How to restrict few users or groups from using specific objects in CA ServiceDesk Universe?

Document ID : KB000054200
Last Modified Date : 14/02/2018
Show Technical Document Details


The CA ServiceDesk universe is grouped into objects which access data from ServiceDesk MDB database. At times not all the users are authorized to use all the objects and attributes in the reports. This document explains the steps for providing object level security in CA Business Intelligence.


There are many objects in the CA ServiceDesk universe. All the objects can be accessed by all the users by default. Any users can select and add an object to an existing report or a new report and view the data by running the report. However, this can be avoided by implementing object level security on the CA ServiceDesk universe.

Object-level security is based on restricting a user from viewing and selecting a specific object in the query panel. By restricting access to an object within the universe, the user will not be able to see the object in the query panel.

Steps to implement object security:

  1. Login to Designer on the CA Business Intelligence Server as Administrator

  2. Click on File->Import, In the import window click on Browse and select CA Universes folder. See Fig 1

    Fig 1
    Figure 1

  3. Click Ok to import the Universe.

  4. After the universe is imported, click on Tools->Manage Security->Manage Access Restrictions

  5. In the Manage Access Restrictions windows, click on New to create a new access restriction. See Fig 2

    Fig 2
    Figure 2

  6. In the Edit Restriction Window, enter a name for the restriction.

  7. Go to Objects tab, click on Add.

  8. In the New Restricted Object pop up, click on Select button. See Fig 3

    Fig 3
    Figure 3

  9. Select the object or the attributes which you want to restrict and click Ok See Fig 4

    Fig 4
    Figure 4

  10. Click Ok

  11. Click Ok to close the Edit Restriction window

  12. In the Available Users and Groups section click on Add User/group. See Fig 5

    Fig 5
    Figure 5

  13. From the Available list of users and groups section, select the user or group to restrict and move it to the Selected Users and Groups section and click on OK. See Fig 6

    Fig 6
    Figure 6

  14. Click on Apply to add the restrictions

  15. Click Ok to close the Manage Access Restrictions Window

  16. From the File menu select Save to save the universe.

  17. From the File menu, select Export

  18. In the Export Universe window, leave the default settings and click OK to export the universe.

  19. When a user of ServiceDesk Manager group tries to modify any web intelligence report, in the query panel the restricted object is no longer visible. See Fig 7

    Fig 7
    Figure 7

    In the above screenshot, the issue object is no longer visible.