Configuring Metadata Manager Privileges and Permissions
Total Page:16
File Type:pdf, Size:1020Kb
Configuring Metadata Manager Privileges and Permissions © Copyright Informatica LLC 1993, 2021. Informatica LLC. No part of this document may be reproduced or transmitted in any form, by any means (electronic, photocopying, recording or otherwise) without prior consent of Informatica LLC. All other company and product names may be trade names or trademarks of their respective owners and/or copyrighted materials of such owners. Abstract You can configure privileges to allow users access to the features in Metadata Manager. You can configure permissions to allow access to resources or objects in Metadata Manager. This article describes the privileges and permissions that you can configure in Metadata Manager. Supported Versions • Metadata Manager 9.6.1 Table of Contents Introduction................................................................ 2 Users, Groups, Privileges, and Roles................................................ 3 Privileges ................................................................. 4 Catalog Privilege Group...................................................... 4 Load Privilege Group........................................................ 6 Model Privilege Group....................................................... 7 Security Privilege Group...................................................... 7 Permissions................................................................ 8 Types of Permissions........................................................ 9 Rules and Guidelines........................................................ 9 Configuring Permissions for Users and Groups....................................... 9 Configuring Permissions for the Metadata Catalog.................................... 10 Sample Scenarios........................................................... 11 Scenario 1.............................................................. 12 Scenario 2.............................................................. 13 Scenario 3.............................................................. 13 Scenario 4.............................................................. 14 Introduction The Metadata Manager Service privileges determine the actions that you can perform using Metadata Manager. Permissions determine the resources and metadata objects that you can access in Metadata Manager. To access specific features of Metadata Manager and perform the required actions on resources or objects in Metadata Manager, you must complete the following tasks: 1. In the Administrator tool, configure the users and groups that need to access Metadata Manager. 2. In the Administrator tool, assign the required privileges or roles to the users and groups. 3. In Metadata Manager, configure the appropriate permissions for the resources or objects that the users need to access. 2 Users, Groups, Privileges, and Roles You can create and manage Metadata Manager users and groups and configure privileges and roles in the Administrator tool. To access the application services and objects in the Informatica domain and to use the application clients, you must have a user account. The tasks you can perform depend on the type of user account that you have and the type of license that you have. The Service Manager stores users and groups in the domain configuration database and copies the list of users and groups to the Metadata Manager repository. The Service Manager periodically synchronizes the list of users and groups in the repository with the users and groups in the domain configuration database. Users You can set up individual user accounts in the Informatica domain. Users can perform tasks based on the roles, privileges, and permissions assigned to them. Groups You can set up groups of users and assign different roles, privileges, and permissions to each group. The roles, privileges, and permissions assigned to the group determine the tasks that users in the group can perform within the Informatica domain. Privileges Privileges determine the actions that users can perform in application clients. You can assign different privileges to a user for each application service of the same service type. Roles Roles are collections of privileges that you can assign to users and groups. You assign roles or privileges to users and groups for the domain and for application services in the domain. The Administrator tool includes several predefined custom roles that you can assign to Metadata Manager users and groups. You can assign the following predefined custom roles to Metadata Manager users and groups: Metadata Manager Basic User This role allows users to perform tasks such as view the catalog, view the lineage, and view the model. This user role provides view permissions on the catalog and the model. Metadata Manager Intermediate User This role allows users to perform tasks such as manage links between metadata objects in a catalog and load a resource. This role includes the privileges available to a Metadata Manager Basic User. Metadata Manager Advanced User This role allows users to manage objects, resources, models, and catalog permissions. This role includes the privileges available to a Metadata Manager Intermediate User. For more information about creating users and groups and assigning roles and privileges, see the Informatica Security Guide. 3 Privileges Metadata Manager Service privileges determine the Metadata Manager actions that users can perform using Metadata Manager. You assign privileges to users and groups in the Administrator tool. The following table describes each Metadata Manager privilege group: Privilege Group Description Catalog Includes privileges to manage objects in the Browse tab of the Metadata Manager interface. Load Includes privileges to manage objects in the Load tab of the Metadata Manager interface. Model Includes privileges to manage objects in the Model tab of the Metadata Manager interface. Security Includes privileges to manage objects in the Security tab of the Metadata Manager interface. Catalog Privilege Group The privileges in the Catalog privilege group determine the tasks that users can perform on the Browse tab of the Metadata Manager application. A user with the privilege to perform a certain action also requires permissions to perform the action on a particular object. Configure permissions on the Security tab of the Metadata Manager application. The following table lists the privileges in the Catalog privilege group and the permissions required to perform a task on an object. The table also lists the Metadata Manager custom roles that have these privileges and permissions assigned by default: Privilege Includes Permission Description Metadata Manager Privileges Custom Roles Assigned with this Privilege Share Shortcuts - Write User can share a folder that contains Metadata Manager a shortcut with other users and Advanced User groups. View Lineage - Read User can perform the following - Metadata Manager actions: Advanced User - Run data lineage analysis on - Metadata Manager metadata objects, categories, and Intermediate User business terms. - Metadata Manager Basic - Run data lineage analysis from the User PowerCenter Designer. Users must also have read permission on the PowerCenter repository folder. View Related - Read User can view related catalogs. - Metadata Manager Catalogs Advanced User - Metadata Manager Intermediate User - Metadata Manager Basic User View Reports - Read User can view Metadata Manager - Metadata Manager reports in Data Analyzer. Advanced User - Metadata Manager Intermediate User 4 Privilege Includes Permission Description Metadata Manager Privileges Custom Roles Assigned with this Privilege View Profile - Read User can view profiling information - Metadata Manager Results for metadata objects in the catalog Advanced User from a relational source. - Metadata Manager Intermediate User View Catalog - Read User can perform the following - Metadata Manager actions: Advanced User - View resources and metadata - Metadata Manager objects in the metadata catalog. Intermediate User - Search the metadata catalog. - Metadata Manager Basic User View - Read User can view relationships for - Metadata Manager Relationships metadata objects, categories, and Advanced User business terms. - Metadata Manager Intermediate User - Metadata Manager Basic User Manage View Write User can create, edit, and delete Metadata Manager Relationships Relationships relationships for custom metadata Advanced User objects, categories, and business terms. View Comments - Read User can view comments for metadata - Metadata Manager objects, categories, and business Advanced User terms. - Metadata Manager Intermediate User - Metadata Manager Basic User Post Comments View Write User can add comments for metadata - Metadata Manager Comments objects, categories, and business Advanced User terms. - Metadata Manager Intermediate User Delete - Post Write User can delete comments for - Metadata Manager Comments Comments metadata objects, categories, and Advanced User - View business terms. - Metadata Manager Comments Intermediate User View Links - Read User can view links for metadata - Metadata Manager objects, categories, and business Advanced User terms. - Metadata Manager Intermediate User - Metadata Manager Basic User Manage Links View Links Write User can create, edit, and delete links - Metadata Manager for metadata objects, categories, and Advanced User business terms. - Metadata Manager Intermediate User 5 Privilege Includes Permission Description Metadata Manager Privileges Custom Roles Assigned