used by Cadenza Feature: GeoJSON Import.
Import Excel, ODS and CSV files
Der Benutzer kann Excel-, ODS- und CSV-Dateien importieren.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Features: CSV Import, Excel Import, ODS Import.
Export data as Excel, ODS and CSV file
The user can export tables to Excel, ODS and CSV files.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Features: CSV Export, Excel Export, ODS Export.
Import GeoPackage files
The user can add GeoPackage layers to a map view.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: GeoPackage Import.
Export data as GeoPackage file
The user can export tables and map layers to GeoPackage files.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Feature: GeoPackage Export.
Import KML files
The user can add KML layers to a map view.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: KML Import.
Export data as KML file
The user can export map layers as a KML file.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Feature: KML Export.
Import shapefiles
The user can import shapefiles.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Shapefile Import.
Export data as shapefile
The user can export map layers as a shapefile.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Shapefile Export.
Import GPX files
The user can import GPS Exchange Format (GPX) files.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: GPX Import.
Export data as GPX file
The user can export GPS Exchange Format (GPX) files.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Feature: GPX Export.
Features
Manage personal interim status in the workbook
The user can save the current status of the open workbook and thus retain an overall picture of their work by saving the current snapshot.
Note: This system privilege particularly enables users without authorization to save or copy the workbook to retain their settings.
Contained in system role Viewer.
Used by Cadenza Feature: ~Interim States.
Add layer from geodata services to the map
The user can add layers from geodata services such as WMS and WMTS to map views.
Contained in system roles Analyst, Creator, Administrator.
Use geocoding services for IP addresses
The user can geocode IP addresses in their own data or in data of objecttypes for which they have the "write data" authorization. The function is available in workbooks in the Location Finder of the map view and via data import.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: IP Geocoding.
Provide objecttypes as a template for data acquisition in the map
The user can make objecttypes available as templates for data acquisition in the map in the Management Center ("Data acquisition" tab of the objecttype). Authorization for the objecttypes is required. The objecttype must meet certain requirements as a template for data acquisition for this function to be available.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: ~Data Acquisition in Maps.
Visualize and analyze movement data in an interactive 3D view
The user can display and analyze movement profiles in an interactive 3D view.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Movement Data Analysis.
Configure map animations and allow playback
The user can set up the animation of filter results on the map for individual workbook filters and enable playback of the animation.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Map Animation.
Create and edit spatial filters
The user can create spatial filters and edit existing spatial filters in workbooks.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Spatial Filtering.
Create new objecttypes from templates for data acquisition in the map
The user can create acquisition layers in workbooks. requirement: The user has at least the "Use (restricted)" authorization for at least one objecttype that has been made available as a template for data acquisition in the map.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: ~Data Acquisition in Maps.
Create, update and delete data
The user can acquire data for an objecttype in workbooks. requirement: The user has the "write data" authorization for at least one objecttype that has been made available as a template for data acquisition.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Features: ~Data Acquisition in Maps, ~Data Acquisition in Tables.
Play map animations
The user can animate the filter assignment in workbooks using the integrated player in the map.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Feature: Map Animation.
Create and edit signature libraries
The user can create and manage signature libraries while editing a sketch layer. Authorization for the repository where the signature library is to be stored is required.
Contained in system roles Creator, Administrator.
Create sketch layers (Requirement: "Edit sketch layers")
The user can add sketch layers to a map view. Additionally, the system privilege "Edit sketch layers" is required. Authorization for the workbook is required.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Sketch Layer.
Edit sketch layers
The user can edit sketch layers of a map view. Authorization for the workbook is required.
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Feature: Sketch Layer.
Use subscription function
The user can subscribe to individual worksheets of a workbook and manage their own subscriptions.
Contained in system roles Viewer, Analyst, Creator, Administrator.
Used by Cadenza Feature: Subscriptions.
Create and edit function attributes
The user can create and edit function attributes for objecttypes.
| With this privilege, the user gains the ability to generate far-reaching SQL statements. There are situations where this privilege is required, but at the same time it should be granted as rarely as possible and only in conjunction with clear instruction. If the privilege should not be available in principle, the feature must be disabled. |
Contained in no system role.
Enrich objecttypes with data
The user can enrich objecttypes with data from other information sources. Authorizations for the objecttypes are required.
Contained in system roles Analyst, Creator, Administrator.
Copy data from a data source to the workbook (workbook-internal copy)
The user can copy objecttype data into the CDS and access it via an automatically created workbook-internal copy of the objecttype. Additionally, further requirements must be met.
Contained in system roles Analyst, Creator, Administrator.
Edit advanced layer settings
The user sees the button in the Designer that opens the dialog to edit advanced layer settings and can edit the settings.
Contained in system roles Analyst, Creator, Administrator.
Move workbook-internal data to the data catalog
The user can move self-service data that was previously only available internally within workbooks to the data catalog. The data and the associated objecttypes are thus also available outside the workbook and can be managed in the Management Center.
Contained in system roles Analyst, Creator, Administrator.
Add empty map views
The user can add empty map views to the workbook.
Contained in system roles Creator, Administrator.
Couple map views
The user can link map views of the same worksheet in order to synchronize their current map section. Also enables editing of overview map options.
Contained in system roles Analyst, Creator, Administrator.
Share anonymous workbook interim status
The user can copy a link to the current interim status of the workbook—including unsaved changes and filter assignments—to the clipboard. This system privilege also allows guest users to share their changes to the workbook.
Contained in no system role.
Used by Cadenza Feature: ~Interim States.
Create empty objecttypes
The user can create an empty objecttype in the Data Manager to enter data for its attributes, and he can create a new acquisition layer based on a selected geometry type (without an objecttype template).
Contained in system roles Analyst, Creator, Administrator.
Used by Cadenza Features: ~Data Acquisition in Maps, ~Data Acquisition in Tables.