Skip to main content

Disable developer access to edit security profile, this should be limited to admin team responsibilities. Specially in a complex scenario where we have multiple projects using Syniti ADMM and we have a centralized admin team to manage the resources

4 comments

Log in to comment and vote

Comments4

  • John Munkberg

    Team•

    Apr 30

    Got it, thank you. Any suggestions on how to differentiate these roles in the Manager screen?

    My initial proposal -

    Manager - Do everything (assign and modify users)

    Consumer - This “type” of manager can use the security profile to assign to Assets. These folks can “consume” the Security Profile as needed (?? not sure I love that name).

    User Manager - These users can only change the users, not assign/unassign the Profile to assets ( not sure this role even makes sense.)

    • Sridhar Kolan

      •

      Apr 30

      we need these feature differences between admin and developer

      1. Admin will create and own the security profile, assign roles and users groups, only this role should have access to edit and add to this profile.

      2. Either give developers access to see/use all the available security profiles without assigning them as managers to specific profiles

      3. Or remove the edit access feature for a developer in the security profiles and we can add them as managers to specific profiles

  • John Munkberg

    Team•

    Apr 25

    Only the manager of a Security Profile should be able to manage that Security Profile.

    Anyone who has access to manage an object has permissions to create a new Security Profile for that object - but then only they can manage that profile unless they assign others to also be managers of that profile.

    Could you please provide a few more details because I’m not sure what specifically you are asking for. Or perhaps there is a bug in the logic you are seeing somewhere?

    • Sridhar Kolan

      •

      Apr 27

      @John Munkberg we needed developers to be assigned as managers for them to use/assign the security profile to the assets they create. Without assigning them as managers to the security profile they dont have this profile in the available drop down values. At the same time we dont want them to change any role, group assignments in the security profiles, for this we want to give them view only access in security profile. In our case there are multiple migration and quality projects using ADMM and security profiles to limit/restrict access to developers, PMO and BU’s.