Previous Page | Next Page

Users, Groups, and Roles

Main Administrative Roles

Main Administrative Roles
Role Capabilities Initial Membership
[icon]
Metadata Server: Unrestricted Members have all capabilities and can't be denied any permissions in the metadata environment.1 [icon]
SAS Administrator
[icon]
Metadata Server: User Administration Members can create, update, and delete users, groups, roles (other than the unrestricted role), internal accounts, logins, and authentication domains.2 [icon]
SAS Administrators
[icon]
Metadata Server: Operation Members can administer the metadata server (monitor, stop, pause, resume, quiesce) and its repositories (add, initialize, register, unregister, delete).3 [icon]
SAS Administrators
[icon]
Management Console: Advanced Members can see all plug-ins in SAS Management Console (in the initial configuration). [icon]
SAS Administrators
1 Unrestricted users can use only those logins that are assigned to them (or to groups to which they belong). They don't automatically have implicit capabilities that are provided by components other than the metadata server.

2 Restricted user administrators can't update identities for which they have an explicit or ACT denial of WriteMetadata.

3 Only someone who has an external user ID that is listed in the adminUsers.txt file with a preceding asterisk can delete, unregister, add, or initialize a foundation repository. Only an unrestricted user can analyze and repair metadata or perform tasks when the metadata server is paused for administration.

Here are some details:

See Also

Roles Overview

Open Up Access

Role Definitions

How to Assign Capabilities to Roles

Previous Page | Next Page | Top of Page