IBM Tivoli Netcool/OMNIbus Version 8.1

Managing authorization with users, groups, roles, and restriction filters

Authorization is the verification of the rights to view and modify information.

About this task

Access to ObjectServer objects is controlled through groups (collections of users), and roles (collections of system and object permissions) granted to groups. Permissions control access to objects and data in the ObjectServer. By combining one or more permissions into roles, you can manage access quickly and efficiently.

Administrators can allow and deny actions on the system and for individual objects by assigning permissions to roles, and granting or revoking roles for appropriate groups of users. You can use Netcool/OMNIbus Administrator to grant and revoke permissions for the users of a Tivoli Netcool/OMNIbus system.

For example, creating automations requires knowledge of Tivoli Netcool/OMNIbus operations and the way a particular ObjectServer is configured. You do not typically want all of your users to be allowed to create or modify automations. One solution is to create a role named AutoAdmin, with permissions to create and alter triggers, trigger groups, files, SQL procedures, external procedures, and signals. You can then grant that role to a group of administrators who will be creating and updating triggers.

To set up Tivoli Netcool/OMNIbus authorization, configure security objects in the following order:

Procedure

  1. Roles: Assign permissions to roles.
  2. Groups: Assign one or more roles to each group. The assigned roles determine the actions that the group members can perform on database objects.
  3. Users: Add users to groups. You must assign each user to one or more groups.

Results

You can create logical groupings such as super users or system administrators, physical groupings such as London or New York NOCs, or any other groupings to simplify your security setup.


Library | Support |