[next] [previous] [contents]

  9. Managing System User Classes
  This chapter describes how to use SysWorks to manage
  system user classes.

  Note that the set of system user classes provided with
  SysWorks is normally sufficient for most organizations, so
  a full understanding of how they work is generally unneces-
  sary.

  The system user class management menu is selected using
  Manage
) System User Classes from the session man-
  ager. It displays the menu illustrated in
Figure 9-1 and
  prompts for a selection.

  The following concepts need to be understood before manag-
  ing system user classes:

  .
        Layered Products - see
Section 6.4

  The following standard pre-defined System User Classes
  exist:


  System User Class Usage



  ACMS ACMS user - provides access to ACMS.
  ALL All users - provides base level functions
                                        for all users.
  ALLIN1 All-In-1 user - provides access to All-
                                        In-1.
  APPLICATION Applications - provides base level func-
                                        tions for all applications.
  BASE Automatically granted to provide basic
                                        OpenVMS authorization details.
  CAPTIVE Captive users - provides reduced base
                                        level functions for captive users.
  DBA Database Administrator - allows a
                                        users to use the SysWorks database
                                        administration features.
  DCL DCL user - allows a user access to
                                        DCL. Note that this system user class is
                                        only necessary when the USER system
                                        user class does not allow access to DCL
                                        by default.
  DEVELOPER Allows a users to use the SysWorks
                                        development features.
  GROUP Groups - provides base level functions
                                        for all groups.
  OPERATOR Operator - almost full read access
                                        and limited read/write access to all
                                        information.
  PATHWORKS Pathworks user - provides access to
                                        Pathworks including LAN Manager,
                                        PCSA and Macintosh variants.
  PRINTER_CONTROLLER Printer controller - may start and stop
                                        print queues and print jobs.
  SYSTEM_MANAGER System manager - full read/write
                                        access to all information.
  USER User recognized by SysWorks - All
                                        users should be a member of this sys-
                                        tem user class - the exception being
                                        Digital and other third party product
                                        usernames.
  USER_REGISTRAR User registrar - may add, create, delete
                                        and remove users from clusters and the
                                        security domain. Note that although a
                                        user registrar may register any user,
                                        they may only grant access to system
                                        user classes which they are a member
                                        of. Thus only members of the SYSTEM_
                                        MANAGER system user class may reg-
                                        ister other system managers. The
                                        exception to this rule is that a member
                                        of the SYSTEM_MANAGER system
                                        user class is an implicit member of all
                                        system user classes, so they can grant a
                                        user access to any system user class.