Skip to main content
Version: 5.1.1.0

Edit User - Assign Access Rights

Apart from the General and Authentications tabs, the user details dialog contains three additional tabs: Groups, Roles, and Scenarios.

User Permissions

Orchestra distinguishes between groups, roles, and scenario permissions. The configuration of these permissions can be performed using the remaining tabs in the user details dialog.

A permission group is a collection of multiple roles. If a group is enabled, roles related to that group cannot be manually disabled via the Roles tab.

danger

Be aware that the permission management is a powerful tool and should only be used by experienced Orchestra system administrators.

note

To ensure access to the monitor at all times, please refrain from altering the roles and groups of default Orchestra users (admin and monitor).

For detailed information about the permissions and their meanings, please refer to the table below:

GroupRoleDescription
SystemEventsPermission to control access to system event management
SystemEvents.ViewPermission to view system events
SystemEvents.DeletePermission to delete system events
AdapterPermission to configure the channel settings for the user-assigned scenarios
AdapterMonitorPermission to view the channel administration (only user-assigned scenarios will be considered)
AdapterManagementPermission to use the reset function on the adapter details view
Adapter.ActivatePermission to activate an adapter (channel)
Adapter.DeactivatePermission to deactivate an adapter (channel)
LandscapePermission to configure the landscape settings for the user-assigned scenarios
LandscapeAdminPermission to use the backup and recovery functionality
LandscapeViewPermission to view the landscape administration (only user-assigned scenarios will be considered)
LandscapeUpdatePermission to adapt the landscape entry configuration
MonitorPermission to analyze log files and permits access to process monitoring
MonitorLogPermission to access logging groups and log files
MonitorProcessPermission to access process monitoring (only user-assigned scenarios will be considered)
ShowMessageDataPermission to access the content of messages inside the processes
AdminPermission to control processes and manage scenario users
DelProcessLogPermission to abort and delete processes (including process logs)
UsersPermission to manage scenario users
AdminUserPermission for administration of monitor and scenario users
AdminScenarioUsersPermission to maintain scenario users
DeploymentPermission to access the scenario administration
DeployPermission to deploy a scenario
UndeployPermission to undeploy a scenario
RedeployPermission to redeploy a scenario
ListPermission to view scenario administration (only user-assigned scenarios will be considered)
Scenario.DownloadPermission to download PSC files for deployed scenarios
Scenario.ActivatePermission to activate a scenario
Scenario.DeactivatePermission to deactivate a scenario
Runtime and ScenarioPermission for scenario and runtime control
Scenario.SuspendResumePermission to control the scenario triggers and persistent queuing
Scenario.SuperUserPermission to view all scenarios (the scenario assignments tab will be ignored)
Runtime.StartPermission to start the runtime
Runtime.StopPermission to stop the runtime
WEBDAV.SUPERUSERGrants administrative access to web-DAV channels
TimerPermission to configure the timer settings for user-assigned scenarios
TimerViewPermission to view the timer administration (only user-assigned scenarios will be considered)
TimerUpdatePermission to modify the timer configuration
TimerPausePermission to start and stop a timer
ThrottlingPermission to configure the throttling settings for users
Throttling.ViewPermission to access the Throttling page in read mode
Throttling.ModifyPermission to modify the throttling configuration
Lookup TablePermission to configure the lookup table settings
LookupTableViewPermission to access the lookup table page in read mode
LookupTableUpdatePermission to modify the lookup table configuration
LicensingPermissions to access and control licensing
Licensing.ViewPermission to access the licensing page in read mode
Licensing.AdminPermission to process the licensing workflow
OtherPermission to access web-related applications, control scenario documentation, and enable additional functionality
ServerAdministratorPermission to save settings in general settings like logout period or log level
RemoteAdministratorAccess to the internal web services
KpiViewMonitorPermission to access the signal monitoring dashboard
RestartProcessPermission to use the process restart functionality
Documentation.ScenarioPermission to view scenario documentation (only user-assigned scenarios will be considered)
Documentation.ServerPermission to download scenario documentation for all deployed scenarios
Serverinfo.DetailsPermission to view and download server information
BusinessCalendarPermission to use the business calendar functionality
AlertSystem.ViewPermission to view the administrative interface of alerting
AlertSystem.ModifyPermission to maintain the alerting rules and actions (includes download and recovery)
Show.hidden.variablesPermission to view all process variables regardless of protection (if "hide.process.variables" is true)
Cell.AdminAccess to the CellCommunicationServiceMonitor
LandscapeAdminPermission to edit/execute landscape entries
LandscapeUpdatePermission to update/change landscape information
QueryModuleInfoPermission to see module overview in the Module Info tab of Server info, providing insights into module status
Recompute.LTA.StatisticsPermission to recompute statistics of LTA
Recompute.Process.OverviewPermission to recompute process overview
EnvironmentSettings.ReaderPermission to read environment settings in the monitor
EnvironmentSettings.WriterPermission to modify environment settings from the monitor
HealthCheckAdminPermission to edit the HealthCheck
HealthCheckUserPermission to execute the HealthCheck
Remote.External.Monitor.EndpointPermission to access the external monitoring endpoint
Remote.ImpersonationTrust in users authenticated by a remote Orchestra
Remote.Qbilon.ExportPermission to access the Qbilon endpoint
Remote.AdministratorPermission to access the Orchestra remote web services via HTTP/HTTPS
Patching.AdminPermission to manage Orchestra patching, including scheduling and execution
Change.process.user.statePermission to manage user-defined process state in the monitoring view
Security.ExportRuntimePermission to export runtime configurations
Security.ImportRuntimePermission to import runtime configurations
ServerMaintenancePermission to evaluate SQL statements via RemoteService DatabaseMonitorService