Default administrator roles

By default, with an installation of Qlik Sense with predefined security rules, some roles are already created:

Property

Description

RootAdmin

A RootAdmin has access to everything and anything within the QMC. Upon installation, the user who successfully enters the first valid license is automatically assigned as RootAdmin.

It is paramount to ensure visibility of who is part of this role and who is not.

AuditAdmin

Has read access to all resources to enable auditing of access rights. Has read and publish rights on the administration stream.

This security role is relevant for support users who want to be able to review permissions, typically for auditing purposes.

ContentAdmin

Has create, read, update, and delete rights for all resources except nodes, engines, repositories, schedulers, proxies, virtual proxies, and syncs. Has read and publish rights on the administration stream.

This is technically an app administrator. They manage apps, resources, and refreshes for their user base, everything which is related to some produced content. Users in this role are unable to change any infrastructure settings on the Qlik Sense server or similar.

DeploymentAdmin

Has create, read, update, and delete rights for apps, tasks, users, licenses, nodes, repositories, schedulers, proxies, virtual proxies, and engines. Has read and publish rights on the administration stream.

This is a typical role which would be assigned to an operational support team which manages production and does releases and deployments on behalf of developers and users.

SecurityAdmin

Same as ContentAdmin, but with create, read, update, and delete rights for proxies and virtual proxies, and no access rights on tasks. Has read rights on server node configuration. Has read and publish rights on the administration stream.

As a security administrator, on top of having access to all content, they also manage how users can authenticate against the Qlik Sense server, including management of certificates.

The default administrator roles are just generic roles which should help your enterprise Qlik Sense deployment get up to speed. Ideally, they should serve as a basis and you, as a Qlik Sense consultant, should modify them to cater for your own company's use case. For additional security roles, it is very easy to create bespoke ones, as well, which is described next.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.58.121.8