Create a Custom Role

Why Create a Custom Role?

In many cases, the predefined roles are sufficient. You might choose to create additional roles for these reasons:
  • To decrease the level of granularity by creating an umbrella role that aggregates two or more existing roles. For example, you might create a role that includes all capabilities other than those of the most privileged roles.
  • To increase the level of granularity by creating a mini-role that provides only a subset of the capabilities of a predefined role. For example, you might create a custom role called Report Distribution that provides only the report scheduling and distribution capabilities for SAS Web Report Studio.
  • To create a cross-application role for a particular type of functionality. For example, you might create an OLAP role that includes the OLAP capabilities from SAS Enterprise Guide and the SAS Add-In for Microsoft Office.

How to Create a Custom Role

  1. On the Plug-ins tab, select User Manager and make sure you are in the correct repository.
    Note: You usually create roles in the foundation repository. You can also create roles in custom repositories.
  2. Right-click and select Newthen selectRole.
  3. In the Properties dialog box:
    1. On the General tab, enter a name.
    2. On the Members tab, assign users and groups to the role.
    3. Define the role's capabilities using either or both of these techniques:
      • Assign capabilities to the role by selecting check boxes on the Capabilities tab. Clicking a tree icon changes the status of the selections beneath that icon's node.
      • Give this role all of the capabilities of one or more other roles by using the Contributing Roles tab. For example, to create a role that includes all capabilities other than those of the most privileged roles, select the Contributing Roles tab, move all roles over and then move the metadata server roles back.
        Note: Changes that you make to a role's capabilities affect any roles to which that role contributes its capabilities.
        Note: You can't selectively assign or incrementally remove a contributed capability.
Note: You don't have to make changes on the role's Authorization tab. This tab has no effect on what the role can do.
Tip
(Optional) To test the new role, temporarily assume the identity of one of its members. See Assume Another User's Identity.