COGNOiSe.com - The IBM Cognos Community

IBM Cognos 8 Platform => COGNOS 8 => COGNOS 8 Administration => Topic started by: TEL on 13 Feb 2008 04:07:57 AM

Title: Roles and Groups
Post by: TEL on 13 Feb 2008 04:07:57 AM
Hello everyone,

I'm starting implementing security and wondered if anyone could provide a little differentiation and definition around the function of Groups and Role in the C8 security model.

My understanding is that Groups are used to collect users together but can't be used to apply security restrictions unless attached to Roles. Users and/or Groups can be attached to roles....is this correct or am I on the wrong track completely? I reviewed the training manual and Groups and Roles always seem to be mentioned together.
I guess if the above is correct it is possible to have a security model which doesn’t user Groups at all.
Any comments greatly appreciated.
Thanks in advance
Tel
Title: Re: Roles and Groups
Post by: JGirl on 18 Feb 2008 10:55:04 PM
Roles exist in the Cognos namespace and are generally used to control access to Cognos functionality and capabilities (ie. studios, administration permissions etc) and are almost a direct mapping to license roles (eg. Consumers, Query Users, System Administrators)

Groups are generally brought in from other namespaces (eg. LDAP Finance, HR etc) are generally used to secure content such as packages, reports, report views etc.

If you have only a small number of users (30ish), there is no reason you couldnt map LDAP users directly to Cognos roles and almost do away with the need for groups (except the 'Everyone' and 'All Authenticated Users' groups in the Cognos namespace), however in larger implementations, security is much easier to manage when you use groups.

Hope this helps.
J
Title: Re: Roles and Groups
Post by: TEL on 19 Feb 2008 07:26:00 AM
Thnx J,

That's a very helpful definition.

KR

Tel