TRUECHART Knowledge Base Live Search

Search

Page tree

trueChart Help

Skip to end of metadata
Go to start of metadata

Data Security Role

Data Permission Roles can be added here for the user based on Dimension and its Value .

Users will be presented with the below screen

Source - Specifies the source from which the Role is added. It can imported from an Excel file , Active Directory or Manually added 

Role - Set of security Roles which is identified as a role. 

User - For which user the Role is created 

Dimension 1+/Value 1+ - The columns here are dynamically created by the Dimensions the user has selected for the roles

Data Security Roles Add/Edit

Added Roles can be edited or deleted - Select a Role and Edit/Delete button will be enabled . 

Settings - Will open up the data permission in TRUECHART Management Console for importing the Role through modes File Import or Active Directory Import . See more on how to import file below

Create a Data Security Role :

  1. Click on the +Add Button which opens the create data security Role page 

The user will be presented with the below:


  1. Enter the role name
  2. Select the user from the  dropdown
  3. Click on +Add button to add a Dimension and its value
  4. Select Dimension and Enter the Value for the selected dimension .

When creating a Role outside a BI Platform the user will be required to enter the Dimension name and not select it

Where multiple Dimensions are added, the permissions will be applied in an "AND" method . e.g. :

User "Bob" is only allowed to view and collaborate on his own client data. 

His role will be defined as :

Dimension 1 

Country                          UK

Dimension 2

Client                             Client XYZ, Client MNO

In order for Bob to utilize KPI-CHAT for his clients he must select both the UK  AND any 1(or more) client before KPI-CHAT will allow him access


Data Permission Roles in TCMC

Following the update in v2021.2.0, Data Permission Roles can now also be managed from within TCMC

Source - Specifies the source from which the Role is added. It can imported from an Excel file , Active Directory or Manually added 

Role - Set of security Roles which is identified as a role. 

Description - A short description of the role for ease of reference

Dimension 1+/Value 1+ - The first 2 Dimensions of the Role and their values

Data Security Roles Add/Edit

Roles can be edited or deleted . When editing a role, users will be presented with the below screen

User - For which user the Role is created 

Description - A short description of the role for ease of reference

Add Dimension - Add a new Dimension to restrict access for the selected Role

Dimension Value - The Dimension Name and it's values. Separated by a semicolon where multiple values are specified

Users Table - Select the users that will be linked to this Role



How to import file using File import and Active Directory 

  1. Open the TRUECHART Management Console and Click on User Administration
  2. Click on the Data Permission tab from the left side panel
  3. Click on Bulk Data Permissions.
  4. Click on File Import 

       File Import:



Import file (csv format) link can be given on FilePath . When the Activate check box is enabled. The file on the given path will be imported as per the Cron expression given .

Save the Changes once all parameters are given and security Roles will be imported to database with the next Cron timer.

Sample Format of a csv import file can be found here Data Permissions Import Sample.csv

  • File is comma separated              ,
  • To separate values for Dimensions make use of a semicolon             ;

Additional Information how to create a Cron expressions can be found here 

     Active Directory:


Available active directory connection that  are added using the Active Directories panel from TCMC will be listed in available connections .

Here we need to set up the Security Schema Rule . The AD should have the same same schema that we mention here in order import rules successfully .

Rule DN - Distinguished Name . Eg cn=name , common name which is used to identity the security rule.

Rule object filter - expression used for search.

Attribute : Role name- identifying name role  (Mandatory)

Attribute : User - identifying name of user (Mandatory)

Additional attributes - Additional attributes can be mentioned here as comma separated values.

Sample Format files of a AD scheme definition (attributes and classes) cane be found here . This can be set up using AD handle tools (apache studio) in AD.

SecurityRuleClassImportable.ldif

SecurityRuleAttributes.ldif

Related Topics:

TRUECHART Management Console 


Permissions on Filters in a Channel :

When in Channel Create/Edit Menu,  Expand the Filters menu and select or add(+) a Filter 

Within the Filter Edit screen, select  to add a Data permission set to the Filter:

  1. Select the required Role - note the Role must have a Dimension that corresponds to the Filter
  2. Select whether the user will have View or Edit Permissions to this Filter. 
  3. Click OK when complete

In cases where a Channel has multiple Filters that correspond to multiple Dimensions on a role, the user will have to link the Role to all relevant Filters of a Channel. 

e.g. 

User "Bob" is only allowed to view and collaborate on his own client data. 

His role will be defined as :

Dimension 1 

Country                          UK

Dimension 2

Client                             Client XYZ, Client MNO

The Channel FIlters will be "Country" and "Client". The user will then link the role that was allocated to Bob on both Permission sets in Filters


Channel Filters in trueChart Management Console

Users can manage Channel filters and their Data Permission Roles from within TCMC as well:

  • Select a Channel
    • If the channel is new, users may Refresh to update the list of channels
  • Select or Add a Filter Or Edit an existing Filter
    • Show in Chat Header will allow this Filter name to be shown in the Chat header of a KPI Chat window
  • Selecting a Filter will allow users to enable the required Roles for a Filter
    • View will allow the users linked to this Role to only view content in this Filter
    • Edit will allow users to participate in the Filter's chat



Related Topics:

Filters and Data Dependencies 








  • No labels