Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Roles in PROS Home

Roles are used to define access permissions on applications.

To display roles available for Performance Quoting, click on Admin/Roles & Groups from PROS Home. Then, select the Quoting application in the left bar.

Two columns are displayed:

  • Roles - role name
  • Groups - groups allowed for a given role


List Performance Quoting Roles

There are 2 types of roles in Performance Quoting:

  • UI roles: To access Performance Quoting UI (prefixed by UI_)
  • API roles: To call the Performance Quoting public APIs. There are 2 ways to get a token to call these APIs:
    • Using another PROS application credentials (application ID and secret)
    • Using a service account that belongs to a specific tenant. The service account is secured by a private key/certificate.
ROLESOURCE APP/SERVICESOURCE TYPEADDITIONAL FEATURESDESCRIPTION
AGREEMENTAgreement servicePROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from the agreement application
API_SUPER_USERAny user that wants to call the public APIService AccountNoneThis role is provided by the AppPortal token when the call is made with an api_user service account. This type of service accounts can be used to call any public API method for all use cases not covered by the roles above (Specific customer integration, etc.). In addition to the API_USER role, this role can execute APIs with the system mode activated and disable the context data provider.
API_USERAny user that wants to call the public APIService AccountNoneThis role is provided by the AppPortal token when the call is made with an api_user service account. This type of service accounts can be used to call any public API method for all use cases not covered by the roles above (Specific customer integration, etc.)
CRMSalesForce or Dynamics CRMService AccountImpersonate a user with the public API* only if the call comes from a known CRM package, this is verified by an additional key and is only for internal useThis role is provided by the AppPortal token when the call is made with a CRM service account. Normally these service accounts will be only shared with CRM admins but additional security checks can ensure that the call is coming from this CRM and from the PROS managed package and that the userID set in the public API header is not fake.
DESIGNERDesigner virtual machinesService AccountNoneThis role is provided by the AppPortal token when the call is made with a designer service account configured on a designer Virtual machine. In this case, all API calls are technical and target non-user-specific actions (Store a model, validate a model, Update the model matrix, etc.).
DOCGEN_DESIGNERDocGen DesignerPROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from the DocGen designer application
DOMAINSDomain ServicePROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from the domain application
DOMAINS_DESIGNERDomain DesignerPROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from the Domains designer application
ECOMMERCEECommercePROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from the ECommerce application
INTERNALPerformance QuotingPROS ApplicationImpersonate a user with the public API*This role is used for calls from one Performance Quoting service to another.
LEGACYSmart CPQPROS ApplicationImpersonate a user with the public API*This role is automatically used when the call comes from Smart CPQ
QUOTE_DESIGNERQuote DesignerPROS ApplicationThis role is automatically used when the call comes from the Quote Designer
UIUsed to allow users to open the performance quoting user interface
UI_DESIGNERThis role allows a user who already has a UI role to benefit from troubleshooting aids such as: Logs messages directly on the UI of the quote The error inspector in the UI of the quote The bootstrap page This role should be reserved for expert users who also have the QUOTE_DESIGNER role, meaning they are able to understand these troubleshooting aids and use them to correct the quote design. This role should not be assigned to ordinary end-users of the quote.

Information: To allow a user to use Performance Quoting, only the UI role needs to be setup. You need to list all groups allowed to open Performance Quoting UI. All roles without the UI prefix are only used for Service Accounts.

(*)User Impersonation: Impersonate a user with the public API means the ability to make a request on behalf of a user (using it's userID). This is useful when the user is already authenticated in a CRM (ex: SalesForce) or another PROS application, and this application uses the public API to communicate with Performance Quoting service.

Multiple Roles: To avoid security leaks. Only AppPortal tokens with one role will be authorized for requests to the public API.