Authorization Category-Based Privileges - Metasys - LIT-1201528 - General System Information - Metasys System - 10.1

Security Administrator System Technical Bulletin

Brand
Metasys
Product name
Metasys System
Document type
Technical Bulletin
Document number
LIT-1201528
Version
10.1
Revision date
2020-01-21
Language
English

Category-based privileges apply to specific categories of Metasys system objects. When you assign users a category-based privilege, they are able to perform the actions associated with that privilege only on specific categories of objects for which that privilege is granted. The Security System has a predefined set of categories available (for example, HVAC and Fire).

If you do not assign users View access permission to a particular category of items, they cannot see the details of those items in the View panel, limiting user access to items (objects, trends, and schedules) within the navigation tree.

Table 1 describes all the predefined authorization category-based privileges.

Table 1. Authorization Category-Based Privileges

Permission

Permission Privileges

No Access

Designates that the user has no access to the items in the specified category.

View

Gives the user the following privileges: view event, snooze event, focus view in panel, view item value, view item on graphic, view item in report, summary view in panel, user navigation views (display panel only), view all extensions in panel, hyperlink from graphic, and view the list of attribute commands (generic integration object).
Note: To snooze an alarm in the alarm bar, the user must have View permission and Manage Item Events permission. To display the Audit Viewer, the user must have View permission and View Metasys Status permission.

Advanced View

Gives the user the same privileges as the View permission, in addition to the capability of editing the advanced attributes for users with edit privileges. When not selected, the Advanced option in all item views (for example, Focus view) is disabled.

Operate

Gives the user the following privileges: Adjust commands; State commands based on States Text – BV, BO, MV, MO; Setpoint; Route (Trend); Execute (Trend); Re-command (Interlock); Set State.

Intervene

Gives the user the following privileges: Release; Release All; Operator Override; Release Operator Override; Timed Operator Override (TOO); Enable; Disable; Preset Counter; Reset – Pulse Meter, Analog Object, Totalization, Optimal Start (OST); Add Recipient Command and Remove Recipient Command (Notification); Cancel Delay Time (Analog Alarm); Cancel Report Delay (Multistate Alarm); and Clear (Trend).

Diagnostic

Gives the user the following privileges: Latch/Clear Statistics; Analyze Field Bus; Out-of-Service; In Service; Timed Out of Service (TOS).

Manage Item Event

Gives the user the following privileges: Acknowledge, Annotate. Applies to category-based events and allows the user to display an alarm in the Alarms Window (also referred to as Metasys - Events and Alarm Bar).

Manage Energy

Gives the user the following privileges:
  • OST Commands: Start/Stop Meter, Cancel Prestart/Prestop
  • Load Commands: Shed, Release Load, Comfort Override, Release Comfort Override, Lock, Unlock
  • DLLR Commands: Set Mode, Set Target, Reset Profile, Reset Interval, Reset Initialization Parameters

Modify Items

Gives the user the following privileges: Modify Item (cannot add or delete).

Commands included: Use GIO to Change Name, Change Units, and Change Display Precision

When users modify items, they can only set the Authorization Category property of a modified object to a category for which they have modify access permissions.

Configure Items

Gives the user the following privileges: Add, Modify, or Delete an Item.

When users create objects, they can only set the Authorization Category property to a category for which they have configuration access permission.