Hi,
I have a requirement to hide payroll information in an opex model from the administrator of TM1. We are now using 9.5.
I have tried using security rules against the }ElementSecurity_Employee cube without success. I set up the following rules:
['XX_DUMMY','ADMIN']=S: 'READ';
['XX_DUMMY','DATAADMIN']=S: 'READ';
['XX_DUMMY','SECURITYADMIN']=S: 'READ';
['ADMIN']=S: 'NONE';
['DATAADMIN']=S: 'NONE';
['SECURITYADMIN']=S: 'NONE';
with the intention that the admin users could have access to the Dummy element and no others. I have refreshed the security and restarted the service.
Also, with the knowledge that the admin users can remove the rules in place, do you have any suggestions on how to monitor that the security is not manipulated?
Thanks,
Bryan
Security Rules
-
- MVP
- Posts: 3704
- Joined: Fri Mar 13, 2009 11:14 am
- OLAP Product: TableManager1
- Version: PA 2.0.x
- Excel Version: Office 365
- Location: Switzerland
Re: Security Rules
Admin is Admin.
The access levels of the default admin groups cannot be overwritten by manual entry (either direct values or rules). This is one of the things we have to live with in the TM1 security model.
If it is imperative that the admin not be able to see payroll data then the best way to do this is to have payroll residing on a separate TM1 server instance where admin rights are more restricted. Of course this can have implications depending on your licensing model.
The access levels of the default admin groups cannot be overwritten by manual entry (either direct values or rules). This is one of the things we have to live with in the TM1 security model.
If it is imperative that the admin not be able to see payroll data then the best way to do this is to have payroll residing on a separate TM1 server instance where admin rights are more restricted. Of course this can have implications depending on your licensing model.
-
- Posts: 11
- Joined: Wed Jun 04, 2008 8:49 am
- OLAP Product: TM1
- Version: 9.1 SP3
- Excel Version: 2003
Re: Security Rules
Thanks. That's what I thought.
I saw an earlier thread that suggested through the use of rules you could make the Admin user unusable, so I thought I'd have a quick play with some rules.
I saw an earlier thread that suggested through the use of rules you could make the Admin user unusable, so I thought I'd have a quick play with some rules.