IBM Cognos BI package data security

You can use the wbmUpdatePackageSecurity command to apply data security to IBM® Cognos® BI packages.

Purpose

The wbmUpdatePackageSecurity command sets Cognos cube package permissions based on users and groups. The data access permissions that were published during the initial cube package generation are overwritten by the latest Monitor data security permissions for the monitor model resource group.

Examples

The following example uses Jacl to set the permissions:
  • Batch mode
    $AdminTask wbmUpdatePackageSecurity {-modelID modelID}
  • Interactive mode
    $AdminTask wbmUpdatePackageSecurity {-interactive}
The following example uses Jython to set the permissions:
  • Batch mode
    AdminTask.wbmUpdatePackageSecurity('[-modelID modelID]')
  • Interactive mode
    AdminTask.wbmUpdatePackageSecurity ('[-interactive]')

Permissions

Users and groups defined in monitor data security, regardless of the monitor data security role, are granted the following permissions for IBM Cognos BI packages:
  • Read
  • Write
  • Traverse
  • Set Policy

In addition, administrators have Set Policy permission.

Monitor cube generation does not define IBM Cognos BI package administration access (Read, Write, Traverse, Set Policy, Execute) explicitly. By default, IBM Cognos BI administrators have full permissions to all published packages.
Important: Monitor cube generation is different from monitor data security, in which no users have default access to monitoring models.

Because all users, by default, are in the IBM Cognos BI System Administrators list, be sure to configure the IBM Cognos BI administrator user.

How access is applied

The way that access is applied depends on whether global security is on or off and if any users or groups are defined in monitor data security.

If global security is off, IBM Cognos BI packages are published without package security specified. Anyone who can access the IBM Cognos BI console can access a package.

If global security is on, all users and groups defined in monitor data security are applied to IBM Cognos BI packages.
  • If no users or groups are defined in monitor data security, only the IBM Cognos BI administrator is added to the user access list of the package. Other users have no access to the package.
  • If at least one user or group is defined in monitor data security, the user or group has user access (Execute, Read, Traverse, and Write permission) to the package.
  • The IBM Cognos BI administrator and users in the following IBM Cognos BI roles have administration access (Read, Write, Traverse, and Set Policy permission) to the package:
    • Controller Administrators
    • Metrics Administrators
    • Planning Rights Administrators
    • PowerPlay Administrators
    • Report Administrators