Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Show Page Sections

Concept

This process allows managing all the information that is not related to the lifecycle of a workspace:

Set up of the access rights of CPQ users. You will precisely customize the type of objects the user can access as well as the actions he is authorized to perform (which steps will be accessible) depending on his role within a team.

The Access rights settings in CPQ are managed by several entities. A user is an entity that can connect to the application.

Note: One user is created by default in the system with a default role - named SSODefaultRole - with limited rights (for security reasons). This Administrator can have its rights extended on-demand (via a ticket to PROS Cloud Services) with all administrative rights in order to create new users, new teams and new roles.

A User is attached to one or several Teams.

The Team defines which Users are working on the same Project (or set of Projects) (Team Assignment).

Within the team, each user has one or several Roles (Administrator, Translator ...). The roles list the accessible type of projects, processes and steps.

A role can be attributed to one or several users (belonging to the same or different teams).



Note: A role is created by default in the system: SSODefaultRole. This role is mandatory for the proper operation of the system and MUST NOT be deleted. Its content can be amended by the administrator to reduce the associated rights, but it MUST be there in the system.
Note: Before entering the various step of the ‘Administer Workgroup’ process, please make sure that:
  • Your current environment in CPQ is correctly set (Team/Workspace/Release/Language)
  • You have created a Workgroup Project in the Dashboard

    At least one workgroup with one user with administrator role must exist. It is thus impossible to delete the default workgroup and administrator user

Defining the Roles

In this step you create Roles that will be attributed to users. Each role gathers the steps a user can access. To sum up, it defines the user responsibilities on the various kinds of projects.

When defining Roles keep in mind that more than one roles can be associated to a user.

Note: The default role (created by the system) - SSODefaultRole - MUST NOT be deleted. However, you can edit it to modify the associated rights to suit your needs.

Create the Users’ roles

  • [Via the Menu Toolbar – Group New]
    • Click on the New ‘Role’ icon.
  • [In the popup]
    • Enter the Role Name and Description
  • Save
    • The new role appears in the ‘Explore Structure’ explorer

Customize the Users’ roles

For each defined role and for each project, you will tick the steps on which you grant access to the user.

You have the possibility to grant access to ‘All steps’ of the projects or to select only a subset of steps.

Moreover, you have the possibility for a given project type to authorize the Creation, the Deletion of project (‘All Steps’ Create and Delete associated check box.)

  • [Via the ‘Explore Structure’ explorer]
    • Select the User role you want to define

In the working area, for each section representing a project, you will customize the access rights. By default, All steps of All projects are accessible. Please refine these settings if needed for each project type.

  • Expand the section associated to a project type
  • Fill the ‘All steps’ line:
    • Tick the Create checkbox to authorize the creation of a project of the selected type.
    • Tick the Delete checkbox to authorize the deletion of a project of the selected type.
      • Uncheck the Updatable box if you want to customize the access to the different steps of the project
  • If ‘All steps’ Updatable check box is unchecked, you can customize precisely on which steps the role grants access rights.
    • Tick the checkboxes of each step that you want to access using this role.
  • Save
    Note: Please make sure that the access rights settings are coherent.

    E.g. if a role allows to access the ‘Manage Collections’ – ‘Manage Products’ step, it is recommended to allow accessing the ‘Design Product’ processes.