Is it possible to define a read-only user?

Everything about Control-M Enterprise Manager Server installation or setup.
Post Reply
User avatar
eche1984
Nouveau
Nouveau
Posts: 44
Joined: 28 Apr 2009 12:00
Location: Buenos Aires, Argentina

Is it possible to define a read-only user?

Post by eche1984 » 16 Mar 2010 4:49

Hi, people!!!

I would like to define a CTM-EM user who can only view the progress of jobs and if it ends OK or not.

Also, I would like to this user to not be able to modify or execute any job.

I will be pleased if anyone knows how I can do it or where can I get documentation about this.

Thanks,
Eche

User avatar
Walty
Nouveau
Nouveau
Posts: 473
Joined: 20 Jan 2006 12:00

Post by Walty » 17 Mar 2010 4:29

Hi,

Put your user in the predifined group named <BrowseGroup>
Another solution would be to create a <new group> with your own specific permissions, and then put the user in this new group.

- The user(s) that belong to that group logout of CONTROL-M/Enterprise Manager GUI clients and CONTROL-M/Enterprise Manager Desktops.
- Recycle the Gui-Server to make the change take effect.

Once all are logged out, they can login again.
Best regards
Walty

User avatar
eche1984
Nouveau
Nouveau
Posts: 44
Joined: 28 Apr 2009 12:00
Location: Buenos Aires, Argentina

Post by eche1984 » 17 Mar 2010 5:45

Thanks, that was very useful.

Now, I want to go one step beyond. Do you know if is possible to give a user permission to submit certain jobs?

I have some Unix & Win jobs that are part of a chain and I'm in charge of starting it. I want the Win operator to have a CTM-EM user only to submit, check or rerun the Win job not all the jobs in CTM-EM.

Hope you understand my point.
Thanks again.

User avatar
Walty
Nouveau
Nouveau
Posts: 473
Joined: 20 Jan 2006 12:00

Post by Walty » 18 Mar 2010 9:01

Yes,

You can do this using the Control-M/EM Security mechanism. If you work with the Full Security Level parameter set to N (default) on Control-M/Server the users not defined in Control-M/Server security will have their rights controlled at Control-M/EM level exclusively.

The implementation of the security level in a DataCenter is very different from one customer to another.
For this reason, I recommend reading the following manuals: Control-M/EM Manager and Control-M/Server Admin Guide.

The security mechanisms of Control-M/EM and Control-M/Server together ensure a high degree of security.
Best regards
Walty

User avatar
eche1984
Nouveau
Nouveau
Posts: 44
Joined: 28 Apr 2009 12:00
Location: Buenos Aires, Argentina

Post by eche1984 » 07 Jul 2011 7:47

Do you know if I can limit an user to access to a specific view point?

Thanks,
Eche

User avatar
Walty
Nouveau
Nouveau
Posts: 473
Joined: 20 Jan 2006 12:00

Post by Walty » 08 Jul 2011 12:38

Hi,

I suggest to use in this situation the Control-M/EM security based on a GROUP with limited access.

Try:

From Control-M/EM Manager / Tools / Authorisations / Groups
- Create a new GROUP and allow what specific access you want (Actions)
- Select 'Filter' and choose in the 'Field' tab what specific option you want to allow (like Application, Jobname,...) and in the 'Value' tab your appropriate selection

From Control-M/EM Manager / Tools / Authorisations / Users :
- Create a new user(s) or choose existing one and select which GROUP they have access (one user can be member of a differents GROUP)

- If user is already login please execute logout/login again

Using this kind of security allow the user to see only the jobs and execute only the actions that they are allowed in the GROUP. The user is not dependent on the type of viewpoint used.
Best regards
Walty

User avatar
eche1984
Nouveau
Nouveau
Posts: 44
Joined: 28 Apr 2009 12:00
Location: Buenos Aires, Argentina

Post by eche1984 » 08 Jul 2011 4:29

Thanks, that info was what I needed!!!

Post Reply