Planning Analytics

 View Only
  • 1.  New PAW User and Group Functionality v84 Cloud

    Posted Wed March 08, 2023 07:33 AM

    Hi All,

    Saw that in PAW V84 we now have some ability to synchronize PAW users and groups into a TM1 model. It's so close to being useful!!

    From my brief testing, I think we can add PAW users or groups into a TM1 model (so effectively adding elements to the respective dimensions). I was also pleased to see that it will assign group memberships too when importing too.

    Where it falls down (IMO) is that I can't sync/refresh this from the modelling screen nor have I seen any new processes to do this (not looked very far to be honest). What I'd hope for is an additional menu item when clicking on a group that will pull in the group membership again from PAW. I can reimport the same group over the top and it will reload the membership (while reporting the group and the users already exist).

    I'd also like the option to be able to automate the sync between PAW and the TM1 model. Could there be a process? Could the group have an attribute assigned that links it to the PAW group automatically? Could we have the necessary rule functions so we can create a cube rule on the }ClientGroups cube that will sync the membership assignments?

    Is this still an open development for the team?

    Manage users and groups on a Planning Analytics database (Cloud only)

    Ibm remove preview
    Manage users and groups on a Planning Analytics database (Cloud only)
    A new editor provides an intuitive interface to manage users and groups on a Planning Analytics database. You can also use the editor to import users and groups from Planning Analytics Workspace into a Planning Analytics database.
    View this on Ibm >



    ------------------------------
    Chris Davidson
    ------------------------------


  • 2.  RE: New PAW User and Group Functionality v84 Cloud

    Posted Wed March 08, 2023 01:28 PM

    Hi Chris,

    Thanks for your feedback on this.  User and group management is area of Planning Analytics that we plan to continue to enhance.  We are generally aligned with a feature that would synchronize group memberships from Workspace to TM1 databases, when the same named group is in both places.  Ideally, this should happen automatically as users in Workspace connect to the TM1 databases.   Let me provide an example: 

    Assume a group named Planners exists in Workspace and is added to a TM1 database using the new Users & Groups feature in PAW modeling.  After the Planners groups is added to the TM1 database some new users are onboard to Planning Analytics.  The Administrator in PAW adds the new users to the Planners groups in Planning Analytics Administration.   One of the new users opens a PAW book which uses a cube from the TM1 database where access to the cube is based on member of the TM1 user in the Planners group in TM1.

    When the user open the book the user made a connection to the TM1 database.  At this point the TM1 database could ask PAW which PAW groups the user belongs to.  PAW would tell TM1 that the user exists in the PAW Planners group.  Because a group named Planners also exists in the TM1 database the user is automatically added to that Planners groups.  If the user is later removed from the PAW Planners group, the next time they connect to the TM1 databases they will be automatically removed from the same named group in TM1.

    The advantage of this approach is that the modeler does not need to manually resync after group memberships are updated in PAW.  This is very similar to how CAM authentication works between Cognos groups and TM1 groups in Planning Analytics on-premises.

    In this short term we will likely to add manual sync feature in the users and groups interface (click on a group in TM1 and resync it so the TM1 groups members match the PAW group members).

     

      



    ------------------------------
    Stuart King
    IBM Planning Analytics Offering Manager
    ------------------------------



  • 3.  RE: New PAW User and Group Functionality v84 Cloud

    Posted Thu March 09, 2023 04:17 AM

    Thanks Stuart. It's a good step forwards and the roadmap towards making it similar to the CAM security sounds great. IN the interim, just a manual sync for a group (or all groups?) is a small extra step after modifying PAW group memberships.

    Do you therefore expect a transition towards using the PAW groups for TM1 security as the recommended approach/best practice?

    Chris



    ------------------------------
    Chris Davidson
    ------------------------------



  • 4.  RE: New PAW User and Group Functionality v84 Cloud

    Posted Wed March 15, 2023 10:02 AM

    Hi Stuart,

    Thank for the explanation. Great to know that once the assignment "users to groups" have been set in PAW, it will/can be sync to TM1 }ClientsGroup.  Is the opposite possible (i.e have PAW User Group be sync/loaded with the info form }ClientsGroup from TM1 Server?

    I have a couple additional questions regarding this topic:

    • For customer "upgrading" from pure TM1 / Perspective / TM1Web to TM1 / PAfE / PAW (incl TM1WEB)
      • TM1 Groups can be easily import in PAW Groups
      • However, is there a way to import from the }ClientsGroup cube the info which user belongs to which group? For a customer with a large user base it would not be practical to have to assign in PAW hundreds or thousands of users manually.

    • If customer uses an external tool to manage permissions/rights,
      • user to group assignment
      • books permissions
      • application permissions
    • Questions 
      • Is there a way to import that information or to maintain this over an API?
      • How can this be automated?
      • Are these functionalities available today?
      • If not, are the planned to be implemented soon? When?

    Thank you,

    Best Regards



    ------------------------------
    Andre Betschen
    ------------------------------



  • 5.  RE: New PAW User and Group Functionality v84 Cloud

    Posted Thu March 16, 2023 02:55 AM

    Hi  Stuart and all,

    I just realized that I based my questions on the documentation and not the actual functionality. Going to Administration => Users and Groups => Groups  and then trying the import functionality, I now see that it is possible not only to add groups in bulk but also manage the assignment of user to the various groups.

    Thus, it is possible to create a .csv file based on the }ClientsGroup cube using a TI process and then upload this through the functionality described above in PAW.

    So my suggestion is to update the documentation to make more clear what can be achieved with the  Administration => Users and Groups => Groups => Import unless I missed or could not find the right section that would describe this.

    However, my questions remain (from an automation perspective)

    • If customer uses an external tool to manage permissions/rights,
      • user to group assignment
      • books permissions
      • application permissions
    • Questions 
      • Is there a way to import that information or to maintain this over an API?
      • How can this be automated?
      • Are these functionalities available today?
      • If not, are the planned to be implemented soon? When?

    Thank you.

    Best Regards

    Andre Betschen



    ------------------------------
    Andre Betschen
    ------------------------------



  • 6.  RE: New PAW User and Group Functionality v84 Cloud

    Posted Thu March 16, 2023 09:11 AM

    Hi Andre,

    The documentation is covering the UI options on Users and Gropus functionality, this is why we don't have a section covering the TI process that would import the csv as it goes further. Glad that you pointed that out as a further step. We do plan more work on security via UI options. 

    Best Regards,



    ------------------------------
    Svetlana Pestsova
    IBM Planning Analytics Product Manager
    ------------------------------