Assign User
Use this command to assign symbol access, authorizations, and group membership to a user.
You can assign access to a total of 767 separate Longview symbols to a user. For example, suppose User1 belongs to Group1. Group1 has access settings to 225 symbols. User1 has access to an additional and separate 542 symbols not listed in the group he belongs to. In total, User1 has access to 767 symbols. Symbol access roles can also been assigned to users and user groups.
This command must be used in conjunction with Maintenance. While it is enabled, no other users can perform maintenance related activities in the Data Server repository. When you are finished, you must remember to disable the Maintenance mode, and thereby allow normal access by other users. For more information, see Maintenance or Exclusive.
Syntax (regular)
ASSIGN USER [DomainName\]UserId ACCESS Dimension RoleName Inherit SymbolName AccessType NumLevels [Priority]
ASSIGN USER [DomainName\]UserId AUTHORIZATION AuthorizationName [AuthorizationGroup]
ASSIGN USER [DomainName\]UserId GROUP GroupName
where:
- DomainName is optional and is the network domain of a Windows-authenticated user.
- UserId is the name of the user to which you want to assign access, authorizations, or groups.
- Dimension is a dimension containing the symbols.
- RoleName is the name of a symbol access role.
- Inherit designates that the privileges are inherited from the role for the dimension specified. Valid values are TRUE (inheriting access from role) and FALSE (setting specific access). If Inherit is TRUE, do not include SymbolName, AccessType, NumLevels, and Priority.
- SymbolName is the top symbol in the hierarchy to which you want to give the user access. It must be a subset of the role. If Inherit is TRUE, do not include this parameter.
-
AccessType is a setting that determines whether the user has read/write access. If Inherit is TRUE, do not include this parameter. Select one of the following:
Value Description W
Write access, to allow the user to change data.
R
Read-only access, to allow the user to read the data but not change it. This is the default.
- NumLevels is a number representing the number of hierarchy levels below SymName. If Inherit is TRUE, do not include this parameter.
- Priority is optional and is a number that designates a symbol’s position in the hierarchy relative to its parent. Symbols are listed in order of ascending priority, with zeros falling at the bottom of the list. If Inherit is TRUE, do not include this parameter.
-
AuthorizationName is a name that designates the type of authorization being granted to the user.
Value
Description
ADDINFOROFFICE
Access the Longview Add-In for Office.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Longview Add-In for Office.
ADDINFOROFFICE
SUBMITDATASubmit data in the Longview Add-In for Office.
ANALYSISREPORTING
AUTHORAccess Longview Analysis and Reporting as a Report Author.
ANALYSISREPORTING
PUBLISHERAccess Longview Analysis and Reporting as a Report Publisher.
ANALYSISREPORTING
sUSERAccess Longview Analysis and Reporting as a Report User.
APPLICATION
ADMINISTRATORAccess Longview Application Administrator.
ATTRIBUTE
Manage attributes.
BATCH
Manage batches.
CONNECTVIA
APPLICATION
FRAMEWORKConnect to the server using Longview Application Framework.
Note: You must assign this authorization to allow users or user groups to access Longview Apps, Longview Designer, Longview tools and editors, the Longview Add-In for Office, and Longview Tax.
DASHBOARDDESIGNER
Access Longview Dashboard Designer.
DELETECOMMENTS
Delete any existing comments in the Data Server. Users without Delete Comments authorization can delete only their own comments before they are submitted to the database.
Note: Delete existing comments functionality is available in Data Grids only.
DESIGNER
Access Longview Designer.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSCREATECreate data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSDELETEDelete data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSMODIFYEdit data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERDATA
IMPORTSPUBLISHPublish data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
DESIGNERLONGVIEW
APPSPUBLISHPublish Longview Apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
FOREIGNEXCHANGE
SETTINGSManage foreign exchange settings.
GROUPADMINISTRATION
Perform group administration.
GROUPSYMBOLACCESS
Manage symbol access for groups.
INTERCOMPANYSETTINGS
Manage intercompany settings.
JOURNALENTRIES
Access Longview Journal Entries.
JOURNALENTRY
Manage journal entries.
JOURNALENTRYCURRENT
PERIODCREATECreate current period journal entries.
JOURNALENTRYCURRENT
PERIODPERMPOSTPermanently post current period journal entries.
JOURNALENTRYCURRENT
PERIODREVIEWPOSTReview post current period journal entries.
JOURNALENTRYDELETE
Delete non-shared journal entries.
JOURNALENTRYFUTURE
PERIODCREATECreate future period journal entries.
JOURNALENTRYFUTURE
PERIODPERMPOSTPermanently post future period journal entries.
JOURNALENTRYFUTURE
PERIODREVIEWPOSTReview post future period journal entries.
JOURNALENTRYOWN
PERMPOSTPermanently post own journal entries.
JOURNALENTRYOWN
REVIEWPOSTReview post own journal entries.
JOURNALENTRYPRIOR
PERIODADJCREATECreate prior period journal entries.
JOURNALENTRYPRIOR
PERIODADJPERMPOSTPermanently post prior period journal entries.
JOURNALENTRYPRIOR
PERIODADJREVIEWPOSTReview post prior period journal entries.
JOURNALENTRYRE
STATEMENTCREATECreate restatement journal entries.
JOURNALENTRYRE
STATEMENTPERMPOSTPermanently post restatement journal entries.
JOURNALENTRYRE
STATEMENTREVIEWPOSTReview post restatement journal entries.
LOCK
Manage locks.
MAPPINGSEDITOR
Access the Mappings editor.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Mappings editor.
MAPPINGSMANAGE
Create, modify, delete mappings.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
MAPSMANAGE
Create, modify, delete maps.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
MODIFYDATA
Submit data.
NDDSETTINGS
Manage NDD settings.
ROLE
Manage symbol access roles.
RULE
Manage rules.
SCHEDULE
Manage schedules.
SERVERMANAGER
Access Longview Server Manager.
SERVERMANAGERSTART
Start/stop the Longview server.
SERVICEACCOUNTUSER
ADMINISTRATORSets the user to be a User Administrator.
SERVICEACCOUNTRESTAPI
Sets user to be a Service Account User.
Note: Can only be set using PUSER or a user who has User Administrator Authorization.
SYMBOL
Manage symbols.
SYMBOLASSIGN
Assign symbols to a hierarchy. Must be used with SYMBOL.
SYMBOLATTRIBUTECREATE
Create symbol attributes. Must be used with ATTRIBUTE.
SYMBOLATTRIBUTEDELETE
Delete symbol attributes. Must be used with ATTRIBUTE.
SYMBOLATTRIBUTEMODIFY
Modify symbol attributes. Must be used with ATTRIBUTE.
SYMBOLCANCREATEROOT
Create root symbols. Must be used with SYMBOL, CREATESYMBOL.
SYMBOLCANDELETEROOT
Delete root symbols. Must be used with SYMBOL, SYMBOLDELETE.
SYMBOLCREATE
Create symbols. Must be used with SYMBOL.
SYMBOLDELETE
Delete symbols. Must be used with SYMBOL.
SYMBOLREMOVE
Remove symbols from a hierarchy. Must be used with SYMBOL.
SYMBOLSET
Modify symbols. Must be used with SYMBOL.
SYMBOLSWITCH
Switch symbols in a hierarchy. Must be used with SYMBOL.
SYSTEMATTRIBUTECREATE
Create system attributes. Must be used with ATTRIBUTE.
SYSTEMATTRIBUTEDELETE
Delete system attributes. Must be used with ATTRIBUTE.
SYSTEMATTRIBUTEMODIFY
Modify system attributes. Must be used with ATTRIBUTE.
USERADMINISTRATION
Perform user administration
USERATTRIBUTECREATE
Create user attributes. Must be used with ATTRIBUTE.
USERATTRIBUTEDELETE
Delete user attributes. Must be used with ATTRIBUTE.
USERATTRIBUTEMODIFY
Modify user attributes. Must be used with ATTRIBUTE.
USERRESETPASSWORD
Reset passwords.
USERSYMBOLACCESS
Manage symbol access for users.
VIEWDATA
View data.
WORKFLOWDESIGNER
Access Longview Workflow Designer.
- AuthorizationGroup is required only when AuthorizationName is USERADMINISTRATION or USERRESETPASSWORD, and is the group for which you want the indicated user to have authorization.
- GroupName is the name of a group to which the user membership is assigned membership.
Syntax example
MAINTENANCE ON
ASSIGN USER JSmith GROUP Administrators
MAINTENANCE OFF
Creating an ASCII input file
To change the access privileges of a large number of users, specify the parameters for this command in an ASCII file.
Create an ASCII file containing the following information for each user:
[DomainName\]UserId{ACCESS{Dimension{RoleName{Inherit{SymbolName{AccessType{NumLevels[{Priority]
[DomainName\]UserId{AUTHORIZATION{AuthorizationName[{AuthorizationGroup]
[DomainName\]UserId{GROUP{GroupName
Note: Include SymName, Access, NumLevels, and Priority only if Inherit is set to FALSE.
Use the QUICKFORMAT command, if necessary, to make formatting changes to the ASCII file.
Syntax (with an ASCII file)
ASSIGN USER @FileName
where:
-
FileName is an ASCII file containing the data. It can include a complete or partial folder path in the format C:\...\FileName. If FileName includes spaces, enclose it in double quotation marks; for example:
@"C:\My Documents\My Data.txt"
Note: If the document is in the same location as lv_af.exe, you do not need to specify the drive or path.
Syntax example
MAINTENANCE ON
ASSIGN USER @Access.txt
MAINTENANCE OFF
See also