This appendix summarizes the PeopleSoft-delivered security data and discusses:
Permission lists and roles cloned when creating sites.
Permission lists with special uses in PeopleSoft Enterprise Portal.
Roles.
User IDs.
Delivered PeopleTools roles.
Adding the portal user roles to all user IDs.
The following list provides an overview of important security information:
Every component, PeopleCode Web library, interface, registry item, and so on, specific to PeopleSoft Enterprise Portal is assigned to two permission lists. These permission lists are:
A system administer permission list in the form xxxx9000.
One of the feature-specific permission lists in the form xxxxNNNN.
Pagelet permission lists include the pagelet, the personalization, and usually the enhancement pages that are accessible from the pagelet.
PeopleSoft Enterprise Portal security for each feature is divided into three groups:
Administrator |
Feature implementation and set up. Highest security level. |
Manager |
Feature maintenance, distribution, and usage. Medium security level. |
User |
Feature access, viewing, and usage. Low security level. |
All logged on user IDs (except for the Guest user) must contain the roles PeopleSoft User and PAPP_USER.
The GUEST user ID must contain the roles PeopleSoft Guest and PAPP_GUEST.
The required roles (PAPP_USER, PAPP_GUEST, PeopleSoft User, and PeopleSoft Guest) contain specific permission lists that are necessary to access the base portal features.
You can adjust the roles to your needs, but you must keep the following permission lists on the specified role:
PTPT1000 is necessary to access the PeopleTools portal base features (included in the role PeopleSoft User).
PAPP0000 is necessary to access the PeopleSoft Enterprise Portal base features (included in the roles PAPP_USER and PAPP_GUEST).
PAPP0001 is necessary for the Guest tab (included in the role PAPP_GUEST).
PAPP0002 is necessary for the homepage Personalization (included in the role PAPP_USER).
Note. When enabling role grant security, you must include the roles PeopleSoft User and PAPP_USER. These roles are required for access to base portal functionality.
When you create sites, the system clones and uses special permission lists and roles on the site. This section describes:
Permission lists cloned when creating sites.
Roles cloned when creating sites.
When you create a site, the system clones and uses the following permission lists on the site content and folder definitions. The Installation Options page lists which permission lists to clone during site creation. These are delivered as PAPP5000, PAPP5060, PAPP5070. The generated permission lists are listed in the following table, where XXX represents the site name.
Permission List |
Description |
SITE_XXX_ADM |
Gives site-specific access for the site administrator to set navigation defaults, set security access to the site, and review and override Branding elements for the site. It is generated by cloning PAPP5000 during site creation. |
SITE_XXX_PUB |
Gives site-specific access for publishing menu items in the navigation of the site. It is generated by cloning PAPP5060 during site creation. |
SITE_XXX_VWR |
Gives site-specific access to view the site. It is generated by cloning PAPP5070 during site creation. |
When you create a site, the following roles are generated and assigned site-specific permission lists. These roles are attached to the appropriate user who is assigned security access to the site.
Role |
Description |
SITE_XXX_ADM |
Gives site-specific access for the site administrator to set navigation defaults, set security access to the site, and review and override Branding elements for the site. It contains the matching permission list SITE_XXX_ADM which is generated during site creation. |
SITE_XXX_PUB |
Gives site-specific access for publishing menu items in the navigation of the site. It contains the matching permission list SITE_XXX_PUB which is generated during site creation. |
SITE_XXX_VWR |
Gives site-specific access to view the site. It contains the matching permission list SITE_XXX_VWR which is generated during site creation. |
See Also
Permission Lists with Special Uses
This section describes:
Permission lists that have special meaning and usage in PeopleSoft Enterprise Portal.
All permissions delivered with PeopleSoft Enterprise Portal.
The following table describes permission lists that have special meaning and usage in PeopleSoft Enterprise Portal.
Permission List |
Description |
PAPP9000 |
Includes every delivered PeopleSoft Enterprise Portal object (excluding Pagelet Wizard and Resource Finder objects). This permission list is included in the role PAPP_SYSTEM_ADMIN. |
PAPX9000 |
Includes every delivered Resource Repository object. This permission list is included in the role PAPP_SYSTEM_ADMIN. |
PAPP0000 |
Required to access the PeopleSoft Enterprise Portal base features. This permission list is included in the roles PAPP_USER and PAPP_GUEST. |
PAPX0000 |
Required to access the Resource Repository base features. This permission list is included in the roles PAPP_USER and PAPP_GUEST. |
PAPP0001 |
Required for the Guest tab. This permission list is included in the role PAPP_GUEST. |
PAPP0002 |
Required for Personalize Content and Layout links on the homepage and the My Links feature in the portal header. This permission list is included in the role PAPP_USER. |
PTPT1000 |
Required to access the PeopleTools base portal features. This permission list is included in the PeopleTools role PeopleSoft User. |
PTPT1400 |
Required to access the PeopleTools base portal features for a guest user. This permission list is included in the PeopleTools role PeopleSoft Guest. |
The following table lists all permission lists delivered with PeopleSoft Enterprise Portal.
Permission List |
Description |
Usage |
PAPP0000 |
Base PeopleSoft Enterprise Portal objects. |
Base access to navigation and template iScripts (Web Libraries), Search Results pages, template pagelets (Content Ratings, Related Information, Related Contacts, Related Discussions), Browse Content pages, common Content Management pages (hidden dynamic navigation pages, and content rendering pages), file attachment viewer pages, and the Language Selection pagelet. Required access for all users, including Guest. |
PAPP0001 |
Base Guest objects. |
Access the homepage tab Guest page and the Signon pagelet. Required access for the Guest user. |
PAPP0002 |
Logged in user access. |
Access the homepage Personalize Content and Layout pages, and My Links edit pages. Required access for all users, except Guest. |
PAPP0010 |
PeopleTools Notification. |
Access the email notification pages from the PeopleTools Notify button. |
PAPP1000 |
External News pagelets. |
Access the integrated External News feed and RSS News pagelets. |
PAPP1100 |
Company News pagelets. |
Access the News Publication pagelets, pagelet personalization, and pagelet enhancement pages for viewing sections and published articles. |
PAPP1110 |
Company Promotions pagelet. |
Access the Company Promotions pagelet and pagelet personalization. |
PAPP1120 |
Web Magazine pagelet. |
Access the Web Magazine pagelet and Web Magazine viewing. |
PAPP1130 |
Promotions by Role pagelet. |
Access the Promotions by Role pagelet. To access the results page, roles with this permission list must also include permission list PAPP2030 (Manage Company Promotions). |
PAPP1140 |
Workgroup Content pagelet. |
Access the Workgroup Content pagelet and pagelet personalization pages. To access the links on this pagelet, roles with this permission list must also include permission list PAPP2010 (Access Content Management). |
PAPP1150 |
News Article Inbox pagelet. |
Access the News Article Inbox pagelet. To access the links on this pagelet, roles with this permission list must also include permission list PAPP2020 (Access News Publications). |
PAPP1160 |
Submitted Promotions pagelet. |
Access the Submitted Promotions pagelet. To access the links on this pagelet, roles with this permission list must also include permission list PAPP4110 (Submit Promotion Items). |
PAPP1200 |
Tasks pagelet. |
Access the Integrated Task List pagelet, pagelet personalization, pagelet enhancement pages, and to the PeopleTools Worklist and Worklist Details pages. |
PAPP1300 |
Email/Calendar pagelets. |
Access the Email and Calendar pagelets and pagelet personalization pages. |
PAPP1500 |
Internet Information pagelets. |
Access the Internet HTML pagelets and associated component interfaces and Web libraries, for example, weather. |
PAPP1600 |
Saved Searches pagelets. |
Access the Saved Searches pagelets, pagelet personalization, and pagelet enhancement Search Results pages. |
PAPP2010 |
Access content management. |
Access the hierarchy, content, and folder definitions. Access to each category is restricted via privilege sets. This permission list is for general page access. |
PAPP2020 |
Manage news publications. |
Publish and unpublish articles. Choose top stories. Note. To access the pages for viewing and editing news content, roles with this permission list must also include permission list PAPP2010 (Access Content Management). |
PAPP2025 |
Administer Company News content. |
Administer News Publication articles and images. These pages allow the user to delete, add, and update news articles and images, ignoring the privilege set or status of the content. This permission list should only be granted to high-level content administrators. To access the pages for viewing and editing news content, roles with this permission list must also include permission list PAPP2010 (Access Content Management). |
PAPP2030 |
Manage Company Promotions. |
Manage Company Promotions by publishing submitted promotions, and inquiring on viewer roles assigned to Company Promotion items. |
PAPP2035 |
Administer Company Promotions. |
Administer Company Promotions by creating and updating promotion targets and categories. |
PAPP2040 |
Manage Categorized Content. |
Unpublish spider content. |
PAPP2045 |
Administer Categorized Content. |
Run the Categorization Spider process to pull categories and content into the Categorized Content feature. |
PAPP2050 |
Administer Content Management. |
Administer Managed Content by assigning top category administrators, creating privilege sets, assigning viewer roles, and defining attachment locations. This permission list should only be granted to high-level content administrators. |
PAPP2070 |
Review Content Access/Location. |
Review Content stored in the Content Management system. The inquiry lists where the content can be accessed, who can access the content, and a preview of the content for users who are viewing members for this content. Get the content's rendering URL for use in third-party. |
PAPP2080 |
Content queries. |
Access to PeopleSoft Query and to the tables and views on the content branch of the QUERY_TREE_PAPP tree. |
PAPP2300 |
Administer External News. |
Administer External News by creating and updating External News publication pagelets, providers, groups, categories, articles, and news feed batch process. |
PAPP2310 |
Manage External News. |
Manage External News by changing the publish and expire dates of news feed articles to remove offensive articles. |
PAPP2700 |
Administer Web Magazine. |
Administer Web Magazine by creating and updating Web Magazine publications, issues, sections, categories, images, and articles. |
PAPP2800 |
Administer Integrated Tasks. |
Administer the Integrated Task pagelet by access to the PeopleTools Worklist, Worklist Details, and Worklist administration pages. |
PAPP3100 |
Administer Weather pagelet. |
Administer Weather pagelet by getting a customer ID or running the Update City List process. |
PAPP3200 |
Administer HTML pagelets. |
Administer HTML pagelets by creating and registering HTML pagelets. |
PAPP3300 |
Administer Email/Calendar pagelet. |
Administer the Email and Calendar pagelets by defining the email and calendar system and user values. |
PAPP3550 |
Administer integration content. |
Component Interface access to integrate external content into the Content Management system (Web Services). |
PAPP3560 |
Administer integration workspaces. |
Placeholder for Collaborative Workspaces Integration Administration. |
PAPP4000 |
Inquire portal registry. |
Access the Portal Registry Inquiry pages for registry structure, inquiry, and item detail. |
PAPP4001 |
Run portal registry processes. |
Access the run control pages for the following processes: Registry Load and Enterprise Components Integration Rules, Menu Import, and Portal Permission Sync. |
PAPP4002 |
Manage homepage tabs. |
Access the Structure and Content pages with edit access for homepage tabs, and display only for other pages. |
PAPP4003 |
Set portal default templates. |
Access the PeopleTools General Settings page for setting site and node template defaults. |
PAPP4004 |
Run processes. |
Access to Process Monitor and the delivered process groups. Use as the process profile permission list on the User Profile definition page. |
PAPP4010 |
Administer pagelet personalization. |
Administer pagelet Personalization by setting the user (any user in the system) preference for given pagelets. |
PAPP4020 |
Manage Menu Item requests. |
Manage Menu Item requests by approving or rejecting requests, and defining the users notified by email for submitted requests. |
PAPP4025 |
Administer Menu Item requests. |
Administer Menu Item requests by approving or rejecting requests, registering approved requests, and defining the users notified by email for submitted requests. |
PAPP4050 |
Administer portal Search. |
Administer portal Search by defining the Search Collections associated with portal Search results pages. |
PAPP4080 |
Navigation queries. |
Access to PeopleSoft Query and to the tables and views on the navigation branch of the QUERY_TREE_PAPP tree. |
PAPP4100 |
Submit Menu Item requests. |
Submit Menu Item requests. |
PAPP4110 |
Submit promotion items. |
Submit Company Promotion items. |
PAPP4120 |
Submit news articles. |
Access the Submit News Articles pages. |
PAPP4200 |
Logon Statistics pagelet. |
Access the Logon Statistics pagelet. |
PAPP4300 |
Manage Content Ratings. |
Manage Content Ratings by creating questions, assigning menu items, and viewing the results. |
PAPP4350 |
Administer Content Ratings. |
Administer Content Ratings using the advanced settings and assigning result viewers. |
PAPP4400 |
Access Account Signon Utility. |
Access the Account Signon Utility by updating the stored user ID and password. |
PAPP4450 |
Administer Account Signon Utility. |
Administer the Account Signon Utility by creating the Sign On forms and URLs to access external secured sites. |
PAPP4500 |
Administer portal options. |
Define installation, system, and registry options. |
PAPP4600 |
Administer context assignment. |
Administer Context Manager by assigning the default template pagelets as well as the individual template pagelets to a specified Menu Item. |
PAPP4680 |
Context queries. |
Access to PeopleSoft Query and to the tables and views on the context branch of the QUERY_TREE_PAPP tree. |
PAPP4700 |
Manage Related Content. |
Manage Related Content by adding Related Content online to Menu Items that are assigned a Related Content template pagelet. This permission list is for general page access. Access to add content to a Menu Item/Related Content publication combination is restricted via assigned Topic Experts as well as access to the Menu Item in the navigation. |
PAPP4710 |
Inquire Related Content. |
Access the Related Content Inquiry Pages listing content according to the assigned Topic Expert or the Menu Item. |
PAPP4750 |
Administer Related Content. |
Administer Related Content by creating or updating Related Content Publications and assigning the Topic Experts to add the content. |
PAPP4800 |
Discussion pagelet. |
Access the Discussion Forum pagelet and pagelet Personalization. |
PAPP4850 |
Administer Discussion pagelet. |
Administer the Discussion Forum pagelet by creating groups, assigning moderators and viewer roles. |
PAPP4855 |
Administer Related Discussions. |
Administer Related Discussions template pagelet by assigning moderators. |
PAPP4910 |
Define pagelets with the Wizard. |
Create Pagelet Wizard pagelets, and delete and clone pagelet definitions. |
PAPP4920 |
Define Pagelet Wizard data. |
Create and update Pagelet Wizard footers, headers, and categories and review existing pagelet definitions. |
PAPP4950 |
Administer Pagelet Wizard |
Create and update Pagelet Wizard data types, display formats, transform types, and pagelet XSL. Publish pagelets to additional sites. Create Data Mover scripts to export and import pagelet definitions. |
PAPP5000 |
Administer Site - Template. |
Template permission list to administer a created portal site by setting site navigation defaults, setting site security assignments, viewing Branding queries, and overriding allowable Branding elements on a created site. |
PAPP5050 |
Create sites. Allow overrides. |
Create portal sites and assign allowed Branding overrides using the Site Wizard. |
PAPP5060 |
Manage Navigation - Template. |
Template permission list to manage a site navigation by publishing Menu Items to the site, as well as updating the Content Management IDs used in an existing Workgroup pagelet created by Pagelet Wizard. |
PAPP5070 |
View Created Site - Template. |
Template permission list to view a created portal site. |
PAPP5100 |
Maintain Branding roles. |
Assign security roles to Branding themes. |
PAPP5150 |
Maintain Branding data. |
Create and maintain Branding themes, headers, and footers. |
PAPP5160 |
Maintain Branding layouts. |
Create and maintain Branding layouts. |
PAPP5180 |
Branding queries. |
Access to PeopleSoft Query and to the tables and views on the Branding branch of the QUERY_TREE_PAPP tree. Also access the Branding query links in the navigation menu. |
PAPP5200 |
Manage Navigation Collections. |
Create and update Navigation Collections. (No delete) |
PAPP5250 |
Administer Navigation Collections. |
Create, delete, and update Navigation Collections. |
PAPP5300 |
Use Workspaces. |
Access to created Collaborative Workspaces including links, members, search, and browsing workspaces. Roles with this permission list should also include permission list PAPP2010 (Access Content Management) and permission list PAPP4800 (Access Discussion Forum). |
PAPP5350 |
Create/Administer Workspaces. |
Create and administer Collaborative Workspaces including privilege sets, templates, and homepage tab layout. |
PAPP5360 |
Manage Workspaces. |
Manage created Collaborative Workspaces including workspace categories. |
PAPP5450 |
Administer Alerts. |
Administer Alerts Notifications including the Notification batch process, and defining features, email options, and alert subscriptions. |
PAPP9000 |
All PeopleSoft Enterprise Portal objects. |
Access to all PeopleSoft Enterprise Portal objects, excluding Pagelet Wizard and Resource Finder. |
PAPP9900 |
System setup data. |
Access to the pages displaying system data that should not be changed or customized. |
PAPP9999 |
Demo examples and testing. |
Access to delivered demo, testing, and SDK material. |
PAPX0000 |
Base Repository objects. |
Base access to Resource Finder profile display and the Related Resources template pagelets. Required access for all users, including Guest. |
PAPX1000 |
Resource Finder pagelet. |
Access the Resource Finder pagelet and pagelet enhancement Search Results pages. |
PAPX2050 |
Manage Resource profiles. |
Manage Resource profiles by updating or creating a profile definition (create an Employee profile type). |
PAPX2060 |
Administer Repository. |
Administer Resource Finder Repository by creating profile attributes or entering a profile not obtained from a feed. |
PAPX2070 |
Administer Repository Search. |
Administer Resource Finder Repository Search Collections. |
PAPX9000 |
All Repository objects. |
Access to all Resource Finder Repository objects. |
PAPX9999 |
Demo examples and testing. |
Testing Resource Finder application classes. |
This section describes:
Roles that have special usage in PeopleSoft Enterprise Portal.
Roles associated with major PeopleSoft Enterprise Portal areas.
Viewer roles.
All delivered roles.
The following table lists roles that have special meaning and usage in PeopleSoft Enterprise Portal.
Role |
Description/Usage |
PAPP_USER |
Must be assigned to every user ID, except the default signon user ID GUEST. |
PeopleSoft User |
Must be assigned to every user ID, except the default signon user ID GUEST. |
PAPP_GUEST |
Must be assigned to the default signon user ID GUEST. |
PeopleSoft Guest |
Must be assigned to the default signon user ID GUEST. |
PAPP_SYSTEM_ADMIN |
Used only during installation and implementation and is assigned to VP1 and PS. |
PeopleSoft Administrator |
Used only during installation and implementation and is assigned to VP1 and PS. It gives access into all the pages regardless of the user's assigned permission lists. |
Portal Administrator |
Used in the production system. It gives access to the portal registry structure (content references and folder references), but not the actual component/pages and pagelets. Be aware that users who have this role will see all pagelets and all menu items (all content references), but they may not be able to access the actual pages. If a user with this role attempts to access a pagelet or a page where they do not have that pagelet or pages's security, a "You are not authorized" error message displays. |
The major areas within PeopleSoft Enterprise Portal are associated with roles. These areas and roles contain overlap. The major areas and roles are shown in the following table.
Area |
Role |
Description |
Content |
PAPP_CONTENT_ADMIN |
Administer internally-created and external content, including External News, Internal News, Context Manager and Content Management. |
Navigation |
PAPP_NAVIGATION_ADMIN |
Administer how users navigate the portal sites, including Menu Items requests, manage navigation, Portal Registry Load, and Navigation Collections. Users who have this role should also have the role of Portal Administrator. |
Portal sites |
PAPP_PORTAL_ADMIN |
Administer the portal and portal sites, including install options, site creation, Logon Statistics, Search, Menu Items requests, manage navigation, Portal Registry Load, Navigation Collections, Collaborative Workspaces, Branding, Account Signon Utility, pagelet Personalization, and Context Manager. Users who have this role should also have the role of Portal Administrator. |
Presentation |
PAPP_DISPLAY_ADMIN |
Administer the presentation of portal sites, including Branding, Pagelet Wizard headers/footers, default templates, and homepage tab layouts. |
Resource Finder |
PAPX_REPOSITORY_ADMIN |
Administer the Resource Finder Repository feature. |
Security |
PAPP_SECURITY_ADMIN |
Administer portal row-level security, including Manage Content privilege sets, Viewer roles, Related Context topic experts, Discussion moderators, pagelet Personalization, and Menu Item Inquiry. Users who have this role may also have the role of Security Administrator. |
Integration |
PAPP_INTEGRATION_ADMIN |
Administer integration content in the enterprise portal, including external content, Internet content, email, account signon utility, and Pagelet Wizard. |
The following roles are delivered as viewer roles, and are used by Content Management to secure individual content items for viewing. To change which roles are designated as viewer roles, select Portal Administration, Content, Viewer Roles.
Role |
Usage / Long Description |
PAPP_CUSTOMER |
Access to applicable customer homepage pagelets and assigned content viewing. |
PAPP_EMPLOYEE |
Access to applicable employee homepage pagelets, assigned content viewing, submit pages (promotions, articles, menu items), and edit account signon information. |
PAPP_GUEST |
Access to applicable Guest homepage pagelets, assigned content viewing, Guest homepage tab, and base PeopleSoft Enterprise Portal access. |
PAPP_SUPPLIER |
Access to applicable supplier homepage pagelets and assigned content viewing. |
The following table lists the roles delivered with PeopleSoft Enterprise Portal.
Role |
Description |
Usage/Long Description |
PAPP_ACCOUNT_SIGNON_ADMIN |
Account signon administrator. |
Administer the User Account Signon Utility. |
PAPP_AUTHOR |
Content author. |
Access the submit pages for News, Promotions, and Menu Items. Access Content Management common pages, where the privilege sets limit the access. |
PAPP_BRANDING_ADMIN |
Branding administrator. |
Administer the Branding feature. |
PAPP_COMPANY_PROMOTIONS_ADMIN |
Company Promotions administrator. |
Administer the Company Promotions feature. |
PAPP_CONTCATG_ADMIN |
Content Categorization administration. |
Administer the Content Categorization feature manually. |
PAPP_CONTENT_ADMIN |
Content administrator. |
Administer internally created and external content, including External News, Internal News, Context Manager and Content Management. |
PAPP_CONTENT_MANAGER |
Content Manager. |
Manage internally created and external content, including External News, Internal News, Context Manager and Content Management. |
PAPP_CONTENT_RATINGS_ADMIN |
Content Ratings administrator. |
Administer the Content Ratings related context feature. |
PAPP_CONTENT_USER |
Content Management user. |
Access Content Management common pages, where assigned privilege sets limit the access. Access the Managed Content pagelet, the News Article In-Box pagelet, and the Submit News Article page. Use this role as a general access role, then create additional roles to assign to the privilege sets within each created category. |
PAPP_CONTEXT_ADMIN |
Related Context administrator. |
Administer the Context Manager feature including the contextual content. |
PAPP_CONTEXT_MANAGER |
Related Context Manager. |
Manage the contextual content used with the Context Manager feature. |
PAPP_CUSTOMER |
Portal Customer. |
Access to applicable Customer homepage pagelets and assigned content viewing. |
PAPP_DEMO_ADMIN |
Demo/Test Items administrator. |
Sample. Administer the sample features, including the Demo Item pagelet and Context Manager Item tester. |
PAPP_DISCUSSIONS_ADMIN |
Discussions administrator. |
Administer Related Discussions and the Discussions Forum feature. |
PAPP_DISPLAY_ADMIN |
Presentation administrator. |
Administer the presentation of the portal sites, including Branding, Pagelet Wizard headers/footers, default templates, and homepage tabs layout. |
PAPP_EMAIL_CALENDAR_ADMIN |
Email / Calendar administrator. |
Administer the Email and Calendar pagelets. |
PAPP_EMPLOYEE |
Portal employee. |
Access to applicable employee homepage pagelets, assigned content viewing, submit pages (Promotions, Articles, Menu Items), find a resource, and edit account signon information. |
PAPP_EXTERNAL_NEWS_ADMIN |
External News administrator. |
Administer the External News pagelet. |
PAPP_GUEST |
Guest user access. |
Access to applicable Guest homepage pagelets, assigned content viewing, Guest homepage tab, and base PeopleSoft Enterprise Portal access. |
PAPP_GUEST_ADMIN |
Guest user administrator. |
Administer pagelet Personalization for a Guest user, or any user, and access the Guest homepage tab. |
PAPP_INSTALL_OPTIONS_ADMIN |
Install options administrator. |
Administer the Install Options for the PeopleSoft Enterprise Portal features. |
PAPP_INTEGRATED_TASKS_ADMIN |
Integrated tasks administrator. |
Administer the Tasks pagelet. |
PAPP_INTEGRATION_ADMIN |
Integration administrator. |
Administer integration content in the PeopleSoft Enterprise Portal, including External Content, Internet Content, Email, Account Signon Utility, and Pagelet Wizard. |
PAPP_INTERNET_PAGELETS_ADMIN |
Internet pagelets administrator. |
Administer Internet pagelets. |
PAPP_LDAP |
LDAP default access. |
Contains the required permission lists needed to access the Portal Solutions database. Use as the default role for LDAP access. |
PAPP_LOGON_STATISTICS_ADMIN |
Logon statistics administrator. |
Review user logon statistics through the User Logon Statistics pagelet. |
PAPP_NAVIGATION_ADMIN |
Navigation administrator. |
Administer how users navigate the portal, including, Menu Items requests, Portal Registry Load, and Navigation Collections. Users who have this role should also have the Portal Administrator role. |
PAPP_NAVIGATION_MANAGER |
Navigation manager. |
Manage submitted menu items and Navigation Collections. |
PAPP_NEWS_PUBLICATIONS_ADMIN |
News Publication administrator. |
Administer the Content Management News Publication feature. |
PAPP_PAGELET_ADMIN |
Pagelet administrator. |
Administer the creation of pagelets using pagelet wizard. Administer Navigation Collections. Administer Integration pagelets. Assign user pagelet personalization. Users who have this role should also have the Portal Administrator role and the Pagelet User role. |
PAPP_PAGELET_USER |
Pagelet access user. |
Access the homepage pagelets. To configure the layout of a homepage tab, the user must be either assigned the Portal Administrator role, or the user must have access to PAPP4002 as well as all of the homepage pagelet permission lists on the homepage tab. |
PAPP_PORTAL_ADMIN |
Portal administrator. |
Administer the portal and portal sites, including install options, site creation, Logon Statistics, Search, Menu Items requests, navigation collections, Portal Registry Load, Branding, Account Signon Utility, pagelet Personalization, alerts and Context Manager. Users who have this role should also have the Portal Administrator role. |
PAPP_PUBLISHER |
Content publisher. |
Manage, review, and publish content to a viewing audience in the New Publications and Company Promotions features. |
PAPP_RELATED_CONTENT_ADMIN |
Related Content administrator. |
Administer features of Context Manager. |
PAPP_SEARCH_ADMIN |
Search administrator. |
Administer the portal Search feature. |
PAPP_SECURITY_ADMIN |
Security administrator. |
Administer portal row-level security, including Managed Content privilege sets, viewer roles, related context topic experts, Discussion moderators, pagelet Personalization, and Menu Item inquiry. Users who have this role may also have the Security Administrator role. |
PAPP_SITE_MGMT_ADMIN |
Site Management administrator. |
Administer the Site Management feature, including creating sites and site Branding. Users who have this role should also have the Portal Administrator role. |
PAPP_SUPPLIER |
Portal supplier. |
Access to applicable supplier homepage pagelets and assigned content viewing. |
PAPP_SYSTEM_ADMIN |
PeopleSoft Enterprise Portal system administrator. |
Access to all PeopleSoft Enterprise Portal objects. |
PAPP_USER |
PeopleSoft Enterprise Portal user. |
Access the base objects in the PeopleSoft Enterprise Portal. Every user in the system, other than Guest, must be assigned this role along with the PeopleSoft User role. |
PAPP_WEB_MAGAZINE_ADMIN |
Web Magazine administrator. |
Administer the Web Magazine pagelet and content. |
PAPP_WORKSPACE_ADMIN |
Workspace Administrator. |
Administer and create collaborative workspaces. |
PAPP_WORKSPACE_MANAGER |
Workspace Manager. |
Manage collaborative workspaces. |
PAPP_WORKSPACE_USER |
Workspace User. |
Access the Collaborative workspace components. Individual workspaces are also secured by members to that workspace. |
PAPX_PROFILE_MANAGER |
Resource profile manager. |
Manage the Resource Finder profiles. |
PAPX_REPOSITORY_ADMIN |
Repository administrator. |
Administer the PeopleSoft Enterprise Resource Finder feature. |
PAPX_SEARCH_ADMIN |
Profile Search administrator. |
Administer the Resource Profile Search. |
You can obtain this information online, including any security fixes, by using the delivered PeopleSoft Query PAPP_SECURITY_ROLE_PERM.
This section discusses:
User IDs with special uses in PeopleSoft Enterprise Portal.
User IDs delivered with PeopleSoft Enterprise Portal.
The following table lists user IDs with special uses in PeopleSoft Enterprise Portal.
User ID |
Description |
GUEST |
The default signon user. |
PS |
The system administrator to access all of the PeopleSoft Enterprise Portal database and the HRMS database. |
VP1 |
The system administrator to access all of the PeopleSoft Enterprise Portal database and the FSCM, EPM, and CRM databases. |
The following table shows the delivered PeopleTools roles and their associated permission lists.
PeopleTools Role |
PeopleTools Permission List |
Permission List Description |
PeopleSoft User |
PTPT1000 |
PeopleSoft-User. |
PeopleSoft Guest |
PTPT1400 |
PeopleSoft-Guest. |
Security Administrator |
PTPT1100 |
Maintain Security. |
PeopleTools |
PTPT1200 |
PeopleTools. |
PeopleSoft Administrator |
**special** |
Behind-the-scenes coding. |
Portal Administrator |
PTPT1300 |
Behind-the-scenes to PeopleSoft Enterprise Portal. |
Portal Manager |
PTPT1600 |
Pagelet Wizard, Navigation Collections. |
To navigate and use common features and pages, every user ID (except for the Guest user IDs) must include the delivered roles PAPP_USER and PeopleSoft User. During a PeopleTools upgrade, the role PeopleSoft User is added to all existing roles. You can update the existing user IDs to include the PAPP_USER role with the delivered PeopleSoft Data Mover script PORTAL_ADD_ROLE.DMS.
Note. Every newly created user ID should include both roles PeopleSoft User and PAPP_USER. Guest user IDs should not include these roles. After running the script, manually update the Guest user ID by replacing the PeopleSoft User role and the PAPP_USER role with the PeopleSoft Guest role and the PAPP_GUEST role.
Use PeopleSoft Data Mover to update the existing user IDs in PeopleSoft Enterprise Portal to include the necessary PAPP_USER role.
There are two ways to start PeopleSoft Data Mover:
Using the Data Mover shortcut in your PeopleSoft program group, as in Start, Programs, <PeopleSoft Group>, Data Mover.
This access method only applies to the Windows Development Environment.
Using the command line interface.
This executes PeopleSoft Data Mover in a console for Windows and a Telnet session for UNIX.
To update the user IDs:
Start PeopleSoft Data Mover and sign on to the PeopleSoft Enterprise Portal database.
Open the script PORTAL_ADD_ROLE.DMS in the <PS_HOME>\scripts directory.
Run the script against the PeopleSoft Enterprise Portal database.
Close PeopleSoft Data Mover.
See Also
Enterprise PeopleTools 8.46 PeopleBook: Data Management, “Using PeopleSoft Data Mover”