企业绩效管理网

 找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 2952|回复: 14

Locking out some admins

[复制链接]

78

主题

403

帖子

578

积分

高级会员

Rank: 4

积分
578
QQ
发表于 2014-6-23 03:14:04 | 显示全部楼层 |阅读模式
I think the answer is no, but thought I would ask anyway... Is there a way to prevent some admins having access to one cube in a model?

I know I could put the cube in different model, however I want the sensitive cube to pass data (salaries aggregated to department level) back to the the non-sensitive cube. If they were in seperate models the only way I can see to pass data is via a data export/import which is not secure.

We have two system accountants that develop basic rules, therefore admins, that should not be able to see this information at leaf level.
回复

使用道具 举报

70

主题

353

帖子

524

积分

高级会员

Rank: 4

积分
524
QQ
发表于 2014-6-23 04:24:07 | 显示全部楼层
This doesn't necessarily help with your question but...

if the 2 System Accountants are only developing "basic rules" is it not preferable to in fact defer that responsibility to someone else considering that the licence for a Developer is circa 拢10k as compared to 拢1500 for a standard read/write user (that is last time I checked anyway.)
回复 支持 反对

使用道具 举报

83

主题

396

帖子

573

积分

高级会员

Rank: 4

积分
573
QQ
发表于 2014-6-23 04:25:19 | 显示全部楼层
Hmm possibly but we got a pretty good deal on the licenses and it's a big system.

I want to restrict sensitive information to some users which is easy, but lock out all but one admin which I cant think how to do.
回复 支持 反对

使用道具 举报

85

主题

419

帖子

604

积分

高级会员

Rank: 4

积分
604
QQ
发表于 2014-6-23 04:53:55 | 显示全部楼层
How about adding said 2 users to a new group "AlmostAdmin" and removing them from "Admin"...

... whilst setting "AlmostAdmin" to have Admin access to all cubes (except the one in question.)

They would also need Admin access to all dims, process etc.
回复 支持 反对

使用道具 举报

85

主题

408

帖子

596

积分

高级会员

Rank: 4

积分
596
QQ
发表于 2014-6-23 05:03:08 | 显示全部楼层
declanr wrote:How about adding said 2 users to a new group "AlmostAdmin" and removing them from "Admin"...

... whilst setting "AlmostAdmin" to have Admin access to all cubes (except the one in question.)

They would also need Admin access to all dims, process etc.
That would work for cubes, even dims but it won't work for processes and chores as the only options for non-admin users are Read or None.  If they don't write TI then perfectly acceptable.
回复 支持 反对

使用道具 举报

90

主题

419

帖子

614

积分

高级会员

Rank: 4

积分
614
QQ
发表于 2014-6-23 05:24:46 | 显示全部楼层
AmbPin wrote: but lock out all but one admin which I cant think how to do.

is that not a really bad idea from a business continiuity perspective? what happens when said person is on holiday, off sick, run over by a bus....
回复 支持 反对

使用道具 举报

69

主题

365

帖子

518

积分

高级会员

Rank: 4

积分
518
QQ
发表于 2014-6-23 05:30:59 | 显示全部楼层
Lotsaram,
Cheers for the clarification.

AmbPin,
Of course that is just a way to solve the specific question but personally I would point to my earlier post as I tend to recommend that users have the minimum security access possible to do their jobs well. Although this must be combined with a minimum of 2 full Admin users for reasons as pointed out by Steve Vincent.


Does anyone know how the IBM licencing works in regards to giving a user partial Admin access?
I imagine in the case of having Admin access tot he majority of cubes a user would need a full on "developer" licence but at what point does that stop? For example what if a user is standard read/write with admin access to 1 dimension?
回复 支持 反对

使用道具 举报

77

主题

412

帖子

590

积分

高级会员

Rank: 4

积分
590
QQ
发表于 2014-6-23 05:41:54 | 显示全部楼层
Simple answer - there isn't. TM1only has 2 types of license, to get access to various menus that are greyed out to a client you must have the admin license. There is no halfway house - you can limit an admin to just securityadmin or dataadmin (detailed in the help guide) but you still require the admin license in order to use them.
回复 支持 反对

使用道具 举报

80

主题

407

帖子

591

积分

高级会员

Rank: 4

积分
591
QQ
发表于 2014-6-23 05:42:53 | 显示全部楼层
declanr wrote:How about adding said 2 users to a new group "AlmostAdmin" and removing them from "Admin"...

... whilst setting "AlmostAdmin" to have Admin access to all cubes (except the one in question.)

They would also need Admin access to all dims, process etc.


This almost works, but if they have security admin then they can give themselves access to the cube I want hidden from them.
回复 支持 反对

使用道具 举报

82

主题

391

帖子

572

积分

高级会员

Rank: 4

积分
572
QQ
发表于 2014-6-23 06:01:04 | 显示全部楼层
If they are only writing rules for a specific few cubes, just give them Admin access to those cubes and give them write access to everything else.

If you need them to be able to change security for other users in addition to having admin access to data then I doubt you would have any option other than giving them full blown Admin access.
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|手机版|小黑屋|企业绩效管理网 ( 京ICP备14007298号   

GMT+8, 2023-5-31 05:03 , Processed in 0.081625 second(s), 40 queries .

Powered by Discuz! X3.1 Licensed

© 2001-2013 Comsenz Inc.

快速回复 返回顶部 返回列表