Assigning Meta Data Security Privileges
There are three types of Meta Data Security privileges that can be granted—Dimensions, Cubes and Slices. Indeed, there are three levels of Security for each: Read, Add and Design. Each type/level has a different consequence (these are summed in the table that follows this section) and would be assigned for a different purpose.
We will consider each Meta Data Privilege in turn, giving the general procedure and providing an example for why we might want to grant the privilege. (The assumption is always that a user with Administrator privileges is performing the actions described—i.e., granting Meta Data Security Privileges to Users/Groups.)
The Meta Data Privileges
The following table provides a detailed summary of the consequences of each level of Meta Data Privileges. [Note: Fact Data Privileges may also need to be granted—subject of the next section.]
Access Level Privilege: READ |
||
Dimension |
Cube |
Slice |
Can see the dimension |
Can see the cube |
Can see the slice |
Can see its members |
Can create a slice |
Slice opens read-only; cannot edit |
Can see its hierarchy |
Can access data locks |
Cannot rename or delete the slice |
Can see its alias groups |
Cannot see its formulas |
Cannot see its metadata security properties |
Can see its subsets |
Cannot see its metadata security properties |
Cannot save slice metadata edits |
Cannot see its metadata security properties |
Cannot see its factdata security defintions |
|
Cannot rename or delete the dimension |
Cannot rename or delete cube |
|
Access Level Privilege: ADD |
||
Dimension |
Cube |
Slice |
Can see the dimension |
Can see the cube |
Can see the slice |
Can see its members |
Can create a slice |
Slice opens editable |
Can add members |
Can access data locks |
Cannot rename or delete the slice |
Can rename and delete newly added members |
Cannot see its formulas |
Cannot see its metadata security properties |
Can see its hierarchy |
Cannot see its metadata security properties |
Cannot save slice metadata edits |
Can add members to root of the hierarchy only |
Cannot see its factdata security defintions |
|
Can see its alias groups |
Cannot rename or delete cube |
|
Can add alias groups |
|
|
Can add aliases |
|
|
Can see its subsets |
|
|
Cannot see its metadata security properties |
|
|
Cannot rename or delete the dimension |
|
|
Cannot rename or delete existing members |
|
|
Cannot modify aggregates |
|
|
Access Level Privilege: DESIGN |
||
Dimension |
Cube |
Slice |
Full privileges |
Full privileges |
Full privileges |
Access Level Privilege: OWNER/ADMINISTRATOR/CREATOR |
||
Dimension |
Cube |
Slice |
Full privileges |
Full privileges |
Full privileges |
Please see the following topics: