Setup Actions
Setup actions grant users the privileges to view and maintain (create, edit, and delete) the object or task in question. These actions can be added to Action Sets, as defined in the Action Sets topic here.
Important: At a minimum, all users must be granted the 'View context' privilege in order to log on to STEP.
Action Sets
|
Action |
Privileges Granted |
|---|---|
|
Maintain action sets (create, delete, add to, remove from) |
|
Administration
|
Action |
Privileges Granted |
|---|---|
| System Administration | Ability to maintain configuration properties, prepare and deploy Extension API extensions, retrieve the STEP system status, and restart the STEP system via the remote system administration REST API. This functionality is strictly for Stibo Systems' STEP SaaS customers only. Note: The 'System Administration' privilege should only be given to trusted system administration users. |
|
View Administration |
Ability to access the STEP System Administration pages from the Start Page |
|
View System Setup Logs |
Ability to view the System Setup Log and Workspace Log (available from View > Logs in the workbench) and the Log tab (available in the editor on most System Setup objects). Without this privilege, the System Setup Log option in the View > Logs menu is grayed out, and the Log tab is not visible on System Setup objects. |
Assets
|
Action |
Privileges Granted |
|---|---|
|
Maintain Asset Importer Configuration |
Controls if a user is permitted to change an Asset Importer configuration. |
|
Modify dimension dependency of all assets |
Set dimension dependency of asset object types:
|
|
Push Asset |
Ability to push assets from within the Tree |
Attributes
Note that the actions concerning domains are also needed for LOV maintenance.
|
Action |
Privileges Granted |
|---|---|
|
Add attribute to attribute group |
Ability to add to and create attributes in attribute groups Note: The 'Create product attribute' action must also be added before users can add attributes to attribute groups. |
|
Create attribute group |
Ability to create attribute groups Note: The action 'Modify name/description of attribute group (also translate)' must also be added before users can create attribute groups. |
|
Create product attribute |
Ability to create attributes
|
|
Delete attribute group |
Ability to delete attribute groups |
|
Delete product attribute |
Ability to delete attributes
|
|
Maintain validation templates |
Create a validation template (validation base type) for attributes and LOVs |
|
Remove attribute from attribute group |
Ability to remove (unlink) attributes that are linked to other attribute groups as well as add attributes to a group. |
|
Merge product attributes |
Ability to merge attributes |
|
Modify definition of product attribute (domain and default unit) |
Note: The 'Create product attribute' action must also be added in order to set validation of attributes. |
|
Modify dimension dependency of product attribute |
Edit the dimension dependencies of attributes |
|
Modify metadata for product attribute (property value) (also translate) |
|
|
Modify name/description of attribute group (also translate) |
|
|
Modify name/description of product attribute (also translate) |
Note: The 'Modify name/description of domain (also translate)' action must also be added in order to create LOV attributes. |
|
Modify valid (node) types for product attribute |
Set which object types the attributes should be valid for. |
|
View attribute |
Ability to view attributes |
|
View attribute group |
Ability to view attribute groups The 'View attribute group' action must be added for users to maintain attributes. |
|
View metadata for attribute (property value) |
View values of description attributes linked to an attribute |
Background Processes
|
Action |
Privileges Granted |
|---|---|
|
Delete background-processes |
Delete queued, started, and ended background processes |
|
View Background Processes of Other Users |
In workbench, while displaying other users' processes via the show all button ( In Web UI, the user can view and download files from the background processes they started. For users without this privilege:
|
Bulk Updates
|
Action |
Privileges Granted |
|---|---|
|
Perform Bulk Update |
Ability to run or schedule a Bulk Update from the File menu. |
Business Modules
|
Action |
Privileges Granted |
|---|---|
|
Install Business Modules |
Activates the Business Module Manager option on the File menu, and enables the ability to install business modules that have been activated by Stibo Systems. |
Business Rules
|
Action |
Privileges Granted |
|---|---|
|
Maintain business-rule |
Create, maintain, and delete business rules. |
Change Packages
|
Action |
Privileges Granted |
|---|---|
|
Maintain change package |
Grants all privileges for change packages, including creation of a change package, deletion, Start Impact Report, Updates, and Seal Package. |
|
View change package |
Grants the privilege to view change packages from the System Setup tab. |
Contexts
|
Action |
Privileges Granted |
|---|---|
|
Maintain dimensions and contexts |
Create and delete dimensions, dimension points, and contexts |
Cryptographic Keys
|
Action |
Privileges Granted |
|---|---|
|
Maintain cryptographic keys |
Create or delete cryptographic keys, and change their passwords. |
Data Quality
|
Action |
Privileges Granted |
|---|---|
|
Maintain unique keys |
|
|
Maintain Value Generator |
|
|
Modify unique key value |
Update locked attribute values used in unique keys |
Deduplication
|
Action |
Privileges Granted |
|---|---|
|
Maintain Deduplication Configurations |
Create, maintain, and delete 'Match Codes and Matching Algorithms' and maintain deduplication configuration options |
|
Maintain Possible Duplicates |
Maintain, merge, and delete possible duplicates |
Events
|
Action |
Privileges Granted |
|---|---|
|
Maintain Event Processor |
|
|
Maintain event queues |
Add, modify or to delete event queues. Removal of this action hides the Event Queues root in System Setup. |
|
View Event Processor |
View Event Processors |
GDSN Data Pools
Having setup actions for GDSN data pools allow users to view and maintain (create, edit, delete) GDSN data pools and GDSN subscriptions.
|
Action |
Privileges Granted |
|---|---|
|
Create GDSN Data Pool Publisher |
Create a GDSN Data Pool Publisher for publishing products to the GDSN. This is the action required to use the Easy setup of GDSN Component Model. |
|
Create GDSN Data Pool Receiver |
Create a GDSN Data Pool Receiver for receiving products from the GDSN |
|
Create GDSN Recipient |
Create GDSN recipient(s) |
|
Create GDSN Subscription |
Create GDSN subscriptions |
|
Delete GDSN Data Pool Publisher |
Delete a GDSN Data Pool Publisher |
|
Delete GDSN Data Pool Receiver |
Delete a GDSN Data Pool Receiver |
|
Delete GDSN Recipient |
Delete GDSN recipient(s) |
|
Delete GDSN Subscription |
Delete GDSN subscriptions |
|
Maintain GDSN subscription |
Maintain GDSN subscriptions |
|
Modify GDSN Data Pool Publisher metadata |
Modification of the GDSN Data Pool Publisher metadata |
|
Modify GDSN Data Pool Publisher name |
Modification of the GDSN Data Pool Publisher name |
|
Modify GDSN Data Pool Receiver metadata |
Modification of the GDSN Data Pool Receiver metadata |
|
Modify GDSN Data Pool Receiver name |
Modification of the GDSN Data Pool Receiver name |
|
Modify GDSN Recipient meta-data |
Modification of the GDSN Data Pool Recipient metadata |
|
Modify GDSN Recipient name |
Modification of the GDSN Data Pool Recipient name |
|
Modify GDSN Subscription meta-data |
Modification of GDSN Subscription metadata |
|
Modify GDSN Subscription name |
Modification of the GDSN Subscription name |
|
View GDSN Data Pool Publisher |
View the GDSN Data Pool Publisher data |
|
View GDSN Data Pool Publisher metadata |
View the GDSN Data Pool Publisher metadata |
|
View GDSN Data Pool Receiver |
View the GDSN Data Pool Receiver data |
|
View GDSN Data Pool Receiver metadata |
View the GDSN Data Pool Receiver metadata |
|
View GDSN Recipient |
View the GDSN Recipient data |
|
View GDSN Recipient meta-data |
View the GDSN Recipient metadata |
|
View GDSN Subscription |
View the GDSN Subscription data |
|
View GDSN Subscription meta-data |
View the GDSN Subscription metadata |
Integration Endpoints
|
Action |
Privileges Granted |
|---|---|
|
Maintain Derived Event Types |
Configure and maintain derived events. If Maintain Derived Event Types is disabled, there is no option to add one. |
|
Maintain Integration Endpoint |
Create, delete, enable, disable, and invoke integration endpoints. Users must also have the privilege 'View Integration Endpoint' in order to maintain an integration endpoint. |
|
View Integration Endpoint |
Ability to view integration endpoints |
Link Types
|
Action |
Privileges Granted |
|---|---|
|
Maintain Link Type |
Note: In order to apply description attributes to link types, these actions are also needed:
|
List of Values (LOVs)
|
Action |
Privileges Granted |
|---|---|
|
Create domain |
Ability to create LOVs Note: The actions 'Modify name/description of domain (also translate)' and 'Modify definition of domain (validator, etc.)' must also be included in order to create LOVs. |
|
Create value in hard domain |
Create values in LOVs where users are not allowed to add values ('hard' LOVs) |
|
Create value in medium domain |
Create values in LOVs where users are allowed to add values ('medium' LOVs) |
|
Delete domain |
Ability to delete LOVs |
|
Delete value in hard/medium domain |
Delete values in both types of LOVs:
|
|
Maintain domain groups |
Create and delete LOV groups |
|
Merge entire domain |
Ability to merge LOVs |
|
Merge value in hard/medium domain |
Merge values in both types of LOVs:
|
|
Modify definition of domain (validator, etc.) |
Set and edit the validation base type of LOVs Note: The 'Create domain' action must also be added in order to set validation of LOVs. |
|
Modify dimension dependency of domain |
Edit the dimension dependencies of LOVs |
|
Modify name/description of domain (also translate) |
|
|
Modify value in hard/medium domain (also translate) |
Edit values in both types of LOVs (including the privilege to translate):
|
|
View domain |
Ability to view LOVs Note: The 'View domain' action must be added in order to maintain LOVs. |
|
View metadata for domain (property value) |
View values of description attributes linked to an LOV |
Object Types
|
Action |
Privileges Granted |
|---|---|
|
Maintain Data Container Type |
Create a data container type |
|
Maintain Setup Entity |
Create an Entity Root and object type. Example: Completeness Metric |
|
Maintain setup group |
Create a Setup Group Root from Maintain > Insert > Setup Group Root... |
|
Maintain system setups |
Ability to maintain options under the System Setting tab located on the 'Users & Groups' node in System Setup. |
|
Maintain type hierarchy (node types) |
In order to link attributes to object types, these actions are also needed:
|
|
View Data Container Type |
View a data container type |
|
View Setup Entity |
View an Entity Root and object type. Example: Completeness Metric |
Print Publication
|
Action |
Privileges Granted |
|---|---|
|
Maintain promotional pricing |
Deprecated |
|
Modify frozen publication |
Modify a frozen publication. This action is only used in conjunction with the 'Publishing - Freeze' component model. |
Purging
|
Action |
Privileges Granted |
|---|---|
|
Empty recycle bin |
Ability to delete contents of the Recycle Bin. In case the Recycle Bin contains objects that exist in more than one workspace, users must also have the 'Force Delete and Purge' action enabled in order to remove those objects. |
|
Force Delete and Purge |
Ability to force purge objects that exist in more than one workspace and objects with events triggered. The action enables the 'Force Purge' button in the Empty Recycle Bin background process and the 'Force Delete and Purge' action in the Maintain menu. |
|
Purge revisions |
Ability to delete obsolete revisions:
|
Reports
|
Action |
Privileges Granted |
|---|---|
|
Run Reports |
Allows users to run reports (including starting a reports background process) from File > Reports in the workbench. Without this privilege, the Reports option in the workbench File menu is grayed out. |
SDK / API Documentation
|
Action |
Privileges Granted |
|---|---|
|
View SDK Documentation |
Ability to view the SDK / API documentation from server/sdk and the STEP API Documentation button on the STEP Start Page. |
Tables
|
Action |
Privileges Granted |
|---|---|
|
Modify table settings |
Ability to maintain table settings on table types, row types, column types, rules / line styles, and colors. |
|
View table types |
Allows users to view tables and table types. |
Tags
|
Action |
Privileges Granted |
|---|---|
|
Maintain Tags |
|
|
Use tag |
Use tags in the rich text editor, table editor, and in table transformations. To restrict certain users to using certain tags, you must create a tag group that contains these tags and link this tag group into an attribute group. In the User Group editor, the attribute group is applied together with the action set that contains the 'Use tag' action. Users belonging to the user group will only be allowed to use the tags in the tag group linked into the attribute group. |
Units
|
Action |
Privileges Granted |
|---|---|
|
Maintain units |
|
|
View unit |
Ability to view units. This is used when linking units to attributes. Note: The 'View unit' action must be included in order to use the 'Maintain units' action |
Users & Groups and Privilege Rules
|
Action |
Privileges Granted |
|---|---|
|
Maintain privilege rules (create, delete, modify) |
Note: In order to maintain privilege rules, the action 'Maintain action sets (create, delete, add to, remove from)' is also needed. |
|
Maintain users and groups |
|
|
Maintain user password |
Ability to change and reset user passwords |
|
Share user settings |
Limits whether or not a user can share their user configured views in Web UI. |
Value Search
|
Action |
Privileges Granted |
|---|---|
|
Enable Value Search/Values in typeahead |
Ability to search for attribute values within attributes |
Web UI
|
Action |
Privileges Granted |
|---|---|
|
Access Web UI |
Ability to access Web UIs on the system. Access to specific Web UI instances can be granted if a Setup Group is defined in the user (group) Setup Privileges, otherwise, this action allows access to ALL Web UI instances on the server. |
|
Maintain Impersonation |
Ability to impersonate another user for Web UI support purposes |
|
Update Web UI configuration |
Access to modify and configure any STEP Web UI |
|
View context |
In addition to granting access to the STEP Workbench, 'View context' also grants the ability to access the Web UI. |
|
Web UI Administration |
Grants the ability to:
|
Workflows
|
Action |
Privileges Granted |
|---|---|
|
Disable STEP Workflow Auto-initiation in Imports |
Ability to disable auto-initiation when importing data |
|
Initiate Item in STEP Workflow |
Ability to start workflows via the Object context menu and via bulk update. It does not have any impact on auto-initiation. The action can be applied to a setup group and will then only take effect for workflows in that setup group. |
|
Maintain STEP Workflow |
Ability to create, delete, cut, copy, duplicate, export, and edit workflows. The action can be applied to a setup group and will then only take effect for workflows in that setup group. Users must also have the 'View setup group' privilege in order to view and maintain workflows |
| Maintain STEP Workflow Profile |
Edit, create, and delete workflow profiles. The action can be applied to a setup group and will then only take effect for workflow profiles in that setup group. Users must have 'View STEP Workflow Profile' in order to access workflow profiles. |
|
Remove Item from STEP Workflow |
Ability to remove objects from workflows via the Object context menu or the workflow context menu. The action can be applied to a setup group and will then only take effect for workflows in that setup group. |
|
STEP Workflow Administrator |
The action can be applied to a setup group and will then only take effect for workflows in that setup group. |
|
View STEP Workflow Profile |
View workflow profiles. If a user does not have this action, the STEP Workflow navigator tab sub tab 'Profile' will not be displayed. The action can be applied to a setup group and will then only take effect for workflow profiles in that setup group. |
|
View and use STEP Workflow |
View and use workflows. The action can be applied to a setup group and will then only take effect for Workflows in that setup group. It is required to also have the 'View setup group' privilege in order to view workflows. |
|
View setup group |
Necessary for users to view workflow tasks |
|
View STEP Workflow Advanced tab |
This action grants the privilege to view the 'Advanced' STEP Workflow navigator tab sub tab. It is required to also have the 'View setup group' privilege in order to view workflows. |
|
View tasks assigned to other users in my group(s) |
Allows users to view all assigned tasks in any and all groups in which they are a member. This privilege differs from what is currently provided by the 'STEP Workflow Administrator' setup action in that the 'STEP Workflow Administrator' setup action allows users to view all tasks across all groups. |
Workspaces
|
Action |
Privileges Granted |
|---|---|
|
Maintain workspaces |
Create and delete workspaces |
) , the user can view and download files from background processes started by any other user.