Permission Sets

A permission set contains individual permissions.

Each permission identifies the object for which permission is given, the conditions that must be met, the type of access to be granted on the object, and the attribute groups the team can access.

Examples:

Manufacturers: you can give component engineers based out of New York City or Houston permission to view all manufacturers and restrict manage permission to some US manufacturers. Additionally, provide access to the attribute group named Dimension.

Items: you can create a permission set for an item that enables you to:

  • Create items in the item class named Root Item Class.
  • Discover all items in the application.
  • Delete all engineering items.
  • View Basic Attributes, Quality and Relationships on all engineering items.
  • Manage only Basic Attributes on all engineering items.

Before you configure the attribute groups for the team, you must run the Upgrade Product Management Data scheduled process to grant access to the attribute groups.

Here are some details on permission sets:

  • The permission sets that you create appear for selection on the Permission Sets tab when you create a team.
  • A permission set can be assigned to multiple teams.
  • You can control access to attribute groups when using the View and Manage permissions.
  • You can’t control access to attribute groups on items when using the Create, Discover, and Delete permissions.
  • To view a listing of the permission sets that have already been created, see the Search Permission Sets page. On the search page,
    • You can search for specific permission sets and sort the list of permission sets by the columns.
    • Click the permission set name to see details of the permission set.

Create a Permission Set for an Object

  1. Navigate to the Product Management work area.
  2. In Actions, click Teams.
  3. On the Search Teams page, select Permissions Sets from the Search Teams drop-down list.
  4. Click Create on the Search Permission Sets page and enter the details for the permission set:
    1. Name: Unique name of the permission set.
    2. Description: Short description on the permission set.
    3. Object: Select the object for which you want to create the permission. For example, Manufacturer.
    4. Condition: Select a condition from the list of available conditions or you can also click Create Condition to create a new condition.

      The condition helps narrow down the object by applying filters on object attributes.

    5. Permission: Permissions are listed according to the selected object. Select a permission based on the actions you want the team to perform on the object.

      Create: Allows user to create the object.

      View: Allows the user to see the object attributes in read-only format.

      Manage: Allows the user to view and edit an object.

      Delete: Allows the user to add the object to a delete group.

      Discover: Allows the user to view only the item number of the item on which the user has discover permission in various places like relationships, structure, affected objects and so on. The items with only discover permission can’t be searched or found in item picker.

  5. Access To: Select the attribute groups the team can access. Note that:
    • This column is disabled when you select the Create privilege, which means users can access all attribute groups when creating a manufacturer.
    • You can control access to attribute groups when using the View and Manage permissions.
    • You can’t control access to attribute groups on items when using the Create, Discover, and Delete permissions.

  6. Click Save.