SAS Viya: CAS Authorization Window
- Introduction
- Navigation
- Examine Access
- Set an Access Level
- Add a Direct Access Control
- Remove a Direct Access Control
- Remove Multiple Direct Access Controls
- Examples: Manage Access to a Caslib
- Provide Row-Level (Filtered) Access
- Identify the Source of Effective Access
Introduction
Use this window to manage access to caslibs, tables, and rows.
For concepts and background information, see CAS Authorization: Overview in SAS Viya: CAS Authorization.
Navigation
Here is one way to access the Authorization window for caslibs and tables:
- In the applications
menu (
), under ADMINISTRATION, select Manage Environment.
- In the vertical
navigation bar in SAS
Environment Manager, click
.
- On the Data page, locate and select a global caslib or table.
- Right-click,
and select View authorization or Edit
authorization.
Note: If Edit authorization is not available, you are not authorized to modify access to the selected object.
Examine Access
Scope
The scope of the display is as follows:
- There is always a row for Authenticated Users.
- There is always a row for you, the currently connected user who is using the display.
- There is a row for each principal that is assigned to an access control that affects access to the current object.
- If you add an identity and do not give that identity at least one direct setting, that identity is automatically removed from the display.
- You cannot directly remove a row. If you remove all direct settings for an identity and there is no other reason for that identity to be displayed, that identity is automatically removed from the display.
- Only the permissions that are relevant for an object (directly or for inheritance purposes) are displayed for that object.
- The display does not reflect the impact of CAS role membership or status.
Permissions
For each principal and permission, the following icons describe effective (net) access to the current caslib or table.
|
Icon |
Meaning |
|---|---|
|
|
Authorized |
|
|
Not Authorized |
|
|
Row-Level |
|
|
Unknown |
Access Levels
The Access Level column provides an alternative to interacting with individual permissions.
- When you manage access, each access level is a shortcut for adding a set of direct access controls.
- When you view access information, each access level is a shorthand description of a set of effective permissions.
|
Access Level |
Permissions |
|---|---|
|
No access |
None |
|
Read |
Only ReadInfo and Select |
|
Write |
All except ManageAccess and AlterCaslib |
|
Full control |
All |
|
Custom |
Any other combination, including any row-level access |
Set an Access Level
- Open the Edit Authorization window for a CAS object.
- If the principal
that you want to work with is not already listed, click
. In the Add Identities window, move the user or group to the right pane, and click OK.
Note: If guest access is enabled, you must select Add Identities after you click. Or, if you need to add Guest to the display, select Add Guest after you click
.
- In the Access
Level column, click and drag a gauge to adjust access.
Note: If a gauge is not displayed, select an access level other than (custom) from the drop-down list.Note: Each time you change an access level, direct access controls are added as needed to meet the definition of the new access level. If you want to discard all unsaved changes, click Cancel.
CAUTION
Reducing the access level for a group that you belong to might block your access. To preserve your access, make sure you have a higher precedence (offsetting) direct grant. If you are a Superuser, this precaution is not strictly necessary.
- If you modified access for a group, click Preview. Examine the impact of the change on other principals. For example, increasing the access level for Authenticated Users from No access to Full control affects all authenticated users who do not have a more specific denial.
- Click Save.
Add a Direct Access Control
- Open the Edit Authorization window for a CAS object.
- If individual permissions are not already displayed, select the Show individual permissions check box.
- If the principal
that you want to work with is not already listed, click
. In the Add Identities window, move the user or group to the right pane, and click OK.
Note: If guest access is enabled, you must select Add Identities after you click. Or, if you need to add Guest to the display, select Add Guest after you click
.
- Click the
effective access icon (for example,
) for the principal and permission that you want to modify.
- In the pop-up
window, select Grant or Deny in
the Direct Setting drop-down list.
CAUTION
Before you deny access for a group that you belong to, make sure you have a higher precedence (offsetting) direct grant. If you are a Superuser, this precaution is not strictly necessary.
- If you modified
access for a group, click Preview in
the Edit Authorization window.
- Notice that a diamond is displayed in the cell that you modified. The diamond indicates that effective access comes from a direct setting.
- Examine the impact on other principals. For example, a direct denial for GroupA affects all members of GroupA who do not have their own direct settings.
- Click Save.
Remove a Direct Access Control
- Open the Edit Authorization window for a CAS object.
- In a cell that includes a diamond, click the effective access icon.
- In the pop-up window, select (none) from the Direct settings drop-down list.
- In the Edit
Authorization window, notice that the new effective access
value is unknown (
). Click Preview.
- Notice that the new effective access value is known. Or, if you removed the only setting that made the associated user or group a relevant principal for the current object, the user or group is no longer included in the display.
- If you modified access for a group, examine the impact on other principals.
- Click Save.
Remove Multiple Direct Access Controls
- Open the Edit Authorization window for a CAS object.
- In a row that includes at least one direct setting, click the first cell. The row is selected.
- Click
to remove all direct access controls for the selected identity.
- Notice that
effective access for any affected cells is unknown (
). Click Preview.
- Notice that all effective access values are known. Or, if the associated user or group is no longer a relevant principal for the current object, the user or group is no longer included in the display.
- If you modified access for a group, examine the impact on other principals.
- Click Save.
Examples: Manage Access to a Caslib
Provide Public Access to a Caslib
To give all users Read access to a new global caslib that you added:
- Open the caslib’s Edit Authorization window.
- In the row for Authenticated Users, increase the Access Level to Read.
- Click Save.
Provide Selective Access to a Caslib
To give a particular user Read and Write access to a new global caslib that you added:
- Open the caslib’s Edit Authorization window.
- Click
in the table toolbar.
- In the left pane of the Add Identities window, locate the user. Move the user to the right pane, and click OK.
- In the Edit Authorization window, increase the user’s Access Level to Write.
- Click Save.
Block All Access to a Caslib
To block all access for a particular identity:
- Open the caslib’s Edit Authorization window.
- If the identity
is not already listed, click
in the table toolbar.
In the left pane of the Add Identities window, locate the user, group, or custom group that you want to block. Move that identity to the right pane, and click OK.
- In the Edit Authorization window, decrease the identity’s Access Level to None.
- If the identity is not an individual user, click Preview. Examine the impact of your change on other listed identities.
- Click Save.
Limit Write Access to a Caslib
To allow only Read access for a particular identity:
- Open the caslib’s Edit Authorization window.
- If the identity
is not already listed, click
in the table toolbar.
In the left pane of the Add Identities window, locate the user, group, or custom group that you want to block. Move that identity to the right pane, and click OK.
- In the Edit Authorization window, decrease the identity’s Access Level to Read.
- If the identity is not an individual user, click Preview. Examine the impact of your change on other listed identities.
- Click Save.
Provide Row-Level (Filtered) Access
To make different subsets of rows available to different identities, set one or more row-level grants. Each row-level grant includes a filter that limits the available rows.
- Open the Edit Authorization window for a CAS table.
- If the principal
that you want to work with is not already listed, click
. In the Add Identities window, move the user or group to the right pane, and click OK.
Note: If guest access is enabled, you must select Add Identities after you click. Or, if you need to add Guest to the display, select Add Guest after you click
.
- If individual permissions are not displayed, select the Show individual permissions check box.
- In the Select column, click an effective access icon.
- In the pop-up window, select Row-level Grant from the Direct setting drop-down list.
- In the Row-Level
Filter window:
- Specify an
expression that includes only the rows that the principal should be
able to access. The basic format is:
column-name operator value. Here are basic examples:Types and Examples of Row-Level Filters Type of Filter
Example
Numeric
sales<1000Character
Make='Ford'Dynamic
user='SUB::SAS.Userid'For details, see Row-Level Access in SAS Viya: CAS Authorization.
Note: If you view or edit a filter that was initially created programmatically, you might see escape characters and a different pattern of quotation marks. - Click OK.
- Specify an
expression that includes only the rows that the principal should be
able to access. The basic format is:
- In the Edit Authorization window, next to the new setting, notice that a diamond is displayed. The diamond indicates that effective access comes from a direct setting.
- If you modified access for a group, click Preview. Examine the impact on other principals.
- Click Save.
Identify the Source of Effective Access
To determine which access control causes a particular effective access result, examine the origins information for that result.
- Open the View Authorization window for the target CAS object.
- Click the effective access icon for which you want origins information.
- In the pop-up
window, next to the Effective Access value,
click
.
Note: The icon is disabled if you have changes that you have neither saved nor previewed. - In the Origins window,
review the displayed information.
- The Source object field indicates where the determinative access control is set.
- The Principals field
indicates which identity the determinative access control are assigned
to.
Note: If multiple access controls of equal precedence cause the result, multiple principals are listed.
For details, see Origins of Effective Access in SAS Viya: CAS Authorization.