CA Workflow has a role called SuperUser that allows users with this access to do things as a proxy for others. It is authorized through an Access Policy class called "Worklist" in EEM. This Access Policy is not created in the Service Desk application definition for EEM. It is created in the Service Catalog R12 EEM application definition. Therefore creating the "Worklist" Access Policy should allow this function to work.
- Open the EEM administration GUI and login to the ServiceDesk Application instance.
- Select the Configure Tab; then the ServiceDesk instance under Applications.
- Click the Add Resource Class button. For the name enter Worklist. In the Add action box enter "superuser" in all lowercase and click the + symbol.
Save the resource class.
- Select the Manage Identities tab; Click Groups; then click the Go button to return the available groups. Click on the New Application Group button.
Create a new group called "Worklist Superuser" and Save.
- Select the Manage Access Policies tab and Click on New policy icon for the Worklist Access Policy. Be careful to click the New Access policy icon for Worklist:
In the name field enter 'SuperuserPolicy' and a description if you would like.
In the Identities section, choose Type: Application Group, Click the Search Identities link and then click the Search button.
Highlight the Worklist Superuser and move it to Selected Identities. In the Access Policy configuration section, check the superuser checkbox under actions.
Save the Access Policy.
- Select the Manage Identities tab, click Users and search for the user whom you want to make a Superuser. Select the user and add the Worklist Superuser group to the Selected User Groups box, then save the changes to this user.
Restart Workflow engine with the commands:
pdm_tomcat_nxd -d STOP -t CAWFpdm_tomcat_nxd -d START -t CAWF
Or restart Service Desk Service which will recycle the Workflow engine.
- Login to the Worklist as the User with Superuser group permissions and confirm Superuser functionality. You will see a new button Change Role button:
Which gives you access to select from any and all EEM users and will give access to that user or group's worklist where the Superuser account can perform activities as if they had logged in as that other user or belonged to the assigned group.