Hi Dennis,
> Dennis writes: New admin here. I would like to know if there is another way to manage users in Cognos. If I get asked if an employee has access, I find myself manually going through each & every group/role looking for the user. If I get asked to remove a user, I have to manually go through each group/role again. I have later found that I did not find all the groups/roles a user had membership in because I missed it during my manual search.
Hi Dennis,
I am a former Cognos product manager and run a company called Attain Insight, which has been an IBM partner for almost 20 years now founded in 2008. We specialize in security for Cognos, and we sell a product that does what you describe called WebGrant.
WebGrant is designed for non-technical users to perform basic user administration. You don't have to know much about Cognos to use WebGrant, and that is by intention. It allows designated individuals to manage user access, add or remove users from groups and roles. As well WebGrant includes audit tracking and license compliance reports (all Cognos reports). This means that common user access questions can be answered without needing IT intervention. It addresses all the needs you've described.
The Attain Insight team gave a presentation on WebGrant at the Toronto User group yesterday. WebGrant customers vary in size from a single Cognos administrator up to customers with over 50 administrators. It is a very popular product.
> Dennis writes: Why can't I use the search function and it work the same as when you search on the AD side of the Accounts screen? TIA for any advice given.
WebGrant resolves the search issue you mentioned as well as for namespace types where Cognos is not able to search. Possibly of central interest is that WebGrant allows you to put one or more users, into one or more groups and / or roles, at once. This feature can be a significant time-saver for administrators.
Any of us at Attain Insight would be happy to give you a short demo and discuss either with you directly or what you might want to call out to your management team as reasons to review your current security.
> Dennis writes: Hey John, thank you so much for your thorough response. I inherited the configuration of our install but I would love to know a few of the drawbacks to placing users in direct roles vs. an AD role. I say that because I don't quite understand the process of cleaning things up yet and I will need to gather enough wool to take to leadership for a config change to our offering. I am researching the audit extension right now. Thanks again!
You are not alone! Many customers have managed security manually often for years. Over time and with turnover of Cognos Administrators, new administrators like yourself can end up being not really sure of how complete or vulnerable the security they have inherited is.
With Cognos security, the main thing is to be systematic and organized in your approach whether adding users directly to groups and roles or using something indirect such as group. Automation of security management is possibly the second most important thing, though a bit of deeper discussion (the days of manually creating and managing groups should now be in the past).
A product like WebGrant will apply security consistently and uniformly so you, or any other administrator, doesn't miss things. WebGrant will expose vulnerabilities before they become an issue. Our new AI agent will allow you to ask questions also so you can find vulnerabilities in your security model (and allow others to use AI to answer questions about what a user has access to).
Dennis, please let me know if you would like more information or a demonstration / discussion.
Best Paul
paul.hulford@attaininsight.com
info@attaininsight.com
------------------------------
Paul Hulford
------------------------------
Original Message:
Sent: Wed October 15, 2025 09:01 AM
From: Dennis McClure
Subject: Better User Mgmt Method?
New admin here. I would like to know if there is another way to manage users in Cognos. If I get asked if an employee has access, I find myself manually going through each & every group/role looking for the user. If I get asked to remove a user, I have to manually go through each group/role again. I have later found that I did not find all the groups/roles a user had membership in because I missed it during my manual search.
Why can't I use the search function and it work the same as when you search on the AD side of the Accounts screen? TIA for any advice given.
------------------------------
Dennis McClure
------------------------------