Essbase Application Access Rights

Hi,
I have a essbase application without planning, and try yo give read rights to a user via Shared Service , but without giving essbase admin rights, user can't see application, i give to user read on application and server access on essbase, unfortunately it doesn't work, i want that user can see one application and read data from it, how can i solve this.

As said in earlier post, you should sync the security from sharedservices to essbase.
once you give server access and read access, you need to sync user.
You can sync that particular user alone rather than syncing all the users. use the following maxl command to sync single user
alter user <username> sync security with all application;
if you are still facing issue, check what access it is showing in essbase (not in shared services).
- Krish

Similar Messages

  • Adding Essbase Server access to Planning Application group

    Hi All,
    How we can add Essbase server access to Planning Application group in Shared services ? Pls. advice

    You can't provision access against any application group.
    However, you can create and use native user groups or use external user groups and provision those groups to have acccess to Essbase and Planning.
    See this post for an example of how I like to set up groups in Shared Services for Planning:
    http://camerons-blog-for-essbase-hackers.blogspot.com/2009/08/planning-security-wrong-way-and-right.html
    The top level group I refer to in the post is where I typically grant Essbase Server Access.
    Regards,
    Cameron Lackpour

  • Using Workspace to access Essbase Application - HELP

    I have created an application in Essbase. Is there anyway that I can register and import the app into Workspace; more specifically Performance Managment Architect or are Essbase applications completely isolated? Please help. The Essbase application is registered in Shared Service but that's as far as it will go.

    How do I access the app through workspace? I have done the following steps:
    - created the application in Essbase Administration console.
    - Registered the app with shared services
    - Exported the dimensions to ss
    - provisioned the user to have a global role on ss of application and dimension creator and on the essbase app as application manager
    - synchronized ss; logged onto workspace
    The app created in EAS does not reflect.

  • Does putting an app in Applications give it an special access rights?

    Hi,
    I am very concerned about security.  I use no Flash or Java (no Java browser plug-in).  I won't install anything that wants to be in the system Applications directory.
    OpenOffice/VLC, for example, I just put in a user directory.  I was going to install World of Warcraft and did not because it wants to install system components.   I use Steam because I can install it in the user's directory.
    The question is this:  Does copying an app, like OpenOffice or VLC, to the system's Applications directory give it any special access rights when it is run by a user?  For example, does user A running OpenOffice from the system Applications directory give it access to anything that user A does not have access to?
    Regards, Patrick

    Applications folder is like any other folder, and the truth is that you can put your apps wherever you want. The difference is that Applications folder is a folder where all users can access to, so if you put an app in another folder, you will probably be able to access to the app only with one user. Apart from that, there isn't any difference.
    Note that some apps are installed directly into Applications folder, like Microsoft Office. In those cases, I don't recommend you to move them to another folder because it doesn't make sense and because you may damage it

  • Access rights in case of a tree-like structure, with inheritance

    Hello,
    the project I've just started to work on should include an easy way (from the user's point of view) to grant/revoke access rights on a tree-like structure with inheritance.
    Basically we are working for several international companies who want to use our application to watch/manage some of their web projects - each project belongs to one company and consisting of several 'campaigns' in several countries (there can be several campaigns per country, but each campaign belongs to exactly one country).
    From our point of view this is a tree-like structure, with a 'root' node at the top level, 'companies' at the first level, 'countries' at the second level, 'campaigns' at the third level, and modules of our application (for example a module to display overall stats of the campaing, and so on) at the fourth level. There could be (and probably will be) some more levels, but that's not important at this point - it will always be a tree-like structure.
    The customer's reqirements are natural - the administrators should be able to grant/revoke access to 'subtrees' of this structure. For example the top managers should be able to see all the data related to their company, the local managers should be able to see all the data related to their company in the country they work in, etc. On the other hand the relular employees should not see some of the modules (with details about clients of the company).
    I wonder whether this can be solved using JAAS in an elegant and flexible manner - from the documents / whitepapers / tutorials I've seen till now it seems to me it seems to me not too suitable.
    All the data will be stored in relational database (Oracle, and in some cases PostgreSQL), and it would be nice to have the access rights stored in the same way (but it's not required). We have some ideas how to solve that using a single table containing paths in the tree, but at this point it's only an idea (not a single line of code written).
    We are sure somebody has already to solve such a problem - maybe using JAAS, maybe some other technology - and we don't want to reinvent a wheel. Do you have an idea how to solve this (using JAAS or something else)?

    Well, I forgot to explain what the 'inheritance' means ...
    We do not want to set the access right on each node of the tree - we prefer (as well as the users) to set/store only as much information as needed. We'd like the nodes to inherit the access rights from their parent nodes. For example we'd like granting access to particular project to mean granting access to all campaigns in all countries (related to the project), without the need to set and store these rights for each of the campaigns/countries.

  • Problem with access rights in web forms

    <p>Hi</p><p>i am facing the problem in giving access rights to users inplanning application.</p><p>i gave write access to all my forms and all my users were giveninteractives user access.</p><p>but when users tried to open to the forms. they are getting thefollowing error</p><p> </p><p><b>Security and/or filtering has resulted in a requireddimension not being represented on this form</b></p><p> </p><p>i don't where i am missing. please help.</p><p> </p><p>thanks</p><p>Balu</p>

    Balu,<BR><BR>1)Check if the security filter have been refreshed.<BR>2)Check if all the members from all dimensions are defined on the webform<BR><BR>Thanks..

  • Grant the Essbase application permission to user in Shared Services

    Hi,
    We got a problem in granting the Essbase permission to user using Shared Services. We are using Hyperion 9.3.1.
    (1) We created an Essbase application + database through Essbase Administration Console, say TBC.Sales.
    (2) Provision the Essbase "Server Access" + Essbase Application "Read" roles to a user.
    (3) In Essbase Admin Console, we "Refresh Security from Shared Services".
    However, the user still cannot see the Essbase Database in SmartView. Does anyone know how to fix the problem?

    The problem is fixed with Essbase 9.3.1.3.0.5.

  • Essbase Application Doesn't show up in Selected Roles in shared services

    Hello all,
    I have few essbase applications which donot show up in the"Selected roles" column in Shared services though the user has been provisioned with the application. Infact the provisioned users can access the application based on the provisioning, but just that I as an administrator donot see it there in the selected roles department. Again this is only in "Selected roles" column meaning I can see it in the "Available roles" column. The application has been registered in EAS and I have also refreshed the security in EAS. We are on 11.1.1.4. Any ideas anyone?
    Thanks,
    Ted.
    Edited by: Teddd on Jan 10, 2013 9:43 AM

    Working with Oracle on it, they think it is a bug.

  • Access rights - heavy issue

    I have managed to somehow partly corrupt the access rights on my iMac/SnowLeo system.
    Getting a lot of failure messages at the start up and some applications are just not working properly anymore.
    iTunes for instance does not longer recognize my iPhone - just doesn't - and again I get some strange messages.
    Tried to repair access rights be starting OS x from DVD and used hard disk tools (not sure whether it is called exactly this in English - have a German system installed) and used "repair access rights" on the OS volume - seemed to work because a lot has been repaired but after starting iMAC again - same problem.
    Now - what can I do to get this fixed on the access rights? Re-install Mac OS x- what would happen with all applications, e-mails etc?
    Any idea - help - would be very much appreciated
    Robert

    Thanks - tried it (and seemed to make a lot of sense) but didn't help at the end :-(
    Still same issues
    Am not a Mac OS X specialist or UNIX or whatever - actually I am not very familiar with the details of the OS and all its settings etc etc.
    However, following some messages, Internet, other sources ---- here's what I have managed to find out:
    1) Mac OS starts up - all fine
    2) after the desktop / dock is visible I get some similar but in general the following message (trying to translate since they are in German on my installation)
    "insecure start objects disabled" - ../Library/StartUpItems/Executor" has not be started since the object does not have the correct security settings
    .. I usually get about 10 of them with different "names"(objects) - e.g. "/Executor","/EyeConnect" etc etc.
    Now - this all happens on my iMac; I also have a similar configured MacBook and just checked the security setting for exactly these objects on it - the difference is in "share and access rights" on the MacBook has "System" read and write and all others only read - funnily enough - I can not find "System" within "Share and Access rights" on the iMac!!!! 
    So - next idea: let's add "System" as a user to these folders/shares with "Share and Access rights" - can find a user named "System".
    Uh - it seems I have managed to "kill" something on my iMac ..... just don't know how (but that's not so important) and just don't know how to repair - re-installation of Mac OS X on iMac didn't make a lot of changes.
    Help appreciated!!!
    Robert

  • Access Rights

    I need two different access rights to a same user. One when he signs on to the application using forms and another when he sign on using SQL*PLUS. Is there a way to do this??

    One way we do is that, when launching the forms application, it first logs on as a dumb user login/login, that only has the rights of executing some stored functions in a package that return the name & password of a user that has all the needed privileges. After the making the calls to those functions, the form has the name & password of the user that will be used to logon and perform what's needed.
    You may say that this way one may easily find-out the name & password of that "priviledged user". Still, those functions are not returning "in clear" the name & password, but they have to be combined in a way one would not easily guess. Moreover, the "login" user has no other priviledges except executing the respective package, no selects, no other things at all.
    null

  • How to set application access type for list of users

    Hi everybody,
    I've an requirement to automise the application access type setting in shared services.
    When i searhed to do with MaxL scripts.I'm able to set the application access type for a single user using
    alter user 'username' add application access type essbase
    alter user 'username' add application access type planning
    But,i've to perform this as a daily activity updating for list of users.Is there away to do it..??..i want to pass the list of users to the above alter user command.??
    Please help me.
    Cheers
    Saran
    Edited by: user11396937 on Aug 27, 2010 2:09 AM

    I discovered that changing "Image interpolation" optioon in general preferences of Photoshop has direct influence on smart object interpolation type. You can even reinterpolate smart object after changing image interpolation in preference. Just click ctrl + t and enter.

  • 5610 T-Mobile doesn't allow applications access to...

    The exact error I get is, "application access set to not allowed". I downloaded a third party application that attempts to access the internet for information, but my T-Mobile branded phone does not allow it.
    What do I need to change in order to fix this problem?

    I did try your suggestion and yes the 5610 will start without a sim inserted. Without the sim my browser is still labeled T-Zones, and certain T-Mobile files still existed and couldn't be deleted. I also got the same error when starting a couple of the same applications. No I didn't expect them to work, but I expected an error along the lines of no connection not the same application access not allowed. Honestly I had no doubt that they made changes which is why i have been giving them such a hard time, I was pretty sure I am being lied to. What this definetly tells me is that I could not just take this phone to another network and have it work correctly because that was an option. What it doesn't tell me is if I get a vanilla phone would I still have problems because of what is or perhaps isn't on the sim card? As far as I am concerned though my phone is defective since it does not work as it should, there is a big difference between cosmetic changes for branding and functional changes that alter the way the equipment works. If third party network applications do work on this phone then I would expect them to work on mine, Ya ok I could see T-Mobile disabling them through the sim so that those features can not be used on thier network (stupid but ok they have that right) but not breaking the phone to disable them after all this is now my phone and should I chose to move to a network that permits them (again an option I am considering) they should work since they are supported by the phone. 

  • Access rights , privileges on XML DB

    Hello,
    I would like to know where can I find information about implementing security and access rights. I have 5 folders under SCOTT/TIGER schema and would like to asign access rights to different user , ie user A can access folder A only, user B can see folder A & Folder B , so on so .
    I will appreciate your help.
    Thanks
    Syed.

    I did and here is the result
    1 select r.res.getClobVal()
    2 from resource_view r
    3* where equals_path(res,'/home/SCOTT')=1
    SQL> /
    R.RES.GETCLOBVAL()
    <Resource xmlns="http://xmlns.oracle.com/xdb/XDBResource.xsd" Hidden="false" Inv
    alid="false" Container="true" CustomRslv="false" VersionHistory="false" StickyRe
    f="true">
    <CreationDate>2003-09-11T15:53:42.672000</CreationDate>
    <ModificationDate>2003-10-01T09:08:15.456000</ModificationDate>
    <DisplayName>SCOTT</DisplayName>
    <Language>en-US</Language>
    <CharacterSet>UTF-8</CharacterSet>
    <ContentType>text/plain</ContentType>
    <RefCount>1</RefCount>
    <ACL>
    R.RES.GETCLOBVAL()
    <acl description="Protected:Readable by PUBLIC and all privileges to OWNER"
    xmlns="http://xmlns.oracle.com/xdb/acl.xsd" xmlns:dav="DAV:" xmlns:xsi="http://w
    ww.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.oracle.com/x
    db/acl.xsd http://xmlns.oracle.com/xdb/acl.xsd">
    <ace>
    <principal>dav:owner</principal>
    <grant>true</grant>
    <privilege>
    <all/>
    </privilege>
    </ace>
    R.RES.GETCLOBVAL()
    <ace>
    <principal>XDBADMIN</principal>
    <grant>true</grant>
    <privilege>
    <all/>
    </privilege>
    </ace>
    <ace>
    <principal>PUBLIC</principal>
    <grant>true</grant>
    <privilege>
    R.RES.GETCLOBVAL()
    <read-properties/>
    <read-contents/>
    <read-acl/>
    <resolve/>
    </privilege>
    </ace>
    </acl>
    </ACL>
    <Owner>SCOTT</Owner>
    <Creator>SYS</Creator>
    <LastModifier>SCOTT</LastModifier>
    R.RES.GETCLOBVAL()
    </Resource>
    and for /home/SCOTT/1999
    SQL> select r.res.getClobVal()
    2 from resource_view r
    3 where equals_path(res,'/home/SCOTT/1999')=1;
    R.RES.GETCLOBVAL()
    <Resource xmlns="http://xmlns.oracle.com/xdb/XDBResource.xsd" Hidden="false" Inv
    alid="false" Container="true" CustomRslv="false" VersionHistory="false" StickyRe
    f="true">
    <CreationDate>2003-09-25T11:56:18.910000</CreationDate>
    <ModificationDate>2003-09-25T11:56:21.023000</ModificationDate>
    <DisplayName>1999</DisplayName>
    <Language>en-US</Language>
    <CharacterSet>WINDOWS-1252</CharacterSet>
    <ContentType>application/octet-stream</ContentType>
    <RefCount>1</RefCount>
    <ACL>
    R.RES.GETCLOBVAL()
    <acl description="Private:All privileges to OWNER only and not accessible to
    others" xmlns="http://xmlns.oracle.com/xdb/acl.xsd" xmlns:dav="DAV:" xmlns:xsi=
    "http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.ora
    cle.com/xdb/acl.xsd http://xmlns.oracle.com/xdb/acl.xs
    d">
    <ace>
    <principal>dav:owner</principal>
    <grant>true</grant>
    <privilege>
    <all/>
    </privilege>
    R.RES.GETCLOBVAL()
    </ace>
    </acl>
    </ACL>
    <Owner>SCOTT</Owner>
    <Creator>SCOTT</Creator>
    <LastModifier>SCOTT</LastModifier>
    </Resource>
    ===========================End====================
    Hope this helped.
    Syed

  • Error starting essbase applications

    Hello specialists!
    I'm having a problem restarting the essbase applications.
    When i restart the essbase i receive the following error message in the applciation log:
    [Thu Jun 21 12:57:34 2012]Local/PlanApp///3348/Error(1019005)
    Unable to Read [E:\Hyperion\user_projects\epmsystem2\EssbaseServer\essbaseserver1\APP\PlanApp\Plan1\Plan1.ind], Not a Recognized Format
    I tried to rename plan1.ind to oldpplan1.ind just to check if the application would start without problems and it worked.
    I would like to know what could have caused this problem and how can i regenerate the plan1.ind file?
    Thanks in advance!
    Best regards!

    Hi,
    You can try these steps:
    1 - Stop the Essbase Server and delete the Plan1.ind file.
    2 - Start the Essbase Server and log into the EAS Console
    3 - Navigate to the corresponding application and right click over the database you are having problems.
    4 - Select Restructure.
    Most Essbase application files are renewed after a Restructure and in this case Plan1.ind will be re-created.

  • Database create error due to folder access right.

    I have an application which will create a SQL database(using CREATE DATABASE) and the database files are supposed to be placed in c:\program files\myApp\data\myDatabase.mdf
    However, when I try to do so, I get the following error:
    System.ApplicationException: System.Data.SqlClient.SqlException: CREATE DATABASE failed. Some file names listed could not be created. Check related errors.CREATE FILE encountered operating system error 5(Access Denied) while attempting to open or create the physical file 'C:\Program Files\myApp\data\myDatabase.mdf'.
    My window login already have administrator role.
    The problem can be solved if I manually add full access right to my login in window exploder.  However, how can I do this programmatically?  Or what is the proper way to create database located under my application folder?

    I get this error ("error 5(Access is denied) while attempting to open or create the physical file...") under the following circumstances:
    1) Using SSE
    2) create a database
    3) Attach to it with SQL Server Studio
    4) Detach
    5) Attach again -- I then get the error. 
    I tried stopping and restarting the server - no success.  I can recreate the database and get my one-shot access again so, at this point, I'm lost.

Maybe you are looking for