Instructions to Restrict Access to the Main Tool
Updated: 9/302014
Applies to SSP v2.5.2 or later
Purpose:
By default, the Main Tool is available for any users that can access the SSP portlet. In some cases, the data may not be suitable for every SSP user. New permissions added to SSP in v2.5.2 allow users to access SSP tools like Journal and Action Plan without accessing the Main Tool. The instructions below describe how to remove the Main Tool from a SSP role. The below are an example for the Support Staff role, but any role could be adjusted.
Permission Comparison
PERSON | PERSON_FILTERED |
---|---|
|
|
Steps
- Remove the PERSON permissions from the desired group (Support Staff in the example)
- Add the PERSON_FILTERED permissions to the desired group (Support Staff in the example)
- Clear the permission caches
Step 1: Remove the PERSON permissions
- As an administrator, navigate to Manage Users -> Manage permissions
- Use Ctrl+F to find the "PERSON_READ" permission. Click it.
- You will see a list of SSP roles with the PERSON_READ permission
- Select Edit in the row for SSP_SUPPORT_STAFF
- Click the Choose Principals buttons
- In the right column named "Your Selections" hover SSP_SUPPORT_STAFF and click on the red icon with the dash symbol in the middle. This will remove the role from the list.
- Click the Submit button in the lower right corner when finished
- Confirm that the SSP_SUPPORT_STAFF role has been removed. If not, change the selection from Grant to Deny
- Choose the Manage Users link again from the top menu
- Repeat for PERSON_WRITE
Step 2: Add the PERSON_FILTERED permissions
- As an administrator, navigate to Manage Users -> Manage permissions
- Use Ctrl+F to find the "PERSON_FILTERED_READ" permission. Click it.
- Click on Add an Assignment
- Type in All Permissions in the entry box
- Click the Submit button
- Click the Choose Principals buttons
- Select SSP Roles in the Groups list
- Select SSP_SUPPORT_STAFF
- Click the green plus icon near the top to add the group to the Your Selection box on the right
- Click the Submit button in the lower right corner when finished
- Select grant for the SSP_SUPPORT_STAFF ENTRY
- Choose the Manage Users link again from the top menu
- Repeat for PERSON_FILTERED_WRITE
Step 3: Clear caches
- Log in to the application as a super user and expand the flyout menu in the top right and select "Platform Administration"
- Click "Manage Cache instances"
- Click "Empty All Caches"
- Click "Empty All Caches" (again)