Configuring User Rules
You can manage the user root for your models in the central user list. You can make individual settings for users here.
Central User List
Maintain Innovator's central user list in the User Management tab.
Normally, you transfer and update the users and their data from an external user configuration, e.g. via the Lightweight Directory Access Protocol (LDAP) from a network or subscription server, preferably using groups. Users imported from LDAP can be identified by an icon in the LDAP column
.
When using single sign-on, only the users from the User Name in Model which are also permitted in System Login and Domain.
Note
The user does not necessarily have to exist in the model. If needed, they are created upon login in the model.
Users can be assigned the Manage Users and Manage Environment rights. To do this, select a user in the Users table and select
Users>Edit>Properties (Enter).
You can create rules for a user. To do so, select a user and select the corresponding rules using Users>New >....
Login Rule
Model Admin Rule
Model Server Rule
Version Rule
Note
Please bear the information about rule evaluation in mind when creating rules and defining their order. Rules that were created directly for a user are used with priority. Group rules with the same applicability then have no effect.
General Procedures in Tables
Prerequisites
Commands in a table take effect exclusively with a selection of one or more entries in this table.
Context
| Purpose, Initial Selection and Shortcut Keys | Go to Target |
|---|---|
|
Purpose: Go to the selected rule in the Groups or Users tab Selection: group or user rule Command: Go to User/Group (Ctrl+M) |
Rule in the relevant rule table in the Groups or Users tab The corresponding group or user is selected in the Groups or Users table. |
|
Purpose: go to the rule in the Groups or Users tab that excludes the rule that cannot be reached Selection: rule that cannot be reached of a group or user Command: Go to excluding rule (Shift+Ctrl+M) |
Rule that excludes the rule that cannot be reached in the corresponding rule table in the Groups or Users tab The corresponding group or user is selected in the Groups or Users tab. |
|
Purpose: go to the group or user in the Members table of the higher-level group Selection: higher-level group of a group or user in the Assigned to Groups table Command: Go to User/Group (Ctrl+M) |
Group or user in the Members table in the Groups tab The corresponding higher-level group is selected in the Groups table. |
|
Selection: higher-level group of a group or user in the Assigned to Groups table Selection: user or group in the Members table Command: Go to User/Group (Ctrl+M) |
Higher-level group of the group or user in the Assigned to Groups table in the Groups or Users tab The corresponding group is selected in the Groups table or the corresponding user is selected in the User table. |
Context
You can change the size of tables in the dialog by moving the separators.
The table separators can be controlled using the mouse and, if the table separator is in focus, using the keyboard arrow keys.
How to proceed
-
To change the size of a table within the dialog with the mouse, click on the table separator and move it.
The mouse pointer is displayed as a horizontal or vertical double arrow in accordance with the possible movement directions.
-
To change the size of a table within the dialog with the keyboard, use the Tab key to set the focus on the table separator and then move this using the arrow keys.
The column separator is indicated by the dotted focus frame.
Prerequisites
Sorting by column contents is only possible in tables without a relevant order, i.e. not in rule tables.
Context
Sorting enables the display and grouping of entries in accordance with the column contents in order to find certain entries more quickly.
You can sort sortable tables by one or more columns.
How to proceed
-
To sort a table by a column, click on its column header. To reverse the sort order, click again.
Entries are alphabetically sorted according to column content. An existing multiple selection is retained.
-
To sort a table by multiple columns, click on the column header of the column with the primary sorting, keep the [Shift] key pressed, and then click the column headers of the columns to be used for secondary sorting.
Secondary sorting is applied to the entries in accordance with the column contents.
Context
Filtering restricts the displayed entries so that certain entries can be found more quickly.
Case sensitivity is not relevant for filtering.
In front of the filter field, you are told how many entries of the total number of entries are still displayed when the filter is applied.
How to proceed
-
To restrict the displayed entries, enter characters that occur in the entries you are looking for into the <Filter> field.
The entries are restricted accordingly and the number of remaining entries is displayed in front of the filter field.
-
To remove the filter, click on
Reset.All entries are displayed again.
Supported Procedures in the Users Table
Prerequisites
You can only change the system login, domain and user name in the model for a manually created user.
Context
In addition to being transferred from an external user configuration, users can also be included in the user list manually.
Tip
You use manually created users to e.g. provide users with rules for Linux servers.
How to proceed
-
To create a user, select
Users>New>User (Ctrl+Shift+U). -
To change a user, select the user and then select
Users>Edit>Properties (Enter).A dialog appears.
-
Enter the name of the user in the system in the System Login field.
-
Enter the user's Windows domain in the system in the Domain field.
-
Enter the e-mail address of the user to be primarily used for the notification service in the E-Mail Address field.
-
Enter the display name used for the user login in the models in the User Name in Model field.
-
Enter the language the notofication service e-mails should be sent in in the Correspondence Language field.
Note
The entry in the Correspondence Language field can also be modified for multiple selection of users.
-
Activate the check box with the same name to assign the Manage Users status to the user.
Context
You can delete users from the central user list.
Attention
Note that users can come from an LDAP server and might reappear in the user list as a result of the synchronization.
The deletion of LDAP users has no effect on the external user management.
How to proceed
-
Select the users which you wish to delete in the table.
-
Select
Users>Edit>Delete (Del).A confirmation dialog appears.
-
Confirm the security question with OK or cancel with Cancel.
Supported Procedures in User Details
The details for the selected user are shown in the Users tab on the right-hand side.
Context
In exceptional cases, you create individual rules for logging into models for specific users. As a group member, a user normally already has rules as a result of their affiliation to a group.
Login rules for users define which roles are available for users when they log into a model as long as these roles are configured in the user management of the model.
In each case, you use a name or pattern to define which roles should be available to users for which project license servers, repositories and models. Only the asterisk (*) is available for the formulation of patterns. You use precise specifications about project license servers, repositories and models to restrict the applicability of the rule.
Attention
Please note that a newly created rule initially gives the user unrestricted access to all models, since the asterisk is the default setting for the drop-down lists.
Note
Please note that due to the rule evaluation steps, the order of rules with an overlapping applicability is decisive and that direct user rules always take priority over group rules.
How to proceed
-
Select the user you want to create or edit a rule for in the Users tab.
-
Select
Users>New>Login Rule (Ctrl+Shift+L) to create a login rule.A dialog appears.
-
To change a login rule, select the login rule and select
Users>Edit>Properties (Enter).A dialog appears.
-
To define a rule that allows access, select the Rule grants access entry in the Access drop-down list.
-
To define a rule that excludes access, select the Rule denies access entry in the Accessdrop-down list.
A sensible exclusion rule requires a corresponding, accessible enabling rule for the user in a group.
-
In the other drop-down lists, use a name or pattern to define which roles should be available to members of the group for which project license servers, repositories and models.
-
Confirm the selection with OK.
You have defined a login rule. Then arrange the rules correctly in the order of the login rules.
Context
You create certain rules for logging into models as an administrator for users. As group members, users might already have corresponding rules via their affiliation to a group.
Model administrator rules define whether users can log into a model as a model administrator. An option can define that this can take place only via plug-ins.
In each case, you use a name or pattern to define the project license servers, repositories and models which logging-in as a model administrator should be possible for. Only the asterisk (*) is available for the formulation of patterns. You use precise specifications about project license servers, repositories and models to restrict the applicability of the rule.
Attention
Please note that a newly created rule initially gives the user unrestricted access as model administrator to all models, since the asterisk is the default setting for the drop-down lists.
Note
Please note that due to the rule evaluation steps, the order of rules with an overlapping applicability is decisive and that direct user rules always take priority over group rules.
How to proceed
-
Select the user you want to create or edit a rule for in the Users tab.
-
To create a model administrator rule, select
Users>New>Model Admin Rule (Ctrl+Shift+A).A dialog appears.
-
To change a model administrator rule, select the login rule and select
Users>Edit>Properties (Enter).A dialog appears.
-
To define a rule that allows access, select the Rule grants access entry in the Access drop-down list.
-
To define a rule that excludes access, select the Rule denies access entry in the Accessdrop-down list.
A sensible exclusion rule requires a corresponding, accessible enabling rule for the user in a group.
-
In the drop-down lists, use a name or pattern to define the project license servers, repositories and models which logging-in as a model administrator should be allowed or excluded for.
-
Confirm the selection with OK.
You have defined a model administrator rule. Then arrange the rules correctly in the order of the model administrator rules.
Context
You create certain rules for executing administrative tasks for the model server. As group members, users might already have corresponding rules via their affiliation to a group.
Model server rules are used to determine whether or not a user can carry out administrative tasks and in which single sign-on data repositories.
Model server rules control authorizations for the following actions:
- Log-in as repository administrator (no password required)
- Start and close a model server (also using the command line)
- Login, rename, copy, export or delete models
- Manage logins to repository models
In each case, you use a name or pattern to define the project license servers and repositories which administrative tasks are allowed or excluded for. Only the asterisk (*) is available for the formulation of patterns. You use precise specifications about project license servers and repositories to restrict the applicability of the rule.
Attention
Please note that a newly created rule initially gives the user unrestricted access to all repositories, since the asterisk is the default setting for the drop-down lists.
Note
Please note that due to the rule evaluation steps, the order of rules with an overlapping applicability is decisive and that direct user rules always take priority over group rules.
How to proceed
-
Select the user you want to create or edit a rule for in the Users tab.
-
To create a model server rule, select
Users>New>Model Server Rule (Ctrl+Shift+S).A dialog appears.
-
To change a model server rule, select the model server rule and select
Users>Edit>Properties (Enter).A dialog appears.
-
To define a rule that allows access, select the Rule grants access entry in the Access drop-down list.
-
To define a rule that excludes access, select the Rule denies access entry in the Accessdrop-down list.
A sensible exclusion rule requires a corresponding, accessible enabling rule for the user in a group.
-
In the other drop-down lists, use a name or pattern to define the project license servers and repositories which administrative tasks are allowed or excluded for.
-
Confirm the selection with OK.
You have defined a model server rule. Then arrange the rules correctly in the order of the model server rules.
Context
You create certain rules for executing administrative tasks for the managed models. As group members, users might already have corresponding rules via their affiliation to a group.
Version rules are used to determine whether and in which managed models a user can carry out administrative tasks.
Version rules control authorizations for the following actions:
- Login as administrator for managed models (no password required)
- Create managed models
- Create, manage and back-up model versions
- Manage logins to model versions
In each case, you use a name or pattern to define the project license servers and models which administrative tasks are allowed or excluded for. Only the asterisk (*) is available for the formulation of patterns. You use precise specifications about project license servers and models to restrict the applicability of the rule.
Attention
Please note that a newly created rule initially gives the user unrestricted access to all managed models, since the asterisk is the default setting for the drop-down lists.
Note
Please note that due to the rule evaluation steps, the order of rules with an overlapping applicability is decisive and that direct user rules always take priority over group rules.
How to proceed
-
Select the user you want to create or edit a rule for in the Users tab.
-
To create a model server rule, select
Users>New>Model Server Rule (Ctrl+Shift+S).A dialog appears.
-
To change a model server rule, select the model server rule and select
Users>Edit>Properties (Enter).A dialog appears.
-
To define a rule that allows access, select the Rule grants access entry in the Access drop-down list.
-
To define a rule that excludes access, select the Rule denies access entry in the Accessdrop-down list.
A sensible exclusion rule requires a corresponding, accessible enabling rule for the user in a group.
-
In the other drop-down lists, use a name or pattern to define the project license servers and repositories which administrative tasks are allowed or excluded for.
-
Confirm the selection with OK.
You have defined a model server rule. Then arrange the rules correctly in the order of the model server rules.
Context
The order of the rules is relevant for the evaluation and effectiveness of the rules.
How to proceed
-
Select the rule whose order you want to change in the rule table.
-
Move the rule using the shortcut [Ctrl]+[Crsr Up] or [Ctrl]+[Crsr Down] or with the
Crsr Up or
Crsr Down buttons.The order is effective in that the first hit is always used for a user.
Rules that cannot currently be reached through the order and are thus ineffective are indicated in the reachable columns with the warning triangle
.
Context
Rules can be deleted. The deletion must be confirmed.
How to proceed
-
Select the rule that you want to delete in the rule table.
-
Select
Users>Edit>Delete (Del). -
Confirm the security question with OK or cancel with Cancel.
Prerequisites
A user can be assigned only to the groups that do not originate from an external user management.
You cannot remove an assignment to an LDAP group.
Context
You can assign users to manually created groups. For a selected user, the Assigned to Groups table displays the groups which the user is assigned to.
As a result of the assignment, the rules of the group are evaluated for the user, too, unless direct user rules are found for the relevant applicability.
How to proceed
-
In the Users table, select the user which you want to change assignment for.
-
Select
Users>Edit>Assign Groups (Ctrl+G).The assignment dialog appears, listing all manually created groups and assigned LDAP groups.
-
Activate the check boxes of the groups to which you want to assign the selected user.
-
Confirm the assignment with OK.
You have assigned the selected user to one or more groups, thus transferring the applicable rules for the user in question.
