About Connection Role Security

Admins can use Connection Roles to control whether regular users can access a Connection. Users without access, won't see the Connection and will get a macro error if they try to run a macro that requires that Connection.  CRON-initiated Schedules are a special case (see below).

For example, an Admin wants to allow only some users to access a specific LogicMonitor Connection. The Admin adds those users to a relevant Role (with Role Permissions) and ensures the Read permission checkbox is not selected. Read permission grants the user access to the Connection when running macros, or when using the [ReportMagic.ConnectionList:] macro.

Note: Connection Roles are unrelated to the ability to run restricted macros.

Unrestricted and Restricted Connections

A Connection is unrestricted - accessible to all users - when any of these apply:

  • The Connection has no associated Connection Roles (see below)
  • The Connection has one or more Connection Roles without an associated Role
  • The Connection has one or more Connection Roles with a Role, but the Role has no Role Permissions

A connection is restricted when it has a fully configured Connection Role (a Connection Role linked to a Role with at least one Role Permission).

Restricting Access to a Connection

To restrict access to a Connection an Admin should do the following:

Step 1 - Create Roles and Permissions

To set up the relevant Roles, Role Permissions and Role Memberships:

  1. From the Admin menu, click Access Control.
  2. Create a new Role if required, or choose an existing one.
  3. Click the Create button to add a Role Permission.
  4. Add a name and description, then in the Type drop-down, choose Connection.
  5. Select Read to make the Connection visible, or leave the box clear to deny access.
  6. Select the relevant Role.
  7. In the Role Memberships section, assign regular users to the Role.

Note: Role Permissions are 'additive' - If one permission allows read access, read is granted regardless of any other permissions that deny it.

Step 2 - Connections and Connection Roles

To set up the relevant Connection Roles, follow these steps:

  1. Ensure you have set up your Connection as required.
  2. From the Admin menu, click Connections. 
  3. Scroll down to the Connection Roles section and click Create to open the dialog box.
  4. Enter a name and description.
  5. Select the Connection that you want to restrict.
  6. In the Role drop-down, select the Role to associate it with.
  7. Save to restrict the Connection to users of that Role.
  8. From the Admin Connection Roles table shows whether the Connection is restricted or unrestricted, and what the restrictions are.

Who Can Access Connections?

As above, Admins can use Connection Roles to prevent users using certain Connections. Access rules differ depending on how a macro is being run.  

Connections used by macros in a manually-run Schedule

A Connection is accessible (visible and usable by macros) if any of the following are true:

  • The user is a Tenant Admin, Super Admin, or Uber Admin
  • The Schedule has been locked by an Admin. See Schedules for more information.
  • The Connection is unrestricted, that is:
    • There are no Connection Roles associated with the Connection
    • There are Connection Roles but none are associated with any Role (by way of Role Permissions)
  • The Connection is restricted but the user has at least one Role with Read permission for that Connection

Connections used by macros in Report Studio

A Connection is accessible if any of the following are true:

  • The user is a Tenant Admin, Super Admin, or Uber Admin
  • The Connection is unrestricted, that is:
    • There are no Connection Roles associated with the Connection
    • There are Connection Roles but none are associated with any Role (by way of Role Permissions)
  • The Connection is restricted but the user has at least one Role with Read permission for that Connection

Connections used by macros in a CRON-initiated Schedule

Since CRON-initiated Schedules do not run on behalf of a specific user, user-level Role membership is not evaluated. A CRON-initiated Schedule can access a Connection if any of the following are true:

  • The Schedule has been locked by an Admin. See Schedules for more information.
  • The Connection is unrestricted, that is:
    • There are no Connection Roles associated with the Connection
    • There are Connection Roles but none are associated with any Role (by way of Role Permissions)

Reconnection

Reconnection

Reconnection

timed out

timed out

Attempt of

Reload
An unhandled error has occurred. Reload 🗙