Redwood Documentation

Product Documentation

 

›Privileges

RunMyJobsSecurity

Roles and Users

  • Authorization
  • Partitions
  • Managing Users and Roles

Privileges

  • Privileges
  • Granted System Privileges
  • Object Security
  • Object Privileges
  • Granting and Revoking System Privileges
  • Granting and Revoking Object Privileges
  • System Privileges
  • Privileges
  • System Privileges

Required Privileges

  • Privileges Required for Objects
  • Ad Hoc Alert Sources
  • Alert Source Actions
  • Applications
  • Audit Rules
  • Audit Trail
  • SAP BAE connectors
  • Credential Protocols
  • Credentials
  • Datum Definitions
  • Documents
  • Alert Escalations
  • Event Definitions
  • Export Rule Sets
  • Export Processes
  • Formats
  • Email Alert Gateways
  • Housekeeping Dashbaord
  • Import Rule Definitions
  • Import Rule Sets
  • Import Sources
  • Imports
  • Chains
  • Process Alert Sources
  • Process Definitions
  • Definition Types (JobDefinitionsTypes)
  • Processes
  • Libraries
  • Process Locks
  • Monitoring Dashbaord
  • Monitor Alert Sources
  • Monitor Nodes
  • Operator Messages
  • Oracle Applications Systems
  • OHI Systems
  • Partitions
  • PeopleSoft Systems
  • Period Functions
  • Process Monitor Definitions
  • Process Monitors
  • Process Server Alert Sources
  • Process Servers
  • Query Filters
  • Queue Alert Source
  • Queues
  • R2W Catalogs
  • Registry Entries
  • Remote Systems
  • Reports
  • Resources
  • Roles
  • SAP Systems
  • Services
  • Shell
  • Subject Role Grant Expanded
  • Subjects
  • Submit Forms
  • Submit Frames
  • Table Definitions
  • Tables
  • Tabs and Links
  • Time Windows
  • Time Zones
  • Triggers
  • Users
  • User Messages
  • Visualization Alerts
  • Visualization Process Server Queues
← PrivilegesObject Security →

Granted System Privileges

The following core, user access, and predefined roles are available:

Core roles (always required):

  • scheduler-administrator - can perform all actions.
  • scheduler-bae-only-user - indicates that the user account is restricted to logging in via the SAP Inbound interface, only.
  • scheduler-isolation-administrator - can import and modify users.
  • scheduler-screen-reader - indicates that you are using a screen reader.
  • scheduler-user - has access to Redwood Server only, cannot see any objects (always required, even for administrators).
  • scheduler-viewer - read only access to all objects.
  • redwood-administrator - can perform all actions.
  • redwood-login - has access to Redwood Server only, cannot see any objects (always required, even for administrators).
  • redwood-support - read only access to all objects.

The user access roles are bound to features that require a specific license key:

  • scheduler-business-user - can access the business-user-centric user interface.
  • scheduler-it-user - can access the it-user-centric user interface.

Predefined roles (optional):

  • scheduler-event-operator - can raise and clear events, as well as all privileges assigned to scheduler-viewer.
  • scheduler-job-administrator - can create/edit/delete event definitions, process definitions, and chain definitions and modify both processes, and chains, as well as all privileges assigned to scheduler-event-operator.
  • redwood-operator - combination of the above two roles.
note

The roles scheduler-business-user and scheduler-it-user are use by the Insight module.

note

The scheduler-bae-only-user role actively prevents you from logging in from any other interface; for example, you will not be able to log into Redwood Server from the web interface or from any other client with this role.

All users need at least the scheduler-user role, even if they have the scheduler-administrator role, or they will not be able to access Redwood Server.

System privileges can be granted for the entire system or a partition, this allows you to limit the privilege to objects in a particular partition.

System-wide privileges are only valid in the partitions the user has at least read privileges for.

The default grants of the above mentioned roles are as follows:

The Administrator role privileges.

RoleSystem Privilege
scheduler-administratorApplication.Create
scheduler-administratorApplication.Delete
scheduler-administratorApplication.Modify
scheduler-administratorApplication.View
scheduler-administratorEventDefinition.Clear
scheduler-administratorEventDefinition.Create
scheduler-administratorEventDefinition.Delete
scheduler-administratorEventDefinition.Modify
scheduler-administratorEventDefinition.Raise
scheduler-administratorEventDefinition.View
scheduler-administratorFormat.Create
scheduler-administratorFormat.Delete
scheduler-administratorFormat.Modify
scheduler-administratorFormat.View
scheduler-administratorJob.Delete
scheduler-administratorJob.Modify
scheduler-administratorJob.View
scheduler-administratorJobDefinition.Create
scheduler-administratorJobDefinition.Delete
scheduler-administratorJobDefinition.DeleteJob
scheduler-administratorJobDefinition.Modify
scheduler-administratorJobDefinition.SubmitJob
scheduler-administratorJobDefinition.View
scheduler-administratorJobDefinitionType.Create
scheduler-administratorJobDefinitionType.Delete
scheduler-administratorJobDefinitionType.Modify
scheduler-administratorJobDefinitionType.View
scheduler-administratorJobFile.View
scheduler-administratorJobLock.Create
scheduler-administratorJobLock.Delete
scheduler-administratorJobLock.Modify
scheduler-administratorJobLock.View
scheduler-administratorProcessServer.Create
scheduler-administratorProcessServer.Delete
scheduler-administratorProcessServer.Modify
scheduler-administratorProcessServer.View
scheduler-administratorQueue.Create
scheduler-administratorQueue.Delete
scheduler-administratorQueue.DeleteJobIn
scheduler-administratorQueue.Modify
scheduler-administratorQueue.SubmitJobIn
scheduler-administratorQueue.View
scheduler-administratorRegistryEntry.Create
scheduler-administratorResource.Create
scheduler-administratorResource.Delete
scheduler-administratorResource.Modify
scheduler-administratorResource.View
scheduler-administratorSAPSystem.Create
scheduler-administratorSAPSystem.Delete
scheduler-administratorSAPSystem.Modify
scheduler-administratorSAPSystem.View
scheduler-administratorService.Create
scheduler-administratorService.Delete
scheduler-administratorService.Modify
scheduler-administratorService.View
scheduler-administratorSubject.View
scheduler-administratorSubmitFrame.Create
scheduler-administratorSubmitFrame.Delete
scheduler-administratorSubmitFrame.Modify
scheduler-administratorSubmitFrame.View
scheduler-administratorTimeWindow.Create
scheduler-administratorTimeWindow.Delete
scheduler-administratorTimeWindow.Modify
scheduler-administratorTimeWindow.View

Isolation Administrator Role Privileges

RoleSystem Privilege
scheduler-isolation-administratorSubject.CanGrant
scheduler-isolation-administratorSubject.Create
scheduler-isolation-administratorSubject.Delete
scheduler-isolation-administratorSubject.Modify
scheduler-isolation-administratorSubject.View

Secondary role privileges

RoleSystem Privilege
scheduler-job-administratorEventDefinition.Create
scheduler-job-administratorEventDefinition.Delete
scheduler-job-administratorEventDefinition.Modify
scheduler-job-administratorJob.Modify
scheduler-job-administratorJobDefinition.Create
scheduler-job-administratorJobDefinition.Delete
scheduler-job-administratorJobDefinition.DeleteJob
scheduler-job-administratorJobDefinition.Modify
scheduler-job-administratorJobDefinition.SubmitJob
scheduler-job-administratorQueue.DeleteJobIn
scheduler-job-administratorQueue.SubmitJobIn
scheduler-event-operatorEventDefinition.Clear
scheduler-event-operatorEventDefinition.Raise

The generic role privileges

RoleSystem Privilege
scheduler-viewerApplication.View
scheduler-viewerEventDefinition.View
scheduler-viewerFormat.View
scheduler-viewerJob.View
scheduler-viewerJobDefinition.View
scheduler-viewerJobDefinitionType.View
scheduler-viewerJobFile.View
scheduler-viewerJobLock.View
scheduler-viewerProcessServer.View
scheduler-viewerQueue.View
scheduler-viewerResource.View
scheduler-viewerSAPSystem.View
scheduler-viewerService.View
scheduler-viewerSubject.View
scheduler-viewerSubmitFrame.View
scheduler-viewerTimeWindow.View
← PrivilegesObject Security →
Docs
Getting StartedInstallationFinance InstallationConcepts
TroubleshootingArchiving
Learn and Connect
Support Portal
BlogEventsResources
ISO/ IEC 27001 Information Security Management
Automate to be human

2023 All Rights Reserved |

Terms of Service | Policies | Cookies | Glossary | Third-party Software | Contact | Copyright | Impressum |