You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

369 lines
19 KiB

[collections/itsi_services]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_drift_detection_template]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_import_objects_cache]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_bulk_import_entities_status_cache]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_discovery_search]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_base_service_template]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_type]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_relationships]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_filter_rules]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_relationship_rules]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_refresh_queue]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_backfill]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_correlation_search]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_content_pack_status]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_content_pack_saved_search_status]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_content_pack_authorship]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin ], delete: [ itoa_admin ]
[collections/itsi_temp_batch_claimed_action_queue]
access = read : [ * ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_temporary_storage]
access = read : [ * ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_kpi_state_cache]
access = read : [ * ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_team]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [itoa_admin, itoa_team_admin ]
[collections/itsi_pages]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_service_analyzer]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_migration]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_migration_queue]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin ], delete: [ itoa_admin ]
[collections/itsi_notable_event_tag]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst , itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_notable_event_comment]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_notable_event_aggregation_policy]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_notable_event_ticketing]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_notable_event_ref_url]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_data_integration]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_event_management]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/maintenance_calendar]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/operative_maintenance_log]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_backup_restore_queue]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin ], delete: [ itoa_admin ]
[collections/itsi_user_realnames]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_retired_entity_delete_status]
access = read : [ * ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_features]
access = read : [ * ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin ]
## DEPRECATED AS OF 4.0.0
[collections/itsi_notable_event_group]
access = read : [ ], write: [ ], delete: [ ]
[collections/itsi_notable_group_user]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_notable_group_system]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin ], delete: [ itoa_admin ]
[collections/itsi_correlation_engine_group_template]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/itsi_notable_event_actions_queue]
access = read : [ itoa_admin, itoa_team_admin ], write : [ itoa_admin, itoa_team_admin ], delete : [ itoa_admin, itoa_team_admin ]
[collections/itsi_notable_event_email_template]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst ], write : [ itoa_admin, itoa_team_admin, itoa_analyst ], delete : [ itoa_admin, itoa_team_admin, itoa_analyst ]
[collections/itsi_entity_management_policies]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_custom_threshold_windows]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin ]
[collections/itsi_upgrade_readiness_prechecks]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin ], delete: [ itoa_admin ]
[collections/itsi_sandbox]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin ]
[collections/itsi_sandbox_service]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_sandbox_sync_log]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_entity_thresholds]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_kpi_at_info]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[collections/itsi_event_management_exports]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
## DEPRECATED AS OF 4.0.0
[collections/itsi_notable_event_state]
access = read : [ ], write: [ ], delete: [ ]
[collections/SA-ITOA_files]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], delete: [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ]
[collections/SA-ITOA_icon_collection]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
[alert_actions/itsi_event_generator]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
owner = nobody
[collections/itsi_kpi_summary_cache]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin ]
[collections/itsi_feature_flagging_view_permissions]
access = read : [ ], write: [ ], delete: [ ]
[collections/itsi_feature_flagging_state]
access = read : [ * ], write: [ ], delete: [ ]
[]
access = read : [ * ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/kpi_alert_info_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[macros/itsi_im_events_indexes]
access = read : [ * ], write : [ admin, sc_admin ]
export = system
[macros/itsi_im_metadata_indexes]
access = read : [ * ], write : [ admin, sc_admin ]
export = system
[macros/itsi_im_metrics_indexes]
access = read : [ * ], write : [ admin, sc_admin ]
export = system
[savedsearches/itsi_event_grouping]
owner = nobody
[savedsearches/itsi_find_dup_alias]
owner = nobody
[savedsearches/itsi_check_kvstore_size]
owner = nobody
[savedsearches/itsi_tracked_alerts_fields]
owner = nobody
[savedsearches/itsi_content_packs_status_update]
owner = nobody
[savedsearches/IT Service Intelligence - User Realnames - Lookup Gen]
owner = nobody
###################################
## Transforms/Lookup Permissions ##
###################################
# The values for read/write for the following stanza must be consistent with the values of the collection stanzas above.
# e.g. itsi_entities operates on the itsi_services kv store collection and must match its permissions
[transforms/itsi_entities]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_import_objects_cache]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_entity_types]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_refresh_queue]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/alarm_console_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/service_kpi_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/disabled_service_kpi_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_tag_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_comment_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/operative_maintenance_log]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_maintenance_calendar]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_user_realnames_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_external_ticket]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_ref_url]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_migration_check]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/service_kpi_sbs_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/kpi_base_search_title_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/service_telemetry_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_group_user_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_group_system_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_actions_queue_lookup]
access = read : [ itoa_admin, itoa_team_admin ], write : [ itoa_admin, itoa_team_admin ], delete : [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_notable_event_actions_registration_lookup]
access = read : [ itoa_admin, itoa_team_admin ], write : [ itoa_admin, itoa_team_admin ], delete : [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_entity_relationships_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_entity_relationship_rules_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_entity_filter_rules_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_services_in_team_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_service_template_sync_status_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[transforms/itsi_kpi_alert_value_cache]
access = read : [ itoa_admin, itoa_team_admin ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin ]
export = system
[transforms/custom_threshold_window_telemetry_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write: [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin ]
export = system
[transforms/calculation_window_telemetry_lookup]
access = read : [ itoa_admin, itoa_team_admin, itoa_analyst, itoa_user ], write : [ itoa_admin, itoa_team_admin ], delete: [ itoa_admin, itoa_team_admin ]
export = system
[commands/itsichangerulesengineprocess]
access = read : [ admin, sc_admin, itoa_admin ], write : [ admin, sc_admin, itoa_admin ]
export = system
## shared Application-level permissions
[]
access = read : [ * ], write : [ admin, sc_admin ]
export = system
[savedsearches]
owner = admin
[governance]
access = read : [ * ], write : [ * ]
## Postprocess
[postprocess]
access = read : [ * ], write : [ * ]
## Exclude export of custom alert actions
[alert_actions/email]
export = none