Previous Topic: Examine Policies for Auditors

Next Topic: Examine Policies for Administrators

Examine Policies for Analysts

You can examine the predefined policies for Analysts to see how they limit application access to resources required to perform the following tasks:

To examine predefined policies for Analysts

  1. Click the Administration tab and the User and Access Management subtab.
  2. Click Access Policies in the left pane.
  3. Search for policies for Analysts as follows:
    1. Clear the checkmark for Show policies matching name.
    2. Select Show policies matching identity.
    3. Enter ug:Analyst in the Add identity field.
    4. Click Add.
    5. Click Go.
  4. All policies for ug:Analyst appear, including [All Identities] that includes this user group.
  5. Examine the Analyst Create-Schedule-Annotate policy.

    This CALM access policy defines the actions that can be performed against application-specific resources. The policy grants users assigned the CA Enterprise Log Manager application user group, Analyst, the ability to create, schedule, and annotate reports, create and schedule action alerts, and create tags. (Auditors can only schedule and annotate reports.)

    Analysts can create reports, alerts, and tags, schedule reports and alerts, and annotate reports.

  6. Examine the Analyst Auditor Report Server Access Policy.

    This scoping policy grants Analysts schedule rights for any Report Server. The resource listed in the policy is AppObject.

    AnalystAuditorReportServerAccessPolicy provides access to Analyst, Auditor, Administrator, and CALM_API_UT

    AppObject is limited to specific resources with filters.

    The filter for the applicaiton object grants access to all report servers and event log stores.

  7. Examine the Analyst Report View-Edit policy.

    This scoping policy grants users assigned the Analyst role the ability to view, edit, or delete any report. The resource specified in the policy is AppObject.

    SIM--AnalysReportViewEditPolicy--SCR

    AppObject is limited to reports by the following filter, which grants the right to view generated reports saved in the EEM Folder /CALM_Configuration/Content/Reports.

    SIM--AnalysReportViewEditPolicy_Filter--SCR

    Note: The ability to edit reports granted by this policy is extended by the CEG policy, which grants the right to add filters to reports using CEG columns.