Dashboards access control

As you monitor the performance of your organization, ensuring the security and integrity of the dashboards and views is paramount. Using the security features in WebSphere® Portal, the dashboard administrator can control users' access to and interaction with dashboards and views.

In WebSphere Portal terminology, pages and portlets, along with other items, are generically referred to as resources. Resource types are broad categories that contain resource instances. Resource instances are specific resources, such as a single dashboard or view. For example, a resource instance Sales Analysis dashboard would belong to the Page resource type.

Users interaction with dashboards and views is determined by the permissions for the WebSphere Portal roles. Roles provide different permissions regarding the interaction of users with the dashboards and views. By default, roles on a resource propagate to all of its child resources. For example, if a user has the Editor role on the Monitor Dashboard Page, by default that user also has the Editor role on all pages that are children of the Monitor Dashboard Page.

You can assign roles on virtual resources and on instances of a resource. Assigning roles to resources saves time when you are administering access control because resource instances inherit parent resource roles. Using resource instances, you can specify individual resource instances a user can access. Although this procedure can be time consuming, it provides more flexibility when assigning roles.

Roles can be assigned to users and user groups. The roles listed here exist for all resources and resource instances. The following table summarizes these roles and describes how they affect user interaction with resources, as described in the WebSphere Portal documentation in the WebSphere Portal Information Center.

WebSphere Portal roles and their permissions
Role Permissions
Administrator Unrestricted access on resources including creating, configuring, and deleting resources. Administrators can also change the access-control configuration.
Security Administrator Create and delete role assignments for roles tied to specific resources.
Delegator No actual access to resource, but can create and delete role assignments. Delegator roles can assign specific users or user groups to roles.
Manager Create new resources as well as configure and delete existing resources that are used by multiple users.
Editor Create new resources and configure existing resources that are used by multiple users.
Privileged user View portal content, personalize portlets and pages, and create new private pages.
User View portal content. For example, view a specific page or user profile.
No role assigned Cannot interact with resource.

For more information on resources and roles, refer to the appropriate section in the WebSphere Portal information center, which can be found at the WebSphere Portal Web site.


Copyright IBM Corporation 2005, 2006. All Rights Reserved.