Viewing roles in your AEB product
Depending on whether you manage users as an admin in the AEB product or manage AEB accounts as a tenant admin, the information on the roles differs slightly. Therefore, first select the use case that suits you best.
Am I a tenant admin?
- Roles you can assign as an admin for users (without an AEB account)
- Roles you can assign as a tenant admin for AEB accounts (with an AEB account)
Roles you can assign as an admin for users (without an AEB account)
You can view, define, and assign roles to users under User administration.
How do I assign roles for a user?
General roles can be used in any AEB product. Additional product-specific roles are also available for certain products. Both the general roles and the product-specific roles are pre-defined for you. If you want to use custom roles as well, you can define your own roles.
The links take you to an overview of roles specific to each product.
- Trade Compliance Management: Product-specific roles
- Carrier Connect: Product-specific roles
- Product Classification: Product-specific roles
Here you can find an overview of roles with the associated rights.
You cannot modify pre-defined roles. All pre-defined roles begin with “I_” to make it easy to distinguish them from the roles you define.
Name | Properties |
---|---|
I_BUSINESSFACADE | This role allows a host system to use APIs – that is, to interact with the application externally. It can only be assigned to a system-based user such as a WSM user. This user type is not allowed to have any other role besides I_BUSINESSFACADE. WSM user: AEB creates a user for the WebServiceManager (WSM) with this role by default when you use an AEB product through your host system. Please note: Using this role to edit a user name or password can corrupt the connection to an ERP system. Do you use other host systems that you would like to connect? |
I_CLIENTADMIN | Users with this role are client administrators. They can create users for the respective client and can assign and remove user roles. If no one in your company has this role yet, AEB Support can create it for you. |
I_CLIENTGROUPADMIN | If client groups have been set up in the system, this role grants rights that include configuring the display settings, managing user tips, or viewing the change history for these client groups. |
I_DDACCESSRIGHT | This role allows the configuration of data-related access rights. |
I_DEFAULTPREF | A user with this role defines default settings (column definitions for overviews, etc.). These settings apply to all users of the active client, as long as individual users do not overwrite them with personalized settings. |
I_EVERYONE | This role assigns the rights of a normal user. This role is included in every other pre-defined role. Every user whom you have not assigned any specific rights has all the rights of this role. This can later be expanded by the addition of other roles or rights or restricted by the removal of rights. |
I_READONLY | A user with this role may view various datasets but is not allowed to make any changes. For this reason, this role should be combined with the appropriate views from other roles so that the user has access but is blocked from making changes. This role makes sense for an auditor, for example. |
All other predefined roles with explanations can be found in the Office under User administration – Roles.
Roles you can assign as a tenant admin for AEB accounts (with an AEB account)
As a tenant admin, you can use the access management to assign roles for your AEB products and test systems to yourself and others.
The tenant admin role is a top-level role.
How do I create an additional tenant admin?
All other roles are system-specific and created by assigning system access rights.
How do I assign system access rights?
Basic roles can be used in any AEB product. Additional product-specific roles are also available for certain products. Both the basic roles and the product-specific roles are pre-defined for you. If you want to use custom roles as well, you can define your own roles.
The links take you to an overview of roles specific to each product.
- Trade Compliance Management: Product-specific roles
- Carrier Connect: Product-specific roles
- Product Classification: Product-specific roles
Here you can find an overview of basic roles with the associated rights.
Label | Rights |
---|---|
I_CLIENTADMIN | With the I_CLIENTADMIN role, you can create AEB accounts for other users within the selected system and assign and revoke roles. |
I_CLIENTGROUPADMIN | If client groups have been set up in the system, this role grants rights that include configuring the display settings, managing user tips, or viewing the change history for these client groups. |
I_DDACCESSRIGHT | This role allows the configuration of data-related access rights. |
I_DEFAULTPREF | A user with this role defines default settings (column definitions for overviews, etc.). These apply to all AEB accounts in the system unless overwritten with personalized settings. |
I_EVERYONE | This role assigns the rights for normal system usage. This role is included in every other pre-defined role. Everyone to whom you have not assigned any specific rights has all the rights of this role. This can later be expanded by the addition of other roles or rights or restricted by the removal of rights. |
I_READONLY | Someone with this role may view various datasets but is not allowed to make any changes. For this reason, this role should be combined with the appropriate views from other roles so that the user has access but is blocked from making changes. This role makes sense for an auditor, for example. |
I_BUSINESSFACADE | This role allows a host system to use APIs – that is, to interact with the application externally. It can only be assigned to a system-based user such as a WSM user. This user type is not allowed to have any other role besides I_BUSINESSFACADE. WSM user: AEB creates a user for the WebServiceManager (WSM) with this role by default when you use an AEB product through your host system. Please note: Using this role to edit a user name or password can corrupt the connection to an ERP system. Are you running other host systems that you wish to connect? |