Just to add to René's answer, the way security works in Cognos is often additive. If you belong to two groups (for example), you will end up with the sum of the privileges granted in both. This holds true if the privileges were applied using the Allow option. So if you belong to groups A and B, and a permission or capability is marked as Allow in group A and not checked in group B, you will end up with that permission or capability granted to you. The time this doesn't hold true is if a permission or capability is explicitly marked as Deny in one of the groups you belong to. In this case, you don't get the permission or privilege. So if in group A a permission or capability is marked as Allow, and in group B the same permission or capability is marked as Deny, you will end up without that permission or capability granted to you.
Hope this helps!
MF.
------------------------------
Mark Fry
Technical Consultant
------------------------------