BO 4.1环境下基于登录用户组隐藏/显示Universe维度的方法咨询
How to Hide/Show Dimensions Based on User Groups in BO 4.1 Universe A
Hey there, let's solve this BO 4.1 permission problem where you need to block TESTUSERS from accessing the SSN dimension in Universe A (while letting POWERUSERS see it). Since you don't know how Universe B was configured, here are two straightforward, reliable methods to achieve exactly what you need—making SSN completely unselectable for TESTUSERS when creating/editing reports:
Method 1: Set Object-Level Permissions Directly in the Universe (IDT/Universe Designer)
This method lets you configure granular control right within the Universe design tool:
- Open Universe A in Information Design Tool (IDT) (or Universe Designer if you're using a traditional .unv Universe).
- Locate the SSN dimension object in the Data Foundation or Business Layer.
- Right-click the SSN object and select Permissions (or Object Security, depending on your tool version).
- Click Add Principals and select the TESTUSERS group from the list.
- For TESTUSERS, set the View permission for this object to Deny (or "No Access"—this will prevent them from even seeing the object in the Universe panel in WebI).
- Repeat the process for the POWERUSERS group, ensuring their View permission is set to Allow (or Full Control for full access).
- Save your changes and republish Universe A to the BO server.
Method 2: Configure Permissions via the Central Management Console (CMC)
If you prefer managing permissions centrally through the CMC, this works just as well:
- Log into your BO 4.1 CMC.
- Navigate to Universes and find Universe A in the list.
- Right-click Universe A and select Permissions.
- Click Add Principals to add both TESTUSERS and POWERUSERS groups.
- For TESTUSERS, expand the Object Rights > Universe Objects section, locate the SSN object in the Universe's object hierarchy, and set its View permission to Deny.
- For POWERUSERS, confirm their View permission for SSN is set to Allow.
- Click Apply to save the permission changes.
Key Notes to Remember:
- Permission Priority: Deny permissions always override Allow permissions, so even if TESTUSERS inherit Allow access from a parent group, setting Deny on the SSN object will take precedence.
- Testing: After making changes, log in as a TESTUSERS member and try creating a WebI report using Universe A—you should not see the SSN dimension in the available objects list.
- Custom Access Levels: If you need this permission setup for multiple objects, consider creating a custom access level (e.g., "No SSN Access") in the CMC that restricts object view rights, then assign this level to TESTUSERS for Universe A.
内容的提问来源于stack exchange,提问作者Henrov
相关产品推荐
相关产品推荐

