Grant and revoke user permissions in ITSI

You can set read and write permissions for the following types of ITSI objects:

  • Service analyzers
  • Glass tables
  • Deep dives
  • Episode review dashboards
  • Correlation searches
  • Multi-KPI alerts

These permissions determine which user roles have read/write permissions to specific objects that have been created, such as a shared service analyzer view, a shared glass table, or a correlation search.

These role-based permissions apply to the shared ITSI objects listed above. Notable event aggregation policies use Episode Granular Permissions by default from ITSI 5.0 and are configured through owner teams and shared teams.

Prerequisites

  • You must have the configure_perms capability to use this role-based permissions workflow for the ITSI objects listed above. This prerequisite does not describe the user-level requirements for editing a NEAP when Episode Granular Permissions is enabled.
  • Before you can set permissions to ITSI objects for a role, the role must have the proper capabilities assigned. For more information, see the ITSI capabilities reference in this manual.

Steps

  1. On the lister page for the object type, locate the object that you want to update and select Edit > Edit Permissions.
  2. Assign read/write permissions to the applicable ITSI roles.
  3. Click Save.

Configure notable event aggregation policy permissions

From ITSI 5.0, do not use the role-based permissions workflow for notable event aggregation policies (NEAPs) when Episode Granular Permissions is enabled.

  1. From the ITSI menu, select Configuration > Notable Event Aggregation Policies.

  2. Open the policy that you want to configure.

  3. Select Filtering Criteria and Instructions > Aggregation Policy & Episode Permissions.

  4. Select the owner team and any shared teams, then click Save.

    Note: Shared teams have read-only access.

To edit a NEAP, a user must be a member of the owner team, have write permission for that team, and have the write_itsi_notable_aggregation_policy capability.

Note: If Episode Granular Permissions is disabled, the legacy role-based Actions > Edit Permissions workflow is available.