Spotfire® Server and Environment Security

Roles

Groups define standard roles for administering and using Spotfire. Each special group enables a set of licenses that correspond to an administrative or user role. To assign a role to a user, just add the user to one of the special groups in the following list.

Group Description
Administrator¹ Members of this group can set library permissions, preferences, licenses, manage users and memberships on the system. Only users who need administrator privileges on Spotfire Server, including the ability to manage users and groups, should belong to this group.
Library Administrator¹ Members of this group are granted full permission to the library. It overrides all folder permissions set in the library, granting full control over content. It also includes the permission to import and export library content. Only users and groups that need administrative privileges in the library should belong to this group.
Deployment Administrator¹ Members of this group have permission to use the Deployments & Packages user interface in the Spotfire Server console. A deployment area is a collection of software packages intended for a specific Spotfire group and client type (Spotfire client, Spotfire Web Player and Spotfire Automation Services) and are used to push hotfixes and other software updates.
Diagnostics Administrator¹ Members of this group have permission to use the Monitoring & Diagnostics page in the Spotfire Server web administration pages.
Scheduling and Routing Administrator¹ Members of this group have permission to use the Scheduling & Routing page in the Spotfire Server web administration pages to create and manage scheduled updates and routing rules.
Scheduled Updates Users The account that runs scheduled updates must be a member of this group. By default, the account scheduledupdates@SPOTFIRESYSTEM is a member of this group.
Automation Services Users Members of this group have permission to execute Spotfire Automation Services jobs on the server, using the Job Builder or the Client Job Sender. By default, the account automationservices@SPOTFIRESYSTEM is a member of this group.
Custom Query Author² Members of this group have permission to save scripts written in custom query languages as trusted to the library.
Script Author³ Members of this group have permission to save scripts as trusted to the library. For more information about scripts see Usage of Scripts and Data Functions in the Spotfire Analyst help.
Everyone This group always contains all users in the Spotfire implementation. No users can be removed from this group, but you can set licenses for the group if you want to.
System Account This group cannot be edited. It contains the system accounts that are used internally in the Spotfire environment.

¹Members of these groups have almost unrestricted access to the system. Only fully trusted users should be added to any of the administrator groups.

²Provides the ability to create data connections that contains arbitrary and unrestricted query language constructs (typically SQL).

³Scripts are very powerful. A script author can, but is not limited to, run arbitrary commands on the Web Player server. See Scripts in Spotfire for a description of the different types of scripts in Spotfire and what capabilities they bring.