Assign Group
Use this command to assign symbol access, authorizations, and users to a user group.
You can assign access to a total of 767 separate Longview symbols to a user. For example, suppose User1 belongs to Group1. Group1 has access settings to 225 symbols. User1 has access to an additional and separate 542 symbols not listed in the group he belongs to. In total, User1 has access to 767 symbols. Symbol access roles can also been assigned to users and user groups.
This command must be used in conjunction with Maintenance. While it is enabled, no other users can perform maintenance related activities in the Data Server repository. When you are finished, you must remember to disable the Maintenance mode, and thereby allow normal access by other users. For more information, see Maintenance or Exclusive.
Syntax (regular)
ASSIGN GROUP GroupName ACCESS Dimension RoleName Inherit SymbolName AccessType NumLevels [Priority]
ASSIGN GROUP GroupName AUTHORIZATION AuthorizationName [AuthorizationGroup]
ASSIGN GROUP GroupName USER [DomainName\]UserId
where:
- GroupName is the name of the group to which you want to assign access, authorizations, or users.
- Dimension is a dimension containing the symbols.
- RoleName is the name of a symbol access role.
- Inherit causes access to be inherited from the role. Valid values are TRUE (inheriting access from the role) and FALSE (setting specific access). If Inherit is TRUE, do not include SymbolName, AccessType, NumLevels, and Priority.
- SymbolName is the top symbol in the hierarchy to which you want to give the group access. It must be a subset of the role. If Inherit is TRUE, do not include this parameter.
- AccessType is a setting that determines whether the user has read/write access. If Inherit is TRUE, do not include this parameter. Select one of the following:
Value Description W
Write access, to allow the user to change data.
R
Read-only access, to allow the user to read the data but not change it. This is the default.
- NumLevels is a number representing the number of hierarchy levels below SymbolName. If Inherit is TRUE, do not include this parameter.
- Priority is optional and is a number that designates a symbol’s position in the hierarchy relative to its parent. Symbols are listed in order of ascending priority, with zeros falling at the bottom of the list. If Inherit is TRUE, do not include this parameter.
- AuthorizationName is a name that designates the type of authorization being granted to the user group and can be the following:
Value Description ADDINFOROFFICE
Access the Longview Add-In for Office.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Longview Add-In for Office.
ADDINFOROFFICESUBMIT
DATASubmit data in the Longview Add-In for Office.
ANALYSISREPORTING
AUTHORAccess Longview Analysis and Reporting as a Report Author.
ANALYSISREPORTING
PUBLISHERAccess Longview Analysis and Reporting as a Report Publisher.
ANALYSISREPORTING
USERAccess Longview Analysis and Reporting as a Report User.
APPLICATION
ADMINISTRATORAccess Longview Application Administrator.
ATTRIBUTE
Manage attributes.
BATCH
Manage batches.
CONNECTVIA
APPLICATION
FRAMEWORKConnect to the server using Longview Application Framework.
Note: You must assign this authorization to allow users or user groups to access Longview Apps, Longview Designer, Longview tools and editors, the Longview Add-In for Office, and Longview Tax.
DASHBOARDDESIGNER
Access Longview Dashboard Designer.
DELETECOMMENTS
Delete any existing comments in the Data Server. Users without Delete Comments authorization can delete only their own comments before they are submitted to the database.
Note: Delete existing comments functionality is available in Data Grids only.
DESIGNER
Access Longview Designer.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSCREATECreate data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSDELETEDelete data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSMODIFYEdit data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSPUBLISHPublish data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERLONGVIEW
APPSPUBLISHPublish Longview Apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
FOREIGNEXCHANGE
SETTINGSManage foreign exchange settings.
GROUPADMINISTRATION
Perform group administration.
GROUPSYMBOLACCESS
Manage symbol access for groups.
INTERCOMPANY
SETTINGSManage intercompany settings.
JOURNALENTRIES
Access Longview Journal Entries.
JOURNALENTRY
Manage journal entries.
JOURNALENTRYCURRENT
PERIODCREATECreate current period journal entries.
JOURNALENTRYCURRENT
PERIODPERMPOSTPermanently post current period journal entries.
JOURNALENTRYCURRENT
PERIODREVIEWPOSTReview post current period journal entries.
JOURNALENTRYDELETE
Delete non-shared journal entries.
JOURNALENTRYFUTURE
PERIODCREATECreate future period journal entries.
JOURNALENTRYFUTURE
PERIODPERMPOSTPermanently post future period journal entries.
JOURNALENTRYFUTURE
PERIODREVIEWPOSTReview post future period journal entries.
JOURNALENTRYOWN
PERMPOSTPermanently post own journal entries.
JOURNALENTRYOWN
REVIEWPOSTReview post own journal entries.
JOURNALENTRYPRIOR
PERIODADJCREATECreate prior period journal entries.
JOURNALENTRYPRIOR
PERIODADJPERMPOSTPermanently post prior period journal entries.
JOURNALENTRYPRIOR
PERIODADJREVIEWPOSTReview post prior period journal entries.
JOURNALENTRYRE
STATEMENTCREATECreate restatement journal entries.
JOURNALENTRYRE
STATEMENTPERMPOSTPermanently post restatement journal entries.
JOURNALENTRYRE
STATEMENTREVIEWPOSTReview post restatement journal entries.
LOCK
Manage locks.
MAPPINGSEDITOR
Access the Mappings editor.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Mappings editor.
MAPPINGSMANAGE
Create, modify, delete mappings.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
MAPSMANAGE
Create, modify, delete maps.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
MODIFYDATA
Submit data.
NDDSETTINGS
Manage NDD settings.
ROLE
Manage symbol access roles.
RULE
Manage rules.
SCHEDULE
Manage schedules.
SERVERMANAGER
Access Longview Server Manager.
SERVERMANAGER
STARTStart/stop the Longview server.
SYMBOL
Manage symbols.
SYMBOLASSIGN
Assign symbols to a hierarchy. Must be used with SYMBOL.
SYMBOLATTRIBUTE
CREATECreate symbol attributes. Must be used with ATTRIBUTE.
SYMBOLATTRIBUTE
DELETEDelete symbol attributes. Must be used with ATTRIBUTE.
SYMBOLATTRIBUTE
MODIFYModify symbol attributes. Must be used with ATTRIBUTE.
SYMBOLCANCREATE
ROOTCreate root symbols. Must be used with SYMBOL, CREATESYMBOL.
SYMBOLCANDELETE
ROOTDelete root symbols. Must be used with SYMBOL, SYMBOLDELETE.
SYMBOLCREATE
Create symbols. Must be used with SYMBOL.
SYMBOLDELETE
Delete symbols. Must be used with SYMBOL.
SYMBOLREMOVE
Remove symbols from a hierarchy. Must be used with SYMBOL.
SYMBOLSET
Modify symbols. Must be used with SYMBOL.
SYMBOLSWITCH
Switch symbols in a hierarchy. Must be used with SYMBOL.
SYSTEMATTRIBUTECREATE
Create system attributes. Must be used with ATTRIBUTE.
SYSTEMATTRIBUTEDELETE
Delete system attributes. Must be used with ATTRIBUTE.
SYSTEMATTRIBUTEMODIFY
Modify system attributes. Must be used with ATTRIBUTE.
USERADMINISTRATION
Perform user administration
USERATTRIBUTECREATE
Create user attributes. Must be used with ATTRIBUTE.
USERATTRIBUTEDELETE
Delete user attributes. Must be used with ATTRIBUTE.
USERATTRIBUTEMODIFY
Modify user attributes. Must be used with ATTRIBUTE.
USERRESETPASSWORD
Reset passwords.
USERSYMBOLACCESS
Manage symbol access for users.
VIEWDATA
View data.
WORKFLOWDESIGNER
Access Longview Workflow Designer.
- AuthorizationGroup is required only when AuthorizationName is USERADMINISTRATION or USERRESETPASSWORD, and is the group for which you want the indicated group to have authorization.
- DomainName is optional and is the network domain of a Windows-authenticated user.
- UserId is the ID of a user.
Syntax example
MAINTENANCE ON
ASSIGN GROUP Administrator ACCESS ACCOUNTS ANALYSIS_REPORTING_ACCESS FALSE TrialBalance W 99 2
MAINTENANCE OFF
Creating an ASCII input file
To change the access privileges of a large number of users, specify the parameters for this command in an ASCII file.
Create an ASCII file containing the following information for each user:
GroupName{ACCESS{Dimension{RoleName{Inherit{SymName{Access{NumLevels[Priority]
GroupName{AUTHORIZATION{AuthorizationName
GroupName{USER{[DomainName\]UserId
Note: Include SymName, Access, NumLevels, and Priority only if Inherit is set to FALSE.
Use the QUICKFORMAT command, if necessary, to make formatting changes to the ASCII file.
where:
- FileName is an ASCII file containing the data. It can include a complete or partial folder path in the format C:\...\FileName. If FileName includes spaces, enclose it in double quotation marks; for example:
@"C:\My Documents\My Data.txt"
Note: If the document is in the same location as lv_af.exe, you do not need to specify the drive or path.
See also