This appendix summarizes the PeopleSoft-delivered security data and discusses:
Permission lists and roles cloned when creating sites.
Permission lists with special uses in PeopleSoft Enterprise Portal.
Roles.
User IDs.
Delivered PeopleTools roles.
Adding the portal user roles to all user IDs.
The following list provides an overview of important security information:
Every component, PeopleCode Web library, interface, registry item, and so on, specific to PeopleSoft Enterprise Portal is assigned to two permission lists. These permission lists are:
A system administer permission list in the form xxxx9000.
One of the feature-specific permission lists in the form xxxxNNNN.
Pagelet permission lists include the pagelet, the personalization, and usually the enhancement pages that are accessible from the pagelet.
PeopleSoft Enterprise Portal security for each feature is divided into three groups:
Administrator |
Feature implementation and set up. Highest security level. |
Manager |
Feature maintenance, distribution, and usage. Medium security level. |
User |
Feature access, viewing, and usage. Low security level. |
All logged on user IDs (except for the Guest user) must contain the roles PeopleSoft User and PAPP_USER, or a cloned version of the roles.
The GUEST user ID must contain the roles PeopleSoft Guest and PAPP_GUEST, or a cloned version of the roles.
The required roles (PAPP_USER, PAPP_GUEST, PeopleSoft User, and PeopleSoft Guest) contain specific permission lists that are necessary to access the base portal features.
You can adjust cloned roles to as needed, but you must keep the following permission lists on the specified role:
PTPT1000 is necessary to access the PeopleTools portal base features (included in the role PeopleSoft User).
PAPP0000 is necessary to access the PeopleSoft Enterprise Portal base features (included in the roles PAPP_USER and PAPP_GUEST).
PAPP0001 is necessary for the Guest tab (included in the role PAPP_GUEST).
PAPP0002 is necessary for the homepage Personalization (included in the role PAPP_USER).
Note. When enabling role grant security, you must include the roles PeopleSoft User and PAPP_USER. These roles are required for access to base portal functionality.
When you create sites, the system clones and uses special permission lists and roles on the site. This section describes:
Permission lists cloned when creating sites.
Roles cloned when creating sites.
When you create a site, the system clones and uses the following permission lists on the site content and folder definitions. The Installation Options page lists which permission lists to clone during site creation. These are delivered as PAPP5000, PAPP5060, PAPP5070. The generated permission lists are listed in the following table, where XXX represents the site name.
Permission List |
Description |
SITE_XXX_ADM |
Gives site-specific access for the site administrator to set navigation defaults, set security access to the site, and review and override Branding elements for the site. It is generated by cloning PAPP5000 during site creation. |
SITE_XXX_PUB |
Gives site-specific access for publishing menu items in the navigation of the site. It is generated by cloning PAPP5060 during site creation. |
SITE_XXX_VWR |
Gives site-specific access to view the site. It is generated by cloning PAPP5070 during site creation. |
When you create a site, the following roles are generated and assigned site-specific permission lists. These roles are attached to the appropriate user who is assigned security access to the site.
Role |
Description |
SITE_XXX_ADM |
Gives site-specific access for the site administrator to set navigation defaults, set security access to the site, and review and override Branding elements for the site. It contains the matching permission list SITE_XXX_ADM which is generated during site creation. |
SITE_XXX_PUB |
Gives site-specific access for publishing menu items in the navigation of the site. It contains the matching permission list SITE_XXX_PUB which is generated during site creation. |
SITE_XXX_VWR |
Gives site-specific access to view the site. It contains the matching permission list SITE_XXX_VWR which is generated during site creation. |
See Also
Permission Lists with Special Uses
This section describes:
Permission lists that have special meaning and usage in PeopleSoft Enterprise Portal.
All permissions delivered with PeopleSoft Enterprise Portal.
The following table describes permission lists that have special meaning and usage in PeopleSoft Enterprise Portal.
Permission List |
Description |
PAPP9000 |
Includes every delivered PeopleSoft Enterprise Portal object (excluding Pagelet Wizard and Resource Finder objects). This permission list is included in the role PAPP_SYSTEM_ADMIN. |
PAPX9000 |
Includes every delivered Resource Repository object. This permission list is included in the role PAPP_SYSTEM_ADMIN. |
PAPP0000 |
Required to access the PeopleSoft Enterprise Portal base features. This permission list is included in the roles PAPP_USER and PAPP_GUEST. |
PAPX0000 |
Required to access the Resource Repository base features. This permission list is included in the roles PAPP_USER and PAPP_GUEST. |
PAPP0001 |
Required for the Guest tab. This permission list is included in the role PAPP_GUEST. |
PAPP0002 |
Required for Personalize Content and Layout links on the homepage and the My Links feature in the portal header. This permission list is included in the role PAPP_USER. |
PAPInnnn |
Required for Investor Portal objects that are in the Enterprise Portal database. These permission lists are used to secure the Investor homepage tab and Investor homepage pagelets to users who are identified as Investor Portal users. The permission lists also grant access to the components under the Investor Portal top level folder in the left navigation menu. |
PAPQnnnn |
Required for access to Internal Controls Enforcer Portal items in the left navigation and for access to Internal Controls Enforcer pagelets. |
PAPJnnnn |
Required for access to EnterpriseOne applications from the Enterprise Portal. |
PTPT1000 |
Required to access the PeopleTools base portal features. This permission list is included in the PeopleTools role PeopleSoft User. If you use a cloned version of this permission list, make sure to retain the needed iScripts and component interfaces security required to access the portal and end-user base access items, such as changing a password. |
PTPT1400 |
Required to access the PeopleTools base portal features for a guest user. This permission list is included in the PeopleTools role PeopleSoft Guest. |
The following table lists all permission lists delivered with PeopleSoft Enterprise Portal.
Permission List |
Description |
Usage |
PAPP0000 |
Base PeopleSoft Enterprise Portal objects. |
Base access to the navigation and template iScripts (Web Libraries), portal search results page, Take a Survey page, Workspace error access page, Site Manager error access page, template pagelets (Content Ratings, Related Information, Related Contacts), menu item file attachment viewer pages, and the Language Selection pagelet. Note: This permission list is required for all users, including GUEST. |
PAPP0001 |
Base Guest objects. |
Access the homepage tab Guest Page and the Sign On pagelet. Note. This permission list is required for the GUEST user. |
PAPP0002 |
Logged in user access. |
Access the homepage Personalize Content and Layout pages, and My Links pages, the user profile pages, and the Related Discussion Template pagelet. Required access for all users, except Guest. |
PAPP0010 |
PeopleTools Notification. |
Access the email notification pages from the PeopleTools Notify button. |
PAPP1000 |
External News pagelets. |
Access the integrated External News feed and RSS News pagelets. |
PAPP1100 |
Company News pagelets. |
Access the News Publication pagelets, pagelet personalization, and pagelet enhancement pages for viewing sections and published articles. |
PAPP1110 |
Company Promotions pagelet. |
Access the Company Promotions pagelet and pagelet personalization. |
PAPP1120 |
Web Magazine pagelet. |
Access the Web Magazine pagelet and Web Magazine viewing. |
PAPP1130 |
Promotions by Role pagelet. |
Access the Promotions by Role pagelet. To access the results page, roles with this permission list must also include permission list PAPP2030 (Manage Company Promotions). |
PAPP1140 |
My Managed Content Pagelet |
Access the My Managed Content pagelet and pagelet personalization. Note. To access the links on this pagelet, roles with this permission list must also include permission list PAPP2010 (Access Content Management). |
PAPP1150 |
My News Content Pagelet |
Access the My News Content pagelet. Note. To access the links on this pagelet, roles with this permission list must also permission list PAPP2010 (Access Content Management). To access the Review for Publishing link, roles with this permission link must also include permission list PAPP2020 (Publish News Articles). |
PAPP1160 |
Submitted Promotions pagelet. |
Access the Submitted Promotions pagelet. To access the links on this pagelet, roles with this permission list must also include permission list PAPP4110 (Submit Promotion Items). |
PAPP1170 |
Poll Pagelet |
Access published Poll pagelets to respond to the current poll question. Note. Users must be included in the Poll definition's respondent roles to respond or view any given poll. Users do not need member privileges or access to the Poll definition in order to respond to a poll question. |
PAPP1200 |
Tasks pagelet. |
Access the Integrated Task List pagelet, pagelet personalization, pagelet enhancement pages, and to the PeopleTools Worklist and Worklist Details pages. Note. To access links for action items, roles with this permission list must also include permission list PAPP5600 (Access Action Items). |
PAPP1210 |
View Community Calendars |
View Community Calendars in display-only mode. Access the Community Calendar search results page. Calendar access is restricted by member privileges on the Calendar definition. Note. This permission list is required to view the links on the Pagelet Wizard generated Community Calendar pagelets. |
PAPP1300 |
Email/Calendar pagelets. |
Access the Email and Calendar pagelets and pagelet personalization pages. |
PAPP1500 |
Internet Information pagelets. |
Access the Internet HTML pagelets and associated component interfaces and web libraries, for example, weather, stocks, and dictionary. |
PAPP1600 |
Saved Searches pagelets. |
Access the Saved Searches pagelets, pagelet personalization, and pagelet enhancement Search Results pages. |
PAPP2000 |
Access Published Content |
Access the Content Management published content viewer pages, hierarchy viewer pages, and Browse by Category viewer pages. Content and folder access is restricted by member privileges on the Folder definition, or content viewer roles on the Content definition, or folder viewer roles on the Folder definition. Note. This permission list is needed for all users when Content Management folders and content items are published as menu items in the left navigation or published as pagelets or available from the portal search. |
PAPP2010 |
Access content management. |
Access the hierarchy management pages, hierarchy search pages, content definition pages, folder definition pages, the My Content Status pages, and the content web services. Content Management access and actions are restricted by member privileges on the Folder definition, or to users listed as Top Administrators for the Content Management feature. |
PAPP2020 |
Publish News Articles |
Access the News Publications Publish Articles page, the Unpublish Articles page, and the Choose Top Stories page. Note. To access the pages for viewing and editing content, roles with this permission list must also include permission list PAPP2010 (Access Content Management) |
PAPP2025 |
Administer News content. |
Administer News Publication articles and images. These pages allow the user to delete, add, and update news articles and images, ignoring the privilege set or status of the content. This permission list should only be granted to high-level content administrators. To access the pages for viewing and editing news content, roles with this permission list must also include permission list PAPP2010 (Access Content Management). |
PAPP2030 |
Manage Company Promotions. |
Manage Company Promotions by publishing submitted promotions, and inquiring on viewer roles assigned to Company Promotion items. |
PAPP2035 |
Administer Company Promotions. |
Administer Company Promotions by creating and updating promotion targets and categories. |
PAPP2045 |
Run Categorization Spider. |
Run the Categorization Spider process to pull categories and content into the Categorized Content feature. Note. Users with this permission list should also be listed as a Top Administrator for the Categorized Content feature. |
PAPP2050 |
Administer Content Management. |
Administer Managed Content by assigning top category administrators, creating privilege sets, assigning viewer roles, and defining attachment locations. This permission list should only be granted to high-level content administrators. |
PAPP2070 |
Review Content Access/Location. |
Review Content stored in the Content Management system. The inquiry lists where the content can be accessed, who can access the content, and a preview of the content for users who are viewing members for this content. Access the Render Content URL page to generate the content's rendering URL for use in third-party applications. |
PAPP2080 |
Query Content Management |
Access the Content Management tables and views on the Enterprise Portal query tree. Note. This permission list should only be granted to high level content administrators to limit access to all content. |
PAPP2300 |
Administer External News. |
Administer External News by creating and updating External News publication pagelets, providers, groups, categories, articles, and news feed batch process. |
PAPP2310 |
Manage External News. |
Manage External News by changing the publish and expire dates of news feed articles to remove offensive articles. |
PAPP2700 |
Administer Web Magazine. |
Administer Web Magazine by creating and updating Web Magazine publications, issues, sections, categories, images, and articles. |
PAPP2800 |
Administer Integrated Tasks. |
Administer the Integrated Task pagelet by access to the PeopleTools Worklist, Worklist Details, and Worklist administration pages. |
PAPP3100 |
Administer Weather pagelet. |
Administer Weather pagelet by getting a customer ID or running the Update City List process. |
PAPP3200 |
Administer HTML pagelets. |
Administer HTML pagelets by creating and registering HTML pagelets. |
PAPP3300 |
Administer Email/Calendar pagelet. |
Administer the Email and Calendar pagelets by defining the email and calendar system and user values. |
PAPP3550 |
Administer integration content. |
Access the SOAP to component interface iScripts (WEBLIB) web services. |
PAPP3560 |
Administer integration workspaces. |
Access the Collaborative Workspace component interface web services. |
PAPP4000 |
Query Portal Registry |
Access PeopleSoft Query and the Portal Registry navigation and homepage tables on the Enterprise Portal query tree. |
PAPP4001 |
Run portal registry processes. |
Access the run control pages and processes for Registry Load, Menu Import, Portal Security Sync, and Sync Navigation Collections. |
PAPP4002 |
Administer Homepage Tabs. |
Administer the Homepage Tab Layout and Content definition. Note. The user must have the Portal Administrator role or have the site-specific administrator role to modify the tab definition from the Configure Homepage menu item. |
PAPP4003 |
Administer Portal Settings |
Administer the Portal General Settings page to set the site and node templates, the folder navigation options, and the portal search options. |
PAPP4004 |
Run Processes. |
Access to Process Monitor and the delivered process groups. Use as the process profile permission list on the User Profile definition page. |
PAPP4005 |
Publish Pagelets to Sites. |
Access the component to copy pagelet content references from one site to another. |
PAPP4006 |
Run Base User Processes |
Access the delivered base user process group for alert and subscribed notifications. Note. Use this permission list as the process profile permission list on the User Profile definition page for end-users. |
PAPP4010 |
Administer Pagelet Personalization. |
Administer Pagelet Personalization by setting any user's preferences for the following pagelets: Weather, External News, RSS News, Stock Quotes, Community Calendars, Managed Content, Discussion Forums, and Pagelet Wizard pagelets. |
PAPP4020 |
Manage Menu Item Requests. |
Manage menu item requests by approving or rejecting requests, and defining the users notified by email for submitted requests. |
PAPP4025 |
Administer Menu Item Requests. |
Administer menu item requests by approving or rejecting requests, registering approved requests, and defining the users notified by email for submitted requests. |
PAPP4040 |
Administer Privilege Sets. |
Administer the Privilege Set definitions for Collaborative Workspaces, Community Calendars, Action Items, Polls, and Discussion Forums. Note. Use permission list PAPP2050 (Administer Content Management) to administer the Content Management Privilege Sets |
PAPP4050 |
Administer Portal Search. |
Administer Search by defining search indexes, search groups, search run controls and search notification. Note. Search groups determine which search collections are associated with a specific search results page. |
PAPP4060 |
Administer Viewer Roles |
Administer Viewer Roles by listing the roles available to secure News Publication articles and Company Promotion items. Note. This permission list should only be granted to high level content administrators. |
PAPP4080 |
Query Navigation. |
Access the Portal Registry navigation tables on the Enterprise Portal query tree. |
PAPP4100 |
Submit Menu Item requests |
Submit Menu Item Requests to request items to be added to the portal navigation. |
PAPP4110 |
Submit promotion items |
Submit company promotion items. |
PAPP4120 |
Submit news articles |
Submit News Articles for publication. Note. This permission list is needed to enable the Submit Article link on News Publication pagelets that allow submits from the pagelet. |
PAPP4130 |
Take a survey |
Take a survey. Access is limited to the survey definition's distribution group. |
PAPP4200 |
Logon Statistics pagelet |
Access the Logon Statistics pagelet. |
PAPP4300 |
Manage Content Ratings |
Manage Content Ratings by creating content rating questions, assigning menu items to the content rating definition, and viewing the respondent results of the content rating questions. |
PAPP4310 |
Access Poll definitions. |
Access Poll Definitions. Poll Definition access and actions are restricted by member privileges on the Poll Definition. |
PAPP4350 |
Administer Content Ratings. |
Administer Content Ratings by assigning Result Viewers, setting non registered URL's, and inquiring on the invisible iTracker results. |
PAPP4355 |
Administer Poll definition. |
Administer Poll Definitions by assigning member privileges or deleting a poll. These Poll Definition actions are not restricted by member privileges. |
PAPP4360 |
Create Poll Definitions |
Create Poll Definitions and assign member privileges to the created poll. |
PAPP4400 |
Access Account Signon Utility. |
Access the Account Signon Utility by updating the stored user ID and password. |
PAPP4450 |
Administer Account Signon Utility. |
Administer the Account Signon Utility by creating the Sign On forms and URLs to access external secured sites. |
PAPP4500 |
Administer portal options. |
Define installation, system, and registry options. |
PAPP4600 |
Administer context assignment. |
Administer Context Manager by assigning the default template pagelets as well as the individual template pagelets to a specified Menu Item. |
PAPP4680 |
Query Context Manager |
Access the Context Manager tables and views on the Enterprise Portal query tree. |
PAPP4700 |
Manage Related Content. |
Manage Related Content by adding Related Content online to Menu Items that are assigned a Related Content template pagelet. This permission list is for general page access. Access to add content to a Menu Item/Related Content publication combination is restricted via assigned Topic Experts as well as access to the Menu Item in the navigation. |
PAPP4710 |
Review Related Content |
Access the Related Content Inquiry Pages listing content according to the assigned Topic Expert or the Menu Item. |
PAPP4750 |
Administer Related Content |
Administer Related Content by creating or updating Related Content Publications and assigning the Topic Experts to add the content. |
PAPP4800 |
Discussion Forums pagelet |
Access the Discussion Forums pagelet and pagelet personalization. The displayed forums are limited by member privileges on the Forum definition. |
PAPP4810 |
Access Discussion Forums |
Access Discussion Forums. Discussion Forum access and actions are restricted by member privileges on the Forum definition. |
PAPP4820 |
Access Guest Discussion Forums |
View Discussion Forums in display-only mode. Access is restricted by member privileges on the Forum definition. |
PAPP4850 |
Administer Discussion Forums |
Administer Discussion Forums by assigning member privileges, editing metadata or deleting a Forum. These Discussion Forum actions are not restricted by member privileges. |
PAPP4855 |
Manage Related Discussions |
Administer Related Discussions template pagelet by assigning moderators. Contributor and viewer privileges are automatically granted to all users who can access the Menu Item that contains the related discussion. |
PAPP4860 |
Create Discussion Forums |
Create Discussion Forums and assign member privileges to the created Forum. |
PAPP4910 |
Define pagelets with the Wizard. |
Create, delete, and clone Pagelet Wizard pagelets definitions. Pagelet Wizard access and actions are restricted by the security on the Pagelet Wizard definition. |
PAPP4920 |
Define Pagelet Wizard data. |
Create and update Pagelet Wizard footers, headers, and categories and review existing pagelet definitions. |
PAPP4950 |
Administer Pagelet Wizard |
Create and update Pagelet Wizard data types, display formats, transform types, and pagelet XSL. Create Data Mover scripts to export and import pagelet definitions. |
PAPP5000 |
Administer Site - Template. |
This permission list is the Site Manager template permission list for site administrators. This permission list is cloned for each created site. It grants site-specific access to the following: define site navigation defaults, define site security, define visible site features, configure homepage display, override allowed branding elements, view Branding queries, and publish pagelets to multiple sites |
PAPP5050 |
Create sites / Allow overrides. |
Create portal sites and assign allowed Branding overrides using the Site Wizard. |
PAPP5060 |
Publish in Sites - Template. |
This permission list is the Site Manager template permission list for site publishers. This permission list is cloned for each created site. It grants site-specific access to the following: manage a site's navigation by publishing men items to the site, update the content IDs used in existing Pagelet Wizard Content Management pagelets, create Action Item Lists, create Community Calendars, create and access Poll Definitions, create and access Content Management, and create Discussion Forums. Note. Users with this permission list should also have the following permission lists (delivered on the base user role PAPP_USER): PAPP4810 (Access Discussion Forums), PAPP5600 (Access Action Items), PAPP1210 (View Community Calendars) and PAPP5500 (Access Community Calendars). |
PAPP5070 |
View Sites - Template. |
This permission list is the Site Manager template permission list for site viewers. This permission list is cloned for each created site. It is a placeholder permission list for the site-specific home link to access the created site. |
PAPP5100 |
Maintain Branding roles. |
Assign security roles to Branding themes. |
PAPP5150 |
Maintain Branding data. |
Create and maintain Branding themes, headers, and footers. |
PAPP5160 |
Maintain Branding layouts. |
Create and maintain Branding layouts. |
PAPP5180 |
Query Branding |
Access the Branding tables and views on the Enterprise Portal query tree. Access the Branding Query menu items. |
PAPP5200 |
Manage Navigation Collections. |
Manage Navigation Collections by creating and updating Navigation Collection definitions. Note. This permission list does not grant access to delete Navigation Collections. |
PAPP5250 |
Administer Navigation Collections. |
Administer Navigation Collections by creating, updating and deleting Navigation Collections definitions. |
PAPP5300 |
Access Workspaces. |
Access Collaborative Workspaces. Access is granted to: links, members, documents, polls, search and browsing. Workspace access and actions are restricted by member privileges on the workspace definition. Note: Users with this permission list should also have the following permission lists (delivered on the base user role PAPP_USER): PAPP4810 (Access Discussion Forums), PAPP5600 (Access Action Items), PAPP1210 (View Community Calendars) and PAPP5500 (Access Community Calendars). |
PAPP5350 |
Administer Workspaces. |
Create and administer Collaborative Workspaces and Templates. Administer Workspace categories, and batch import Workspaces. Administer existing Workspaces by activating, deactivating, or deleting a workspace. These Workspace actions are not restricted by member privileges on the Workspace definition. Workspace access is restricted by member privileges on the Workspace definition. |
PAPP5360 |
Manage Workspaces. |
Create and manage Collaborative Workspaces. Manage existing Workspaces by activating, deactivating, or deleting a workspace. Workspace access and actions are restricted by member privileges on the Workspace definition. |
PAPP5400 |
Access My Alerts. |
Access to the user-defined alerts. |
PAPP5450 |
Administer Alerts. |
Administer Alerts Notifications including the Notification batch process, and defining features, email options, and alert subscriptions. |
PAPP5500 |
Access Community Calendars. |
Access Community Calendars. Calendar access and actions are restricted by member privileges on the Calendar definition. |
PAPP5550 |
Administer Community Calendars. |
Administer Community Calendars by assigning member privileges or deleting a Calendar. These actions are not restricted by member privileges. |
PAPP5560 |
Create Community Calendars. |
Create Community Calendars and assign member privileges to calendars. |
PAPP5600 |
Access Action Items |
Access Action Items. Action Item access and actions are restricted by member privileges on the List definition or the assigned user. |
PAPP5650 |
Review Action Items |
Review Action Items. Action Item access and actions are restricted by member privileges on the List definition or the assigned user. |
PAPP5655 |
Administer Action Items. |
Administer Action Item Lists by assigning member privileges or deleting a List. These actions are not restricted by member privileges. |
PAPP5660 |
Create Action Item list. |
Create Action Item lists and assign member privileges. |
PAPP9000 |
All Enterprise Portal objects. |
Access all Enterprise Portal-owned objects excluding Resource Finder |
PAPP9900 |
System setup data. |
Access to the pages displaying system data that should not be changed or customized. |
PAPP9999 |
Demo examples and testing. |
Access to delivered demo, testing, and SDK material. |
PAPX0000 |
Base Repository objects. |
Base access to Resource Finder profile display and the Related Resources template pagelets. Required access for all users, including Guest. |
PAPX1000 |
Resource Finder pagelet. |
Access the Resource Finder pagelet and pagelet enhancement Search Results pages. |
PAPX2050 |
Manage Resource profiles. |
Manage Resource profiles by updating or creating a profile definition (create an Employee profile type). |
PAPX2060 |
Administer Repository. |
Administer Resource Finder Repository by creating profile attributes or entering a profile not obtained from a feed. |
PAPX2070 |
Administer Repository Search. |
Administer Resource Finder Repository Search Collections. |
PAPX9000 |
All Repository objects. |
Access to all Resource Finder Repository objects. |
PAPX9999 |
Demo examples and testing. |
Testing Resource Finder application classes. |
This section describes:
Roles that have special usage in PeopleSoft Enterprise Portal.
Roles associated with major PeopleSoft Enterprise Portal areas.
Viewer roles.
All delivered roles.
The following table lists roles that have special meaning and usage in PeopleSoft Enterprise Portal.
Note. In Enterprise Portal 9, the base object permission lists have been streamlined to include only those components that all users need and are cannot access directly from the left navigation. Additional permission lists have been created for some components and added to the PAPP_USER role. The components My Discussion Forums, My Alerts, and Browse by Category were removed from the PAPP000n permission list. This enables you to disable a given feature by removing the feature's base permission list from the PAPP_USER role.
Role |
Description/Usage |
PAPP_USER |
Must be assigned to every user ID, except the default signon user ID GUEST. |
PeopleSoft User |
Must be assigned to every user ID, except the default signon user ID GUEST. |
PAPP_GUEST |
Must be assigned to the default signon user ID GUEST. |
PeopleSoft Guest |
Must be assigned to the default signon user ID GUEST. |
PAPP_SYSTEM_ADMIN |
Used only during installation and implementation and is assigned to VP1 and PS. |
PeopleSoft Administrator |
Used only during installation and implementation and is assigned to VP1 and PS. It gives access into all the pages regardless of the user's assigned permission lists. |
Portal Administrator |
Used in the production system. It gives access to the portal registry structure (content references and folder references), but not the actual component/pages and pagelets. Be aware that users who have this role will see all pagelets and all menu items (all content references), but they may not be able to access the actual pages. If a user with this role attempts to access a pagelet or a page where they do not have that pagelet or pages's security, a "You are not authorized" error message displays. |
The major areas within PeopleSoft Enterprise Portal are associated with roles. These areas and roles contain overlap. The major areas and roles are shown in the following table.
Area |
Role |
Description |
Content |
PAPP_CONTENT_ADMIN |
Administer internally-created and external content, including External News, Internal News, Context Manager and Content Management. |
Navigation |
PAPP_NAVIGATION_ADMIN |
Administer how users navigate the portal sites, including Menu Items requests, manage navigation, Portal Registry Load, and Navigation Collections. Users who have this role should also have the role of Portal Administrator. |
Portal sites |
PAPP_PORTAL_ADMIN |
Administer the portal and portal sites, including install options, site creation, Logon Statistics, Search, Menu Items requests, manage navigation, Portal Registry Load, Navigation Collections, Collaborative Workspaces, Branding, Account Signon Utility, pagelet Personalization, and Context Manager. Users who have this role should also have the role of Portal Administrator. |
Presentation |
PAPP_DISPLAY_ADMIN |
Administer the presentation of portal sites, including Branding, Pagelet Wizard headers/footers, default templates, and homepage tab layouts. |
Resource Finder |
PAPX_REPOSITORY_ADMIN |
Administer the Resource Finder Repository feature. |
Security |
PAPP_SECURITY_ADMIN |
Administer portal row-level security, including Manage Content privilege sets, Viewer roles, Related Context topic experts, Discussion moderators, pagelet Personalization, and Menu Item Inquiry. Users who have this role may also have the role of Security Administrator. |
Integration |
PAPP_INTEGRATION_ADMIN |
Administer integration content in the enterprise portal, including external content, Internet content, email, account signon utility, and Pagelet Wizard. |
The following roles are delivered as viewer roles, and are used by Content Management to secure individual content items for viewing. To change which roles are designated as viewer roles, select Portal Administration, Content, Viewer Roles.
Role |
Usage / Long Description |
PAPP_CUSTOMER |
Access to applicable customer homepage pagelets and assigned content viewing. |
PAPP_EMPLOYEE |
Access to applicable employee homepage pagelets, assigned content viewing, submit pages (promotions, articles, menu items), and edit account signon information. |
PAPP_GUEST |
Access to applicable Guest homepage pagelets, assigned content viewing, Guest homepage tab, and base PeopleSoft Enterprise Portal access. |
PAPP_SUPPLIER |
Access to applicable supplier homepage pagelets and assigned content viewing. |
The following table lists the roles delivered with PeopleSoft Enterprise Portal.
Role |
Description |
Usage/Long Description |
PAPP_ACCOUNT_SIGNON_ADMIN |
Account signon administrator. |
Administer the User Account Signon Utility. |
PAPP_AUTHOR |
Content author. |
Access the submit pages for News, Promotions, and Menu Items. Access Content Management common pages, where the privilege sets limit the access. |
PAPP_BRANDING_ADMIN |
Branding administrator. |
Administer the Branding feature. |
PAPP_COMPANY_PROMOTIONS_ADMIN |
Company Promotions administrator. |
Administer the Company Promotions feature. |
PAPP_CONTCATG_ADMIN |
Content Categorization administration. |
Administer the Content Categorization feature manually. |
PAPP_CONTENT_ADMIN |
Content administrator. |
Administer internally created and external content, including External News, Internal News, Context Manager and Content Management. |
PAPP_CONTENT_MANAGER |
Content Manager. |
Manage internally created and external content, including External News, Internal News, Context Manager and Content Management. |
PAPP_CONTENT_RATINGS_ADMIN |
Content Ratings administrator. |
Administer the Content Ratings related context feature. |
PAPP_CONTENT_USER |
Content Management user. |
Access Content Management common pages, where assigned privilege sets limit the access. Access the Managed Content pagelet, the News Article In-Box pagelet, and the Submit News Article page. Use this role as a general access role, then create additional roles to assign to the privilege sets within each created category. |
PAPP_CONTEXT_ADMIN |
Related Context administrator. |
Administer the Context Manager feature including the contextual content. |
PAPP_CONTEXT_MANAGER |
Related Context Manager. |
Manage the contextual content used with the Context Manager feature. |
PAPP_CUSTOMER |
Portal Customer. |
Access to applicable Customer homepage pagelets and assigned content viewing. |
PAPP_DEMO_ADMIN |
Demo/Test Items administrator. |
Sample. Administer the sample features, including the Demo Item pagelet and Context Manager Item tester. |
PAPP_DISCUSSIONS_ADMIN |
Discussions administrator. |
Administer Related Discussions and the Discussions Forum feature. |
PAPP_DISPLAY_ADMIN |
Presentation administrator. |
Administer the presentation of the portal sites, including Branding, Pagelet Wizard headers/footers, default templates, and homepage tabs layout. |
PAPP_EMAIL_CALENDAR_ADMIN |
Email / Calendar administrator. |
Administer the Email and Calendar pagelets. |
PAPP_EMPLOYEE |
Portal employee. |
Access to applicable employee homepage pagelets, assigned content viewing, submit pages (Promotions, Articles, Menu Items), find a resource, and edit account signon information. |
PAPP_EXTERNAL_NEWS_ADMIN |
External News administrator. |
Administer the External News pagelet. |
PAPP_GUEST |
Guest user access. |
Access to applicable Guest homepage pagelets, assigned content viewing, Guest homepage tab, and base PeopleSoft Enterprise Portal access. |
PAPP_GUEST_ADMIN |
Guest user administrator. |
Administer pagelet Personalization for a Guest user, or any user, and access the Guest homepage tab. |
PAPP_INSTALL_OPTIONS_ADMIN |
Install options administrator. |
Administer the Install Options for the PeopleSoft Enterprise Portal features. |
PAPP_INTEGRATED_TASKS_ADMIN |
Integrated tasks administrator. |
Administer the Tasks pagelet. |
PAPP_INTEGRATION_ADMIN |
Integration administrator. |
Administer integration content in the PeopleSoft Enterprise Portal, including External Content, Internet Content, Email, Account Signon Utility, and Pagelet Wizard. |
PAPP_INTERNET_PAGELETS_ADMIN |
Internet pagelets administrator. |
Administer Internet pagelets. |
PAPP_LDAP |
LDAP default access. |
Contains the required permission lists needed to access the Portal Solutions database. Use as the default role for LDAP access. |
PAPP_LOGON_STATISTICS_ADMIN |
Logon statistics administrator. |
Review user logon statistics through the User Logon Statistics pagelet. |
PAPP_NAVIGATION_ADMIN |
Navigation administrator. |
Administer how users navigate the portal, including, Menu Items requests, Portal Registry Load, and Navigation Collections. Users who have this role should also have the Portal Administrator role. |
PAPP_NAVIGATION_MANAGER |
Navigation manager. |
Manage submitted menu items and Navigation Collections. |
PAPP_NEWS_PUBLICATIONS_ADMIN |
News Publication administrator. |
Administer the Content Management News Publication feature. |
PAPP_PAGELET_ADMIN |
Pagelet administrator. |
Administer the creation of pagelets using pagelet wizard. Administer Navigation Collections. Administer Integration pagelets. Assign user pagelet personalization. Users who have this role should also have the Portal Administrator role and the Pagelet User role. |
PAPP_PAGELET_USER |
Pagelet access user. |
Access the homepage pagelets. To configure the layout of a homepage tab, the user must be either assigned the Portal Administrator role, or the user must have access to PAPP4002 as well as all of the homepage pagelet permission lists on the homepage tab. |
PAPP_PORTAL_ADMIN |
Portal administrator. |
Administer the portal and portal sites, including install options, site creation, Logon Statistics, Search, Menu Items requests, navigation collections, Portal Registry Load, Branding, Account Signon Utility, pagelet Personalization, alerts and Context Manager. Users who have this role should also have the Portal Administrator role. |
PAPP_PUBLISHER |
Content publisher. |
Manage, review, and publish content to a viewing audience in the New Publications and Company Promotions features. |
PAPP_RELATED_CONTENT_ADMIN |
Related Content administrator. |
Administer features of Context Manager. |
PAPP_SEARCH_ADMIN |
Search administrator. |
Administer the portal Search feature. |
PAPP_SECURITY_ADMIN |
Security administrator. |
Administer portal row-level security, including Managed Content privilege sets, viewer roles, related context topic experts, Discussion moderators, pagelet Personalization, and Menu Item inquiry. Users who have this role may also have the Security Administrator role. |
PAPP_SITE_MGMT_ADMIN |
Site Management administrator. |
Administer the Site Management feature, including creating sites and site Branding. Users who have this role should also have the Portal Administrator role. |
PAPP_SUPPLIER |
Portal supplier. |
Access to applicable supplier homepage pagelets and assigned content viewing. |
PAPP_SYSTEM_ADMIN |
PeopleSoft Enterprise Portal system administrator. |
Access to all PeopleSoft Enterprise Portal objects. |
PAPP_USER |
PeopleSoft Enterprise Portal user. |
Access the base objects in the PeopleSoft Enterprise Portal. Every user in the system, other than Guest, must be assigned this role along with the PeopleSoft User role. |
PAPP_WEB_MAGAZINE_ADMIN |
Web Magazine administrator. |
Administer the Web Magazine pagelet and content. |
PAPP_WORKSPACE_ADMIN |
Workspace Administrator. |
Administer and create collaborative workspaces. |
PAPP_WORKSPACE_MANAGER |
Workspace Manager. |
Manage collaborative workspaces. |
PAPP_WORKSPACE_USER |
Workspace User. |
Access the Collaborative workspace components. Individual workspaces are also secured by members to that workspace. |
PAPX_PROFILE_MANAGER |
Resource profile manager. |
Manage the Resource Finder profiles. |
PAPX_REPOSITORY_ADMIN |
Repository administrator. |
Administer the PeopleSoft Enterprise Resource Finder feature. |
PAPX_SEARCH_ADMIN |
Profile Search administrator. |
Administer the Resource Profile Search. |
You can obtain this information online, including any security fixes, by using the delivered PeopleSoft Query PAPP_SECURITY_ROLE_PERM.
This section discusses:
User IDs with special uses in PeopleSoft Enterprise Portal.
User IDs delivered with PeopleSoft Enterprise Portal.
The following table lists user IDs with special uses in PeopleSoft Enterprise Portal.
User ID |
Description |
GUEST |
The default signon user. |
PS |
The system administrator to access all of the PeopleSoft Enterprise Portal database and the HRMS database. |
VP1 |
The system administrator to access all of the PeopleSoft Enterprise Portal database and the FSCM, EPM, and CRM databases. |
The following table shows the delivered PeopleTools roles and their associated permission lists.
PeopleTools Role |
PeopleTools Permission List |
Permission List Description |
PeopleSoft User |
PTPT1000 |
PeopleSoft-User. |
PeopleSoft Guest |
PTPT1400 |
PeopleSoft-Guest. |
Security Administrator |
PTPT1100 |
Maintain Security. |
PeopleTools |
PTPT1200 |
PeopleTools. |
PeopleSoft Administrator |
**special** |
Behind-the-scenes coding. |
Portal Administrator |
PTPT1300 |
Behind-the-scenes to PeopleSoft Enterprise Portal. |
Portal Manager |
PTPT1600 |
Pagelet Wizard, Navigation Collections. |
To navigate and use common features and pages, every user ID (except for the Guest user IDs) must include the delivered roles PAPP_USER and PeopleSoft User. During a PeopleTools upgrade, the role PeopleSoft User is added to all existing roles. You can update the existing user IDs to include the PAPP_USER role with the delivered PeopleSoft Data Mover script PORTAL_ADD_ROLE.DMS.
Note. Every newly created user ID should include both roles PeopleSoft User and PAPP_USER. Guest user IDs should not include these roles. After running the script, manually update the Guest user ID by replacing the PeopleSoft User role and the PAPP_USER role with the PeopleSoft Guest role and the PAPP_GUEST role.
Use PeopleSoft Data Mover to update the existing user IDs in PeopleSoft Enterprise Portal to include the necessary PAPP_USER role.
There are two ways to start PeopleSoft Data Mover:
Using the Data Mover shortcut in your PeopleSoft program group, as in Start, Programs, <PeopleSoft Group>, Data Mover.
This access method only applies to the Windows Development Environment.
Using the command line interface.
This executes PeopleSoft Data Mover in a console for Windows and a Telnet session for UNIX.
To update the user IDs:
Start PeopleSoft Data Mover and sign on to the PeopleSoft Enterprise Portal database.
Open the script PORTAL_ADD_ROLE.DMS in the <PS_HOME>\scripts directory.
Run the script against the PeopleSoft Enterprise Portal database.
Close PeopleSoft Data Mover.
See Also
Enterprise PeopleTools 8.48 PeopleBook: Data Management, “Using PeopleSoft Data Mover”