We do not use Framework Manager to control any security - We control everything with multiple sign-on's on each data connection in Cognos Administration > Data Source Connections > Configurations.
Typically, we have 2 sign-on's for each connection, each with specific grant/deny permissions.
Therefore, a user running a report will be automatically directed to a specific sign-on and then there is security on our Oracle database which handles redirection using synonyms to a view (with masked columns) or the table (with all columns available) based on the sign-on selected.
So, all our necessary security (in this particular scenario) is handled at the database level rather than in Cognos.
That's why, as we have fully functional database security in place, I don't want to have to recreate it either in Framework Manager or in Data Modules.
Hope this helps.
Thanks again,
Adam.
------------------------------
Adam McIlravey
------------------------------
Original Message:
Sent: Fri January 10, 2020 09:40 AM
From: brenda grossnickle
Subject: Data Modules and Data Server Connections
A bit off topic, but how do you redirect to a different view based on the Cognos Group/Role?
In Framework Manage, we use a Cognos Macro that switches the data source based on the users Groups/Roles. For users in the SecureGroup, the macro changes the data source to SecureDS which uses the signin SecureUser. The SecureUser signin logs into SQL with specific credentials that have special permissions - mostly for decrypting sensitive information. If the user is not in the SecureGroup then the default data source and SQL credentials are used.
t sounds like you do something very different. Can you explain a bit more about your setup in Framework Manager.
------------------------------
brenda grossnickle
BI Programmer Analyst
FIS
------------------------------