cancel
Showing results for 
Search instead for 
Did you mean: 

Web Intelligence Security Best Practices

Former Member
0 Kudos

Hi All,

We are in the process of starting to use web intelligence. I am puttng together a security model for it and I have some questions around best practices. We have a fairly simple two tier security model so far, end users and creators. Creators will be able to create reports in certain folders and everyone else will be able to run and refresh those reports they can see.

  1. I was going to create a group for all the creators and assign them to a custom access level in the web intelligence application. Then they would also need to be in another creator group for the particular folder. So they would be able to the create reports in that folder and execute reports in another.
  2. For all the end users, they need to be able to view and refresh reports, drilling, data tracking, etc. if they have access to them. Is the best practice then to just assign the Everyone group the out of the box view on demand access level?

I have been digging around looking for resources and welcome anyone's input or ideas on the subject.

Thanks in advance for any assistance provided.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

First part. you don't need to create separate group for those users. Assign the same group with custom access level at application level and folder level.

But for the second part, you can put them in new group and assign the view on demand or you can create custom access level. Apply the rights to at the folder level and application level.

Former Member
0 Kudos

Thank you for your prompt reply.

But that means that the same security groups will need to be creaed on both palces, web intelligence application and at the folder level?

I was thinking if I create a developer group for the web intelligence application level, all developers would go into there. Then at the folder level I could create another folder level security group for developers to access the folder.

Would that not simplify the maintenance at the application level? Or would that not work?

Former Member
0 Kudos

Groups will be created in one place - user and groups in CMC.

Add the members to the group.

Assign the group with access level to application -WEBI and same do it for Folder level.