Remove Group
Use this command to remove symbol access, authorizations, and users from a user group.
This command must be used in conjunction with Maintenance. While it is enabled, no other users can perform maintenance related activities in the Data Server repository. When you are finished, you must remember to disable the Maintenance mode, and thereby allow normal access by other users.
For more information, see Maintenance or Exclusive.
Note: For systems on the ISW Platform, when a user belongs to a group with authorizations configured, the user's individual authorizations are ignored and only the group authorizations apply. If the group has no authorizations configured, the user's individual authorizations are used instead. Any group authorizations that exceed what the user's license permits are also ignored.
Syntax:
REMOVE GROUP GroupName ACCESS Dimension RoleName [SymbolName [AccessType]]
REMOVE GROUP GroupName ACCESS
REMOVE GROUP GroupName AUTHORIZATION AuthorizationName [AuthorizationGroup]
REMOVE GROUP GroupName AUTHORIZATION
REMOVE GROUP GroupName USER [[DomainName\]UserId]
REMOVE GROUP GroupName USER
where:
- GroupName is the name of the group from which you want to remove access, authorizations, or users.
- Dimension is the dimension containing the symbol you want to remove access to.
- RoleName is name of a symbol access role.
- SymbolName is a symbol from which the specified group needs access removed.
- AccessType is a setting that determines whether the user has read/write access. Select one of the following:
Value Description W
Write access, to allow the user to change data.
R
Read-only access, to allow the user to read the data but not change it. This is the default.
- AuthorizationName is a name that designates the type of authorization removed from the group.
Value
Description
Platform License ADDINFOROFFICE
Access the Longview Add-In for Office.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Longview Add-In for Office.
Designer
Power User
Viewer
ADDINFOROFFICE
SUBMITDATASubmit data in the Longview Add-In for Office.
Designer
Power User
ANALYSISREPORTING
AUTHORAccess Longview Analysis and Reporting as a Report Author.
Power user ANALYSISREPORTING
PUBLISHERAccess Longview Analysis and Reporting as a Report Publisher.
Designer ANALYSISREPORTING
USERAccess Longview Analysis and Reporting as a Report User.
Viewer APPLICATION
ADMINISTRATORAccess Longview Application Administrator.
Admin
Designer
Service
ATTRIBUTE
Manage attributes.
Designer BATCH
Manage batches.
Admin
Designer
CONNECTVIA
APPLICATION
FRAMEWORKConnect to the server using Longview Application Framework.
Note: You must assign this authorization to allow users or user groups to access Longview Apps, Longview Designer, Longview tools and editors, the Longview Add-In for Office, and Longview Tax.
Admin
Designer
Power User
Viewer
Service
DASHBOARDDESIGNER
Access Longview Dashboard Designer.
Designer DELETECOMMENTS
Delete any existing comments in the Data Server. Users without Delete Comments authorization can delete only their own comments before they are submitted to the database.
Note: Delete existing comments functionality is available in Data Grids only.
Designer DESIGNER
Access Longview Designer.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSCREATECreate data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSDELETEDelete data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSMODIFYEdit data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERDATA
IMPORTSPUBLISHPublish data import apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer DESIGNERLONGVIEW
APPSPUBLISHPublish Longview Apps in Longview Designer.
Note: You must also assign the DESIGNER authorization to allow users or user groups to access Longview Designer.
Designer FOREIGNEXCHANGE
SETTINGSManage foreign exchange settings.
Admin
Designer
GROUPADMINISTRATION
Perform group administration.
Does not apply GROUPSYMBOLACCESS
Manage symbol access for groups.
Does not apply INTERCOMPANYSETTINGS
Manage intercompany settings.
Designer JOURNALENTRIES
Access Longview Journal Entries.
Designer
Power User
JOURNALENTRY
Manage journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODCREATECreate current period journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODPERMPOSTPermanently post current period journal entries.
Designer
Power User
Service
JOURNALENTRYCURRENT
PERIODREVIEWPOSTReview post current period journal entries.
Designer
Power User
Service
JOURNALENTRYDELETE
Delete non-shared journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODCREATECreate future period journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODPERMPOSTPermanently post future period journal entries.
Designer
Power User
Service
JOURNALENTRYFUTURE
PERIODREVIEWPOSTReview post future period journal entries.
Designer
Power User
Service
JOURNALENTRYOWN
PERMPOSTPermanently post own journal entries.
Designer
Power User
Service
JOURNALENTRYOWN
REVIEWPOSTReview post own journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJCREATECreate prior period journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJPERMPOSTPermanently post prior period journal entries.
Designer
Power User
Service
JOURNALENTRYPRIOR
PERIODADJREVIEWPOSTReview post prior period journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTCREATECreate restatement journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTPERMPOSTPermanently post restatement journal entries.
Designer
Power User
Service
JOURNALENTRYRE
STATEMENTREVIEWPOSTReview post restatement journal entries.
Designer
Power User
Service
LOCK
Manage locks.
Designer
Service
MAPPINGSEDITOR
Access the Mappings editor.
Note: You must also assign the CONNECTVIAAPPLICATIONFRAMEWORK authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MAPPINGSMANAGE
Create, modify, delete mappings.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MAPSMANAGE
Create, modify, delete maps.
Note: You must also assign the MAPPINGSEDITOR authorization to allow users or user groups to access the Mappings editor.
Designer
Power User
Service
MODIFYDATA
Submit data.
Designer
Power User
Service
NDDSETTINGS
Manage NDD settings.
Designer
ROLE
Manage symbol access roles.
Designer
Service
RULE
Manage rules.
Designer
Service
SCHEDULE
Manage schedules.
Designer
Service
SERVERMANAGER
Access Longview Server Manager.
Admin
Service
Designer
SERVERMANAGERSTART
Start/stop the Longview server.
Admin
Service
Designer
SERVICEACCOUNTUSER
ADMINISTRATORSets the user to be a User Administrator.
Service SERVICEACCOUNTRESTAPI
Sets user to be a Service Account User.
Note: Can only be set using PUSER or a user who has User Administrator Authorization.
Admin
Designer
Service
SYMBOL
Manage symbols.
Designer
Service
SYMBOLASSIGN
Assign symbols to a hierarchy. Must be used with SYMBOL.
Designer
Service
SYMBOLATTRIBUTECREATE
Create symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLATTRIBUTEDELETE
Delete symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLATTRIBUTEMODIFY
Modify symbol attributes. Must be used with ATTRIBUTE.
Designer
Service
SYMBOLCANCREATEROOT
Create root symbols. Must be used with SYMBOL, CREATESYMBOL.
Designer
Service
SYMBOLCANDELETEROOT
Delete root symbols. Must be used with SYMBOL, SYMBOLDELETE.
Designer
Service
SYMBOLCREATE
Create symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLDELETE
Delete symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLREMOVE
Remove symbols from a hierarchy. Must be used with SYMBOL.
Designer
Service
SYMBOLSET
Modify symbols. Must be used with SYMBOL.
Designer
Service
SYMBOLSWITCH
Switch symbols in a hierarchy. Must be used with SYMBOL.
Designer
Service
SYSTEMATTRIBUTECREATE
Create system attributes. Must be used with ATTRIBUTE.
Designer
Service
SYSTEMATTRIBUTEDELETE
Delete system attributes. Must be used with ATTRIBUTE.
Designer
Service
SYSTEMATTRIBUTEMODIFY
Modify system attributes. Must be used with ATTRIBUTE.
Designer
Service
USERADMINISTRATION
Perform user administration
Does not apply USERATTRIBUTECREATE
Create user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERATTRIBUTEDELETE
Delete user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERATTRIBUTEMODIFY
Modify user attributes. Must be used with ATTRIBUTE.
Designer
Service
USERRESETPASSWORD
Reset passwords.
Does not apply USERSYMBOLACCESS
Manage symbol access for users.
Does not apply VIEWDATA
View data.
Designer
Power User
Viewer
Service
WORKFLOWDESIGNER
Access Longview Workflow Designer.
Designer - AuthorizationGroup is required only when AuthorizationName is USERADMINISTRATION or USERRESTPASSWORD, and is the group from which you want the indicated group’s authorization removed.
For ACCESS, if the optional AccessType parameter is not included in the syntax, the command removes all access to the specified symbol from the indicated group. If the optional SymName and AccessType parameters are not included in the syntax, the command removes all symbol access for the dimension and role combination from the indicated group. If the syntax contains only “REMOVE GROUP GroupName ACCESS”, the command removes all access from the indicated group.
For AUTHORIZATION, if the syntax contains only “REMOVE GROUP GroupName AUTHORIZATION”, the command removes all authorizations from the indicated group.
For USER, if the optional DomainName\UserId is not included in the syntax, the command removes all users from the indicated group.
Syntax example:
MAINTENANCE ON
REMOVE GROUP NorthAm ACCESS ACCOUNTS AnalystRole Cash W
MAINTENANCE OFF
Creating an ASCII input file
To remove the access privileges of a large number of groups, specify the parameters for this command in an ASCII file.
Create an ASCII file containing the following information for each group:
GroupName{ACCESS{Dimension{RoleName[{SymbolName][{AccessType]
GroupName{ACCESS{Dimension{RoleName
GroupName{AUTHORIZATION{AuthorizationName[{AuthorizationGroup]
GroupName{AUTHORIZATION{AuthorizationName
GroupName{USER{[DomainName\]UserId
GroupName{USER
Use the QUICKFORMAT command, if necessary, to make formatting changes to the ASCII file.
Syntax (with an ASCII file):
REMOVE GROUP @FileName
where:
- FileName is an ASCII file containing the data. It can include a complete or partial folder path in the format C:\...\FileName. If FileName includes spaces, enclose it in double quotation marks; for example:
@"C:\My Documents\My Data.txt"
If the document is in the same location as lv_af.exe, you do not need to specify the drive or path.
Syntax example:
MAINTENANCE ON
REMOVE GROUP @Access.txt
MAINTENANCE OFF
See also