Roles in PROS Home
Roles are used to define access permissions on applications.
To display roles available for Performance Quoting, click on Admin/Roles & Groups from PROS Home. Then, select the Quoting application in the left bar.
Two columns are displayed:
- Roles - role name
- Groups - groups allowed for a given role
List Performance Quoting Roles
There are 2 types of roles in Performance Quoting:
- UI roles: To access Performance Quoting UI (prefixed by UI_)
- API roles: To call the Performance Quoting public APIs. There are 2 ways to get a token to call these APIs:
- Using another PROS application credentials (application ID and secret)
- Using a service account that belongs to a specific tenant. The service account is secured by a private key/certificate.
| ROLE | SOURCE APP/SERVICE | SOURCE TYPE | ADDITIONAL FEATURES | DESCRIPTION |
|---|---|---|---|---|
| AGREEMENT | Agreement service | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from the agreement application |
| API_SUPER_USER | Any user that wants to call the public API | Service Account | None | This role is provided by the AppPortal token when the call is made with an api_user service account. This type of service accounts can be used to call any public API method for all use cases not covered by the roles above (Specific customer integration, etc.). In addition to the API_USER role, this role can execute APIs with the system mode activated and disable the context data provider. |
| API_USER | Any user that wants to call the public API | Service Account | None | This role is provided by the AppPortal token when the call is made with an api_user service account. This type of service accounts can be used to call any public API method for all use cases not covered by the roles above (Specific customer integration, etc.) |
| CRM | SalesForce or Dynamics CRM | Service Account | Impersonate a user with the public API* only if the call comes from a known CRM package, this is verified by an additional key and is only for internal use | This role is provided by the AppPortal token when the call is made with a CRM service account. Normally these service accounts will be only shared with CRM admins but additional security checks can ensure that the call is coming from this CRM and from the PROS managed package and that the userID set in the public API header is not fake. |
| DESIGNER | Designer virtual machines | Service Account | None | This role is provided by the AppPortal token when the call is made with a designer service account configured on a designer Virtual machine. In this case, all API calls are technical and target non-user-specific actions (Store a model, validate a model, Update the model matrix, etc.). |
| DOCGEN_DESIGNER | DocGen Designer | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from the DocGen designer application |
| DOMAINS | Domain Service | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from the domain application |
| DOMAINS_DESIGNER | Domain Designer | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from the Domains designer application |
| ECOMMERCE | ECommerce | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from the ECommerce application |
| INTERNAL | Performance Quoting | PROS Application | Impersonate a user with the public API* | This role is used for calls from one Performance Quoting service to another. |
| LEGACY | Smart CPQ | PROS Application | Impersonate a user with the public API* | This role is automatically used when the call comes from Smart CPQ |
| QUOTE_DESIGNER | Quote Designer | PROS Application | This role is automatically used when the call comes from the Quote Designer | |
| UI | Used to allow users to open the performance quoting user interface | |||
| UI_DESIGNER | This role allows a user who already has a UI role to benefit from troubleshooting aids such as: Logs messages directly on the UI of the quote The error inspector in the UI of the quote The bootstrap page This role should be reserved for expert users who also have the QUOTE_DESIGNER role, meaning they are able to understand these troubleshooting aids and use them to correct the quote design. This role should not be assigned to ordinary end-users of the quote. |
Information: To allow a user to use Performance Quoting, only the UI role needs to be setup. You need to list all groups allowed to open Performance Quoting UI. All roles without the UI prefix are only used for Service Accounts.
(*)User Impersonation: Impersonate a user with the public API means the ability to make a request on behalf of a user (using it's userID). This is useful when the user is already authenticated in a CRM (ex: SalesForce) or another PROS application, and this application uses the public API to communicate with Performance Quoting service.
Multiple Roles: To avoid security leaks. Only AppPortal tokens with one role will be authorized for requests to the public API.
