Assign Group
Use this command to assign symbol access, authorizations, and users to a user group.
You can assign access to a total of 767 separate Longview symbols to a user. For example, suppose User1 belongs to Group1. Group1 has access settings to 225 symbols. User1 has access to an additional and separate 542 symbols not listed in the group he belongs to. In total, User1 has access to 767 symbols. Symbol access roles can also been assigned to users and user groups.
This command must be used in conjunction with Maintenance. While it is enabled, no other users can perform maintenance related activities in the Data Server repository. When you are finished, you must remember to disable the Maintenance mode, and thereby allow normal access by other users. For more information, see Maintenance or Exclusive.
Note: For systems on the ISW Platform, when a user belongs to a group with authorizations configured, the user's individual authorizations are ignored and only the group authorizations apply. If the group has no authorizations configured, the user's individual authorizations are used instead. Any group authorizations that exceed what the user's license permits are also ignored.
Syntax (regular)
ASSIGN GROUP GroupName ACCESS Dimension RoleName Inherit SymbolName AccessType NumLevels [Priority]
ASSIGN GROUP GroupName AUTHORIZATION AuthorizationName [AuthorizationGroup]
ASSIGN GROUP GroupName USER [DomainName\]UserId
where:
- GroupName is the name of the group to which you want to assign access, authorizations, or users.
- Dimension is a dimension containing the symbols.
- RoleName is the name of a symbol access role.
- Inherit causes access to be inherited from the role. Valid values are TRUE (inheriting access from the role) and FALSE (setting specific access). If Inherit is TRUE, do not include SymbolName, AccessType, NumLevels, and Priority.
- SymbolName is the top symbol in the hierarchy to which you want to give the group access. It must be a subset of the role. If Inherit is TRUE, do not include this parameter.
-
AccessType is a setting that determines whether the user has read/write access. If Inherit is TRUE, do not include this parameter. Select one of the following:
Value Description W
Write access, to allow the user to change data.
R
Read-only access, to allow the user to read the data but not change it. This is the default.
- NumLevels is a number representing the number of hierarchy levels below SymbolName. If Inherit is TRUE, do not include this parameter.
- Priority is optional and is a number that designates a symbol’s position in the hierarchy relative to its parent. Symbols are listed in order of ascending priority, with zeros falling at the bottom of the list. If Inherit is TRUE, do not include this parameter.
-
AuthorizationName is a name that designates the type of authorization being granted to the user group and can be the following:
Value
Description
Platform License ADDINFOROFFICE
Access the Longview Add-In for Office.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Longview Add-In for Office.
Designer
Power User
Viewer
ADDINFOROFFICE
SUBMITDATASubmit data in the Longview Add-In for Office.
Designer
Power User
ANALYSISREPORTING
AUTHORAccess Longview Analysis and Reporting as a Report Author.
Power user ANALYSISREPORTING
PUBLISHERAccess Longview Analysis and Reporting as a Report Publisher.
Designer ANALYSISREPORTING
USERAccess Longview Analysis and Reporting as a Report User.
Viewer APPLICATION
ADMINISTRATORAccess Longview Application Administrator.
Admin
Designer
Service
ATTRIBUTE
Manage attributes.
Designer BATCH
Manage batches.
Admin
Designer
CONNECTVIA
APPLICATION
FRAMEWORKConnect to the server using Longview Application Framework.
Note: You must assign this authorization to allow users or user groups to access Longview Apps, Longview Designer, Longview tools and editors, the Longview Add-In for Office, and Longview Tax.
Admin
Designer
Power User
Viewer
Service
DASHBOARDDESIGNER
Access Longview Dashboard Designer.
Designer DELETECOMMENTS
Delete any existing comments in the Data Server. Users without Delete Comments authorization can delete only their own comments before they are submitted to the database.
Note: Delete existing comments functionality is available in Data Grids only.
Designer DESIGNER
Access Longview Designer.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSCREATECreate data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSDELETEDelete data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSMODIFYEdit data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSPUBLISHPublish data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERLONGVIEW
APPSPUBLISHPublish Longview Apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer FOREIGNEXCHANGE
SETTINGSManage foreign exchange settings.
Admin
Designer
GROUPADMINISTRATION
Perform group administration.
Does not apply GROUPSYMBOLACCESS
Manage symbol access for groups.
Does not apply INTERCOMPANYSETTINGS
Manage intercompany settings.
Designer JOURNALENTRIES
Access Longview Journal Entries.
Designer
Power User
JOURNALENTRY
Manage journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODCREATECreate current period journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODPERMPOSTPermanently post current period journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODREVIEWPOSTReview post current period journal entries.
Designer
Power User
Service
JOURNALENTRYDELETE
Delete non-shared journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODCREATECreate future period journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODPERMPOSTPermanently post future period journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODREVIEWPOSTReview post future period journal entries.
Designer
Power User
Service
JOURNALENTRYOWN
PERMPOSTPermanently post own journal entries.
Designer
Power User
Service
JOURNALENTRYOWN
REVIEWPOSTReview post own journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJCREATECreate prior period journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJPERMPOSTPermanently post prior period journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJREVIEWPOSTReview post prior period journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTCREATECreate restatement journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTPERMPOSTPermanently post restatement journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTREVIEWPOSTReview post restatement journal entries.
Designer
Power User
Service
LOCK
Manage locks.
Designer
Service
MAPPINGSEDITOR
Access the Mappings editor.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MAPPINGSMANAGE
Create, modify, delete mappings.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MAPSMANAGE
Create, modify, delete maps.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MODIFYDATA
Submit data.
Designer
Power User
Service
NDDSETTINGS
Manage NDD settings.
Designer
ROLE
Manage symbol access roles.
Designer
Service
RULE
Manage rules.
Designer
Service
SCHEDULE
Manage schedules.
Designer
Service
SERVERMANAGER
Access Longview Server Manager.
Admin
Service
Designer
SERVERMANAGERSTART
Start/stop the Longview server.
Admin
Service
Designer
SERVICEACCOUNTUSER
ADMINISTRATORSets the user to be a User Administrator.
Service SERVICEACCOUNTRESTAPI
Sets user to be a Service Account User.
Note: Can only be set using PUSER or a user who has User Administrator Authorization.
Admin
Designer
Service
SYMBOL
Manage symbols.
Designer
Service
SYMBOLASSIGN
Assign symbols to a hierarchy. Must be used with SYMBOL.
Designer
Service
SYMBOLATTRIBUTECREATE
Create symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLATTRIBUTEDELETE
Delete symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLATTRIBUTEMODIFY
Modify symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLCANCREATEROOT
Create root symbols. Must be used with SYMBOL, CREATESYMBOL.
Designer
Service
SYMBOLCANDELETEROOT
Delete root symbols. Must be used with SYMBOL, SYMBOLDELETE.
Designer
Service
SYMBOLCREATE
Create symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLDELETE
Delete symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLREMOVE
Remove symbols from a hierarchy. Must be used with SYMBOL.
Designer
Service
SYMBOLSET
Modify symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLSWITCH
Switch symbols in a hierarchy. Must be used with SYMBOL.
Designer
Service
SYSTEMATTRIBUTECREATE
Create system attributes. Must be used with ATTRIBUTE.
Designer
Service
SYSTEMATTRIBUTEDELETE
Delete system attributes. Must be used with ATTRIBUTE.
Designer
Service
SYSTEMATTRIBUTEMODIFY
Modify system attributes. Must be used with ATTRIBUTE.
Designer
Service
USERADMINISTRATION
Perform user administration
Does not apply USERATTRIBUTECREATE
Create user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERATTRIBUTEDELETE
Delete user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERATTRIBUTEMODIFY
Modify user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERRESETPASSWORD
Reset passwords.
Does not apply USERSYMBOLACCESS
Manage symbol access for users.
Does not apply VIEWDATA
View data.
Designer
Power User
Viewer
Service
WORKFLOWDESIGNER
Access Longview Workflow Designer.
Designer - AuthorizationGroup is required only when AuthorizationName is USERADMINISTRATION or USERRESETPASSWORD, and is the group for which you want the indicated group to have authorization.
- DomainName is optional and is the network domain of a Windows-authenticated user.
- UserId is the ID of a user.
Syntax example:
MAINTENANCE ON
ASSIGN GROUP Administrator ACCESS ACCOUNTS ANALYSIS_REPORTING_ACCESS FALSE TrialBalance W 99 2
MAINTENANCE OFF
Creating an ASCII input file
To change the access privileges of a large number of users, specify the parameters for this command in an ASCII file.
Create an ASCII file containing the following information for each user:
GroupName{ACCESS{Dimension{RoleName{Inherit{SymName{Access{NumLevels[Priority]
GroupName{AUTHORIZATION{AuthorizationName
GroupName{USER{[DomainName\]UserId
Note: Include SymName, Access, NumLevels, and Priority only if Inherit is set to FALSE.
Use the QUICKFORMAT command, if necessary, to make formatting changes to the ASCII file.
Syntax (with an ASCII file):
ASSIGN GROUP @FileName
where:
-
FileName is an ASCII file containing the data. It can include a complete or partial folder path in the format C:\...\FileName. If FileName includes spaces, enclose it in double quotation marks; for example:
@"C:\My Documents\My Data.txt"
Note: If the document is in the same location as lv_af.exe, you do not need to specify the drive or path.
Syntax
MAINTENANCE ON
ASSIGN GROUP @Access.txt
MAINTENANCE OFF
See also