Control-M Automation API Authorizations

Control-M enables you to control what users are authorized to view or change via Control-M Automation APIs and services, based on the roles and users that you define. The following tables summarize the required access control categories and levels for several API Operation.

You must define role authorizations in the Roles tab in the Configuration domain, as described in Adding a Role.

Session Service Authorizations

The following table lists the Interface Access categories required by the API Session service. You set these access levels through the role definitions in the Configuration domain, on the General tab.

API Operation

Interface Access Category

Log In, Log Out, and Get Access Tokens

Automation API

Alternatively, for product versions earlier than 9.0.20 or when using Compatibility mode:

Control-M Configuration Manager

Control-M Desktop, Utilities and EM API

Authentication Service Authorizations

To use the Authentication service to create, update, delete, or get details of your own tokens, you must have the Automation API interface access category. You set this access category through the role definitions in the Configuration domain, on the General tab.

To use the Authentication service to control authentication tokens of other users, an administrator must have the following role access levels. You set these access levels through the role definitions in the Configuration domain, on the Access Control tab.

API Operation

Access Control Category

Access Level

Retrieve Token Details

All:

Configuration > Admin Management > Authorizations/ Users & Roles

All:

Browse

Create or Update Tokens

All:

Configuration > Admin Management > Authorizations/ Users & Roles

All:

Update

Delete Tokens

authentication token::delete

All:

Configuration > Admin Management > Authorizations/ Users & Roles

All:

Full

Configuration Service Authorizations

The following table lists the role access levels required by the various API operations in the Config service. You set these access levels through the role definitions in the Configuration domain, on the Access Control tab.

If the access levels are defined through Configuration > Admin Management differ from (that is, are higher or lower than) those defined in the other Configuration categories, such as Configuration > Agents or Configuration > Plug-ins, or Configuration > Run as Definition, then the definitions in Admin Management take precedence.

API Operation

Access Control Category

Access Level

Access Control-M/Server Details

All:

Configuration > Admin Management > Configuration

All:

Browse

Add or Update Control-M/Servers

All:

Configuration > Admin Management > Configuration

All:

Update

Delete Control-M/Servers

All:

Configuration > Admin Management > Configuration

All:

Full

Access Agent and Agentless Host Details

All:

Configuration > Agents

All:

None

Access Agent Information

All:

Configuration > Agents

All:

Browse

Access and Update Detailed Agent Configuration Information

All:

Configuration > Agents

All:

Full

Manage Agent Certificates

All:

Configuration > Admin Management > Configuration

As Follows:

  • Browse

  • Browse

  • Browse

  • Browse

  • Update

  • Full

Add or Update Agents

All:

Configuration > Agents

All:

Update

Delete Agents and Agentless Hosts

All:

Configuration > Agents

All:

Full

Access Run as User Configuration Information

All:

Configuration > Run as Definition

All:

Browse

Add or Update Run as Users

All:

Configuration > Run as Definition

All:

Update

Delete Run as User Configuration

config server:runasuser::delete

All:

Configuration > Run as Definition

All:

Full

Perform High Availability Actions

All:

Configuration > Admin Management > Configuration

All:

Update

Get High Availability Status

All:

Configuration > Admin Management > Configuration

All:

Browse

Access Detailed Job Archiving Configuration

All:

Configuration > Admin Management > Configuration

All:

Browse

Manage Configurations of Job Archiving

All:

Configuration > Admin Management > Configuration

All:

Update

Access Configurations for File Transfers Between External Users (Control-M MFT Enterprise B2B)

All:

Configuration > Plug-ins

All:

Browse

Manage Control-M MFT Enterprise B2B Configurations

All:

Configuration > Plug-ins

All:

Update

Delete Control-M MFT Enterprise B2B Configurations

All:

Configuration > Plug-ins

All:

Full

Access Configurations for File Transfers Between Remote Hosts (Control-M MFT)

All:

Configuration > Plug-ins

All:

Browse

Add or Delete Configurations for Control-M MFT

All:

Configuration > Plug-ins

All:

Full

Update Configurations for Control-M MFT

All:

Configuration > Plug-ins

All:

Update

Manage SSH settings for Control-M MFT

All:

Configuration > Admin Management > Security

All:

Full

Access Details of Roles, Users, and LDAP Groups

All:

Configuration > Admin Management > Authorizations/ Users & Roles

All:

Browse

Manage Role, Users, and LDAP Group Authorizations

All:

Configuration > Admin Management > Authorizations/ Users & Roles

For simulation functions, also:

Configuration > Admin Management > Configuration

All:

Update

Delete Role and User Authorization

All:

Configuration > Admin Management > Authorizations/ Users & Roles

All:

Full

Access System Settings Details

All:

Configuration > Admin Management > Configuration

All:

Browse

System Settings

config systemsettings::set

Configuration > Admin Management > Configuration

Update

Access Control-M Vault Secrets Details

config secrets::get

Tools > Secrets

Browse

Add or Update Control-M Vault Secrets

All:

Tools > Secrets

All:

Update

Delete Control-M Vault Secrets

config secret::delete

Tools > Secrets

Full

Provision Service Authorizations

The following table lists the role access levels required by the various API operations in the Provision service. You set these access levels through the role definitions in the Configuration domain, on the Access Control tab.

If the access levels defined through Configuration > Admin Management differ from (that is, are higher or lower than) those defined in the other Configuration categories, such as Configuration > Agents or Configuration > Run as Definition, then the definitions in Admin Management take precedence.

API Operation

Access Control Category

Access Level

Provision Control-M/Servers

All:

Configuration > Agents

and

Configuration > Run as Definition

All:

Update

Access Provisioned Agent Details

provision images

Configuration > Agents

Browse

Provision New Agents

All:

Configuration > Agents

All:

Update

Undo Agent Provisions

All:

Configuration > Agents

All:

Full

Upgrade Existing Agents and Deploy Plug-ins

All:

Configuration > Agents

All:

Full

Access Agent Upgrade Details

All:

Configuration > Agents

All:

Browse

Build and Deploy Service Authorizations

The following table lists the role access levels required by the various API operations in the Build and Deploy services. You set these access levels through the role definitions in the Configuration domain, on the Access Control tab.

If the access levels defined through Configuration > Admin Management differ from (that is, are higher or lower than) those defined in the other Configuration categories, such as Configuration > Connection Profiles, then the definitions in Admin Management take precedence.

API Operation

Access Control Category

Access Level

Build Job Definitions

build

Access tokens are enough.

Retrieve Deployed Job Definitions

deploy jobs::get

Planning > Folders and Jobs

Browse level on all retrieved folders

  • Server: All

  • Folder Name: *

  • Access Level: Browse

Deploy Control-M Objects Definitions

Planning > Folders and Jobs

Update level on all folders deployed

  • Server: All

  • Folder Name: *

  • Access Level: Update

Planning > Run as

Grant permission to write jobs that Run as use on specific hosts as required by all jobs deployed.

  • Server: All

  • Run as Name or Pattern: *

  • Agent/Host Group: *

Tools > Calendars

Update level on all calendars deployed

  • Server: All

  • Calendar Name: *

  • Access Level: Update

Tools > Site Standards

Update level for all site standards deployed.

Update level for site standard policies.

Configuration > Connection Profiles

Full level on all connection profiles deployed if you plan to create new connection profiles. Update level if you only want to modify existing connection profiles.

  • Server: All

  • Name: *

  • Access Level: Full or Update

Delete Deployed Objects

All:

Planning > Folders and Jobs

Full access level on all folders to delete

  • Server: All

  • Folder Name: *

  • Access Level: Full

Deploy AI Job Type

deploy ai:jobtype

Tools > Application Integrator

Full

Retrieve Deployed AI Job Type Details

deploy ai:jobtypes::get

Deploy Control-M Integration Plug-ins

deploy jobtype

Tools > Application Integrator

Browse

Retrieve Deployed Calendar Definitions

deploy calendars::get

Tools > Calendars

Browse access level on all calendars to retrieve

  • Server: All

  • Calendar Name: *

  • Access Level: Browse

Delete Deployed Calendars

deploy calendar::delete

Tools > Calendars

Full access level on all calendars to delete

  • Server: All

  • Calendar Name: *

  • Access Level: Full

Retrieve Deployed Connection Profile Details

All:

Configuration > Connection Profiles

Browse access level on all connection profiles to retrieve

  • Server: All

  • Name: *

  • Plug-in Type: All plug-ins

  • Access Level: Browse

Delete Deployed Connection Profiles

All:

Configuration > Connection Profiles

Full access level on all connection profiles to delete

  • Server: All

  • Name: *

  • Plug-in Type: All plug-ins

  • Access Level: Full

Test Deployed Connection Profiles

deploy connectionprofile::test

Retrieve Site Standard and Site Standard Policy Details

All:

Tools > Site Standards

Browse level for all site standards deployed.

Browse level for site standard policies.

Add Site Standard Policies

deploy sitestandardpolicies::add

All:

Tools > Site Standards

Site Standard Policies: Update

Rename or Delete Site Standards and Site Standard Policies

All:

Tools > Site Standards

All Deployed Site Standards: Full

Site Standard Policies: Full

Run Service Authorizations

The following table lists the role access levels required by the various API operations in the Run service. You set these access levels through the role definitions in the Configuration domain, on the Access Control tab.

API Operation

Access Control Category

Access Level

Access Job Statuses and Details

All:

Monitoring > Job Permissions

All View options for all jobs.

Perform Job Actions

All:

Monitoring > Job Permissions

All Actions and View options for all relevant jobs.

Run Job Definition Files

Planning > Folders and Jobs

Update level on all folders deployed

  • Server: All

  • Folder Name: *

  • Access Level: Update

  • Run checkbox selected

 

Planning > Run as

Grant permission to write jobs that Run as a user on specific hosts, as required by all jobs deployed.

  • Server: All

  • Run as Name or Pattern: *

  • Agent/Host Group: *

run ondemand

Monitoring > Job Permissions

Actions > Confirm

Order Deployed Folders and Jobs

run order

Planning > Folders and Jobs

Update level on all folders deployed

  • Server: All

  • Folder Name: *

  • Access Level: Update

  • Run checkbox selected

Retrieve Events

run events::get

Tools > Events

Browse level for events retrieved

  • Server: All

  • Event Name: *

  • Access Level: Browse

Add Events

run event::add

Tools > Events

Update level for events to add

  • Server: All

  • Event Name: *

  • Access Level: Update

Delete Events

run event::delete

Tools > Events

Full access level for events to delete

  • Server: All

  • Event Name: *

  • Access Level: Full

Retrieve Resources

run resources::get

Tools > Resource Pool

At least Browse level for resource pools retrieved

  • Server: All

  • Resource Name: *

  • Access Level: Browse

 

Tools > Lock Resources

At lease Browse level for lock resources retrieved

  • Server: All

  • Resource Name: *

  • Access Level: Browse

Add and Update Resources

All:

Tools > Resource Pool

Update level for resource pools updated

  • Server: All

  • Resource Name: *

  • Access Level: Update

Delete Resources

run resource::delete

Tools > Resource Pool

Full level for resource pools deleted

  • Server: All

  • Resource Name: *

  • Access Level: Full

Retrieve Workload Policy Details

All:

Tools > Workload Policies

All:

Browse

Add and Manage Workload Policies

All:

Tools > Workload Policies

All:

Update

Delete Workload Policies

run workloadpolicy::delete

Tools > Workload Policies

Full

Retrieve Pool Variable Details

run variables::get

Tools > Pool Variables

Browse

Define and Update Pool Variables

run variables::set

Tools > Pool Variables

Update

Delete Pool Variables

run variables::delete

Tools > Pool Variables

Full

Update Alerts

All:

Alerts

All:

Update