CapitalKnowledge

Introduction

Access Control

The facilities in Capital Access Manager comprise five broad areas:

  • Domains - a method of controlling user access to the projects within the Capital applications. Domains can be allocated to user accounts and user groups. See Domains for more information on how to create domains.

  • Roles - a selection of permissions (access rights) collected together under one name. The permissions selected for a role have an effect across all of the applications in the Capital suite (they are not applicable to the Capital Harness & Factory applications). Usually, a role equates to a job description. A role may be applied to user accounts and user groups. As many users may perform the same job, for example, job X, they would usually require the same permission set. To save administration time, a single role may be created for job X that contains all (and only) those permissions that are required for that job. Once the role has been created, it is easier to assign the 'job x role' to those users performing that job (in which they will assume all of the permissions in that role), rather than to repetitively apply each of the required permissions to every user. Roles can also be allocated to a user group. See Roles for more information how to create roles.

  • User Accounts - enable the various roles, domains and license policy to be applied to individual Capital users. In order to be able to log into the Capital applications, every user must have their own, active, unique user account within which an appropriate username has been specified and (if not using the delegated sign-on facility) a password has been entered. For user accounts with the Delegated Sign On facility enabled, Capital will use the security policies and matching user profiles enabled within the underlying operating system to validate the account. The user account facility enables the administrator to specify security parameters for the user and also to allocate the appropriate roles, edited permissions and domains. Once a user's account has been created, the roles, permissions and domains allocated to that account will be enforced whenever the user logs into the Capital applications under the specified username (and password). The administrator can also mark existing user accounts as inactive if required, inactive user accounts will not be able to log into Capital applications. Refer to User Accounts for more information on creating user accounts.

  • User Groups - enables the rapid allocation of a set of predetermined roles, domains and license policy to a user's account. Refer to User Groups for more information on creating user groups. Many of the facilities in Capital Access Manager require certain information to be already present in the Capital Access Manager database before they can be used as designed. The following table indicates the pre-requisite information required for each facility, the suffixes indicate which of the pre-requisites are Mandatory (M) or Optional (O) for that facility:

  • License Policy - a sub-set of enabled licenses related to software features. License policies control feature access across the user base. The licenses included in a policy are assigned to individual user accounts, or all user accounts included a user group. A license can be checked out (used) by a user account only if it is included in any of the user groups to which the user belongs, or if it is included on the user account directly. Refer to License Policy for more information on creating license policy.

Table 1: Facility Pre-requisites Facility

								Domains

							

							
								Roles

							

							
								User Accounts 

							

							
								User Groups

							

						

					

						
							
								Pre-requisite Information

							

							
								-

							

							
								-

							

							
								Roles (O)

								Permissions(O)

								Domains(O)

								License Policy(O)

							

							
								User Accounts(M)

								Roles (M)

								Domains (O)

								License Policy(O)

The Capital Access Manager Tree

The main Capital Access Manager tree, displayed in the left hand side window of the application, displays nodes based on the above five areas of content.

Figure 1: Capital Access Manager Application

Node visibility and structure is based on the permissions available for the current user. For example, a user with the System Administrator role assigned will see all available nodes in the Capital Access Manager tree due to the permissions associated with that role, however, a user with the Designer role assigned will only see the User Accounts node due to the more limited permissions associated with that role.

The Capital Access Manager tree has a filter box to enable object searches in large datasets. For more details on filter use, see Browser Tab and Dialog Box Filters in the Capital Design Tools - Common Functions User Guide.

Parent Topic:

Introduction

Capital Access Manager User Guide, 2512.2606

Unpublished work. © 2026 Siemens

Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/idbc1d6592-5be5-4030-9aac-c69197c24564 · retrieved 2026-07-18