Security

This section includes the security requirements for access to Genesis Navigation and Genesis Designer as well as additional requirements to perform specific actions on these pages. Security requirements are also listed for solution administrators to install Genesis and manage libraries and instances in Settings. See these sections:

Genesis Navigation

To access Genesis Navigation, you must be in the following security groups:

  • Access Group on the Dashboard Profile {Genesisinstancename} Navigation. By default, it is set to Everyone.

  • Access Group on the Genesis instance Workspace. By default, it is set to Everyone.

The following table includes additional security requirements to perform specific actions in Genesis Navigation.

Actions Security Requirements
View Application Groups in the drop-down menu
  • Access Group on the Application Group settings

  • Hide set to No on the Application Group settings

View a Navigation Group in the navigation bar or a Page in the page bar
  • Access Group on the Navigation Group or Page settings

  • No Access Type set to Hide on the Navigation Group or Page settings

  • Hide set to No on the Navigation Group or Page settings

You can configure the display of a Navigation Group in the navigation bar or a Page in the page bar for users without access. When these users select the item, they will see a message indicating they do not have access. To configure this option, follow these instructions in the settings:

  1. In the Access Group drop-down menu, select the security group.

  2. In the No Access Type drop-down menu, select ShowBanner.

  3. In No Access Banner, type banner_NoAccess_(App)_(Main).

  4. In the Hide drop-down menu, select No.

View linked content or an injected Content Block on a Page You must have the security requirements of the content based on standard platform configuration to view the data and objects configured for the Page. For example, to view a Cube View, a user must have access to that Cube View and its cube data.

Genesis Designer

To access Genesis Designer, you must be in the following security groups:

  • Access Group on the Dashboard Profile {Genesisinstancename} Designer. By default, it is set to Everyone.

  • Access Group on the Genesis instance Workspace. By default, it is set to Everyone.

In addition, members of these security groups can also complete the following actions in Genesis Designer.

  • On the Navigation page, you can edit Application Group, Navigation Group, and Page settings. You can also delete Navigation Groups, Pages, linked content, or injected Content Blocks.

  • On the Colors page, you can view settings and apply, copy, edit, and delete color sets.

  • On the Styles page, you can view and save settings.

  • You can view the Image Library.

The following sections include additional security requirements to perform more actions in Genesis Designer. See these sections:

Navigation

The following table includes additional security requirements to perform specific actions in Genesis Designer > Designer Home > Navigation.

Actions Security Requirements
  • Add Navigation Groups and Pages

  • Link existing content to a Page

  • Inject a Content Block to a Page

Application security role ManageApplicationWorkspaces

Configure settings for injected Content Blocks

Any security requirements listed in the Content Block Guide, which is in the Content Library on the Details page. You can also view and download the guide in OneStream Solution Exchange.

View content on the Preview tab

  • Access Group on the Genesis Application Group, Navigation Group, and Page

  • Security requirements of the content based on standard platform configuration

View content on the Content tab

Security requirements of the content based on standard platform configuration

Content Management

The following table includes additional security requirements to perform specific actions in Genesis Designer > Designer Home > Content Management.

Actions Security Requirements

Inject Content Blocks

Application security role ManageApplicationWorkspaces

Delete Content Blocks Maintenance group on the Genesis instance Workspace

Image Library

The following table includes additional security requirements to perform specific actions in Genesis Designer > Image Library.

Actions Security Requirements
  • Add new images

  • Replace existing images

You must meet one of the following requirements:

  • System security group Administrators

  • Application security role AdministerApplication

Delete images

Maintenance Group on the Genesis instance Workspace

Solution Administration

To install Genesis, you must meet one of the following requirements:

  • System security group Administrators

  • Application security role AdministerApplication and application user interface role ApplicationLoadExtractPage

To view the Settings page and manage the instance and libraries, you must be in the system security group Administrators.