Authorization Levels for Repository Items
Introduction
This page gives an overview of the item-related roles and associated privileges that can be assigned in Cadenza Workbooks. If you’re looking for system privileges then you can find them here: System Privileges and Default Roles
Each item (repository, data source, object type, workbook) in Cadenza Workbooks has individual roles that can be assigned to a user. A user can therefore have different roles for different items. This allows a user to have write access to one workbook and edit its contents while having read-only access to another workbook. In addition, there can be workbooks to which he has no access at all.
The item related roles are an addition to the standard roles in Cadenza Workbooks. A user can have different item related roles for different items, but in Cadenza the user has only one standard role, which defines his functionality holistically via application privileges.
The following tables show the roles and privileges for the individual items. All tables are structured in the same way:
-
On the horizontal axis are the hard coded roles of the item
-
On the vertical axis are the privileges that grant certain actions or views in Cadenza
Repository
Use content |
Edit content |
Manage content |
Edit and manage |
Owner |
Granted Actions |
|
See repository in the repository overview in the Management Center |
✅ |
✅ |
✅ |
✅ |
✅ |
|
Open repository and see its items |
✅ |
✅ |
✅ |
✅ |
✅ |
|
Edit content of repository (add, edit and delete items) |
✅ |
✅ |
✅ |
✅ |
|
|
Edit repository |
✅ |
✅ |
✅ |
|
||
See the items of the repository in the overviews in the Management Center, delete them and see their owners |
✅ |
✅ |
✅ |
|
||
Access all items of repository without any restrictions |
✅ |
✅ |
|
|||
Delete repository |
✅ |
✅ |
✅ |
|
||
Share repository |
✅ |
✅ |
|
|||
See owner of repository |
✅ |
✅ |
|
|||
Change owner of repository |
✅ |
Project
Use (restricted) |
Use (unrestricted) |
Edit and manage |
Owner |
Granted Actions |
|
See project in the project overview in the Management Center |
✅ |
✅ |
✅ |
|
|
Use project workbooks in a restricted way |
✅ |
✅ |
✅ |
✅ |
|
Use project workbooks |
✅ |
✅ |
✅ |
|
|
Add, edit and delete workbooks and objecttypes |
✅ |
✅ |
✅ |
|
|
Edit project properties |
✅ |
✅ |
|
||
Delete project |
✅ |
✅ |
|
||
Share project |
✅ |
✅ |
|
||
See owner of project |
✅ |
✅ |
|
||
Change owner of project |
✅ |
Data protection context
Every authorization level: The user can see at the name if a DPC is set.
Use |
Edit content |
Edit and manage |
Owner |
Granted Actions |
|
See data protection in the data protection overview in the Management Center |
✅ |
✅ |
✅ |
✅ |
DPC is listed, e.g. in the MC, with limited details |
Use data protection context |
✅ |
✅ |
✅ |
✅ |
Details of the DPC can be read (e.g. detail page in MC) |
Add projects, workbooks and objecttypes to the data protection context |
✅ |
✅ |
✅ |
OT, Workbooks and projects can be assigned to the DPC, DPC can be changed/updated (adding OTs) |
|
Change data protection context properties |
✅ |
✅ |
Details of an DPC can be changed. DPC can be prolonged/confirmed |
||
Delete data protection context |
✅ |
✅ |
DPC can be deleted |
||
Share data protection context |
✅ |
✅ |
DPC can be shared |
||
See owner of data protection context |
✅ |
✅ |
See the owner of the DPC (for example in the overview list in MC) |
||
Change owner of data protection context |
✅ |
Datasource
Every authorization level:
-
view details of an object type that is based on this data source
-
use object type in workbook that is based on this data source
-
see the name of the data source (e.g. if shown on OT or in data manager or in filters in the Management Center)
-
A CDS data source can be used to import data without any authorization level on it (additional privilege(s) on the repository needed)
Use |
Edit and manage |
Owner |
Granted Actions |
|
See data source in the data source overview in the Management Center |
✅ |
✅ |
✅ |
|
Open data source |
✅ |
✅ |
✅ |
|
Create an objecttype from data source |
✅ |
✅ |
✅ |
|
Edit data source |
✅ |
✅ |
|
|
Delete data source |
✅ |
✅ |
|
|
Share data source |
✅ |
✅ |
|
|
See owner of data source |
✅ |
✅ |
|
|
Change owner of data source |
✅ |
|
Objecttype
Use (restricted) |
Use (unrestricted) |
Edit and manage |
Owner |
Write data |
Granted Actions |
|
See objecttype in the objecttype overview in the Management Center |
✅ |
✅ |
✅ |
|
||
Use objecttype in a restricted way |
✅ |
✅ |
✅ |
✅ |
|
|
Use objecttype without any restrictions |
✅ |
✅ |
✅ |
|
||
Edit and overwrite objecttype |
✅ |
✅ |
|
|||
Change data of objecttype |
✅ |
✅ |
|
|||
Delete objecttype |
✅ |
✅ |
|
|||
Share objecttype |
✅ |
✅ |
|
|||
See owner of objecttype |
✅ |
✅ |
|
|||
Change owner of objecttype |
✅ |
|
Workbook
Use in simplified mode |
Use |
Edit and manage |
Owner |
Granted Actions |
|
See workbook in the workbook repository in the Management Center |
✅ |
✅ |
✅ |
|
|
Open the workbook and use it with restricted access and simplified mode |
✅ |
✅ |
✅ |
✅ |
|
Open the workbook without restrictions and create a copy if necessary |
✅ |
✅ |
✅ |
|
|
Overwrite workbook |
✅ |
✅ |
|
||
Delete workbook |
✅ |
✅ |
|
||
Share workbook |
✅ |
✅ |
|
||
See owner of workbook |
✅ |
✅ |
|
||
Change owner of workbook |
✅ |
|
Analytic Extension
Every authorization level:
Analytics Extension type "Data Generation" or "Data Enrichment"
-
Use object types (visualize data etc.) - more privileges needed on the OT depending on the action.
Use |
Edit and manage |
Owner |
Granted Actions |
|
See analytics extension in the analytics extension overview in the Management Center |
✅ |
✅ |
✅ |
|
Use analytics extension |
✅ |
✅ |
✅ |
|
Edit analytics extension |
✅ |
✅ |
|
|
Delete analytics extension |
✅ |
✅ |
|
|
Share analytics extension |
✅ |
✅ |
|
|
See owner of analytics extension |
✅ |
✅ |
|
|
Change owner of analytics extension |
✅ |
|
Base link to external content
Use |
Edit and manage |
Owner |
Granted Actions |
|
See base link in the base link overview in the Management Center |
✅ |
✅ |
✅ |
|
Use base link |
✅ |
✅ |
✅ |
|
Edit base link |
✅ |
✅ |
|
|
Delete base link |
✅ |
✅ |
|
|
Share base link |
✅ |
✅ |
|
|
See owner of base link |
✅ |
✅ |
|
|
Change owner of base link |
✅ |
|
Workbook Report Layout
Use |
Edit and manage |
Owner |
Granted Actions |
|
See report template in the report template overview in the Management Center |
✅ |
✅ |
✅ |
|
Use report template |
✅ |
✅ |
✅ |
|
Edit report template |
✅ |
✅ |
Additionally, the ManageReportTemplates system privilege is required. |
|
Delete report template |
✅ |
✅ |
Additionally, the ManageReportTemplates system privilege is required. |
|
Share report template |
✅ |
✅ |
|
|
See owner of report template |
✅ |
✅ |
|
|
Change owner of report template |
✅ |
|
Layer
Use |
Edit and manage |
Owner |
Granted Actions |
|
See layer in the layer overview in the Management Center |
✅ |
✅ |
✅ |
|
Use layer |
✅ |
✅ |
✅ |
|
Edit and overwrite layer |
✅ |
✅ |
|
|
Delete layer |
✅ |
✅ |
|
|
Share layer |
✅ |
✅ |
|
|
See owner of layer |
✅ |
✅ |
|
|
Change owner of layer |
✅ |
|
Map views
Every authorization level:
The "default" map view can be used by any user without additional privileges:
-
visible privilege on the repository is still needed additionally
-
visible privilege on the default map view is granted "automatically"
-
for editing/overwriting/deleting the default map view write/delete privileges still need to be assigned to the user
Use |
Edit and manage |
Owner |
Granted Actions |
|
See map view in the map view overview in the Management Center |
✅ |
✅ |
✅ |
|
Use map view |
✅ |
✅ |
✅ |
|
Edit and overwrite map view |
✅ |
✅ |
|
|
Delete map view |
✅ |
✅ |
|
|
Share map view |
✅ |
✅ |
|
|
See owner of map view |
✅ |
✅ |
|
|
Change owner of map view |
✅ |
|