Previous Topic: Roles and Default Access RightsNext Topic: Default Role for All Users


Tasks that Each Role Can Perform

Each user can have different roles in different business units. The roles provide default access rights to various functions. In addition, administrators can use configuration settings to add access rights to a role or remove access rights from a role.

Note: For more details about the configuration settings, see the Implementation Guide.

Request-related functions are available through Catalog Component, while subscription and invoice-related functions are available through Accounting Component.

The following table lists the tasks that each role can perform. Explanations for the roles and authorization numbers appear after the table. The letter X indicates that the role can perform the task, while the dash (-) indicates that the user cannot perform the task.

 

Roles

Tasks

Cat Usr

Req Mgr

Cat Adm

End Usr

Adm

Svc Mgr

SBU Adm

SD Adm

Shopping

 

 

 

 

 

 

 

 

By default, all users have all shopping functions, except as noted in Roles and Default Access Rights. However, administrators can configure the access rights of each role to create proxy requests, edit requests, and so forth.

All users can also delegate the use of their catalogs to create requests on their behalf.

X

X

X

X

X

-

X

X

Managing Requests

 

 

 

 

 

 

 

 

View, edit, delete and cancel requests

X

X

X

X

X

X

X

X

Act on assigned requests pending action

X

X

X

X

X

X

X

X

Search for requests

X

X

X

X

X

X

X

X

View all items in a request

X

X

X

X

X

X

X

X

View request tracking and audit trail information

-

X

X

-

X

-

X

X

General

 

 

 

 

 

 

 

 

View dashboards

X

X

X

X

X

X

X

X

Add personal dashboards

X

X

X

X

X

X

X

X

Create shared dashboards

-

-

X

-

X

-

X

X

View subscriptions and invoices

-

-

-

X

X

-

X

X

During checkout, change the Requested For user from the current setting to another account or user. That account or user requires a role in the business unit scope of the logged in user.

-

X

X

-

X

-

X

X

View and add News Messages

-

-

-

X

X

X

X

X

View Documents (if enabled) and View Reports

-

-

-

-

-

X

X

X

Managing the Catalog

 

 

 

 

 

 

 

 

View and alter catalog services and service option groups

-

-

X

-

-

X

X

X

View and alter CA Service Catalog configuration settings

-

-

X

-

-

-

X

X

Manage catalog entries or configuration

-

-

-

-

-

X

X

X

Manage subscriptions or invoices

-

-

-

-

X

-

X

X

Managing other elements

 

 

 

 

 

 

 

 

Manage accounts within your business unit scope

-

-

-

-

X

-

X

X

Manage users with roles in your business unit scope

-

-

-

-

X

-

X

X

Manage the dashboard library for the business unit

-

-

-

-

X

-

X

X

Manage scheduled tasks

-

-

-

-

X

-

X

X

Manage reports

-

-

-

-

X

X

X

X

Manage Change Events and Alerts

 

-

-

-

-

X

-

X

X

Roles Key

Code

Role

Adm

Administrator

Cat Adm

Catalog Administrator

Cat Usr

Catalog User (none)

End Usr

end user

Req Mgr

request manager

Svc Mgr

service manager

SB Adm

Super Business Unit administrator

SD Adm

Service Delivery administrator

Tasks that Each Role Can Perform for Other Users

The following table displays the roles that can perform authorized tasks for themselves and for other accounts and users.

 

Roles

Can Perform Tasks for Themselves and

Cat Usr

Req Mgr

Cat Adm

End Usr

Adm

Svc Mgr

SBU Adm

SD Adm

Other accounts and users with roles in their business unit

-

X

X

-

X

X

X

X

Other accounts and users with roles in their business unit and any of its child business units.

-

X

X

-

-

X

X

X

Other accounts and users with roles in all business units, including all child business units

-

-

-

-

-

X

-

X