User's Manual

An application with the same name as the Shared Services project. This application allows
you to specify security at the Analytic Server level, and is known as the global Analytic
Server application.
A Shared Services application for each Essbase application on the Analytic Server. In Shared
Services, if an Essbase application contains multiple databases, the databases must have the
same user security access levels. (However, users can have different calculation script and
database filters assigned for databases within the same application. See “Assigning Database
Calculation and Filter Access” on page 151).
Once you have migrated to Shared Services, when you create a new application and database in
Essbase, a corresponding Shared Services application is created within the Analytic Server project
and the application is automatically registered with Shared Services.
Essbase Users and Groups in Shared Services
When you migrate to Shared Services, all native Essbase users and groups that do not already
exist in an external authentication directory are converted to native Shared Services users and
groups in the native Shared Services user directory and are given equivalent roles. Any externally-
authenticated users are registered with Shared Services but are still stored in their original
authentication directory. For more information on migrating users and groups, see the Hyperion
Essbase - System 9 Database Administrator's Guide.
Note:
Shared Services supports aggregated groups, in which a parent group contains one or more sub-
groups. The sub-groups inherit the roles of their parent group. For example, if a parent group
is provisioned with the Essbase Administrator role, any sub-groups (and users in the groups)
inherit the Essbase Administrator role.
Once you have migrated to Shared Services, you must create and manage users and groups in
User Management Console, or through the external authentication provider.
Note:
If manual user synchronization is specified, when you provision a user with an Analytic Server
role, you must request a refresh of security information to enable the user to log in. For
information on manual user synchronization, see the Hyperion Essbase - System 9 Database
Administrator's Guide.
Assigning Database Calculation and Filter Access
After provisioning users for Essbase applications in User Management Console, you can assign
more granular access permissions to users and groups for a specific Essbase application and
database. For example, after assigning a user access to an application and assigning the user’s
Essbase Users and Groups in Shared Services
151