Skip to content

Access Control for aP Connect Workflows

aP Connect Workflows can read, export, import, and write, data; create and cost scenarios; and generate reports and email notifications. However, they can perform these processes only if they use an account that has the required licenses and privileges.

An aPrioriCIGenerateUs account is a dedicated account that is configured to meet the license and access requirements of the workflows that aP Connect system administrators create, that is:

  • Access to Digital Factories and components under cost
  • Licensing for all requisite process groups
  • Access to the requisite component schema
Note the following:
  • The aPrioriCI Generate User is not a person.
  • Only aP Connect workflows use the aPrioriCIGenerateUser account.
  • aP Connect system administrators use their own accounts, not the aPrioriCIGenerateUser account.

In most cases, aPriori Customer Support creates, licenses, and configures access control for the aPrioriCIGenerateUser account. However, you must work with aPriori Customer Support to configure access control for the aPrioriCIGenerateUser account if all three of these conditions are true:

  • Your company wants to or is now using aP Connect.
  • Your company started using the aPriori Cloud solution prior to the 2019 R3 release.
  • Your company uses a custom access control model.

Access Requirements for APrioriCIGenerateUser Accounts

If your deployment implements a custom aPriori Access Control model, you must grant the permissions that are shown in the following table to the APrioriCIGenerateUser account.

Permission Required Permission Required Permission Required Permission Required
Read Create Cost Using Update
Components Y Y NA Y
Digital Factory Y NA Y NA

If the APrioriCIGenerateUser account does not have the required permissions, workflows that are executed by the account might not complete.

To grant the required permissions to the APrioriCIGenerateUser account, use the System Admin Toolset to:

  • Add the APrioriCIGenerateUser to a pre-existing group that has all required permissions (if such a group exists).
  • Add the APrioriCIGenerateUser to a pre-existing group that does not have all required permissions and grant any missing required permissions to the group.
  • Create a new group, grant the required permissions to the group, and add the aPrioriCIGenerateUser to the new group.

License Requirements for aPrioriCIGenerateUser Accounts

The aPrioriCIGenerateUser account requires licensing that provides access to all Digital Factories and process groups that your company is licensed for. If a workflow is configured to cost a scenario that uses a Digital Factories or process group that the APrioriCIGenerateUser accounts is not licensed for, the costing fails.

To Examine the Licensing for the aPrioriCIGenerateUser Account:

  1. Open the aPriori System Administrator window. From the aP Pro (via AppStream) menu bar, select Tools -> System Admin Toolset. Then, in the System Admin Toolset, click System Administrator.
  2. Open the Users tab. In the aPriori System Administrator window click Users.
  3. Open the Edit Users window. In the Users tab, in the Login ID column, select APrioriCIGenerateUser and then click Edit Users.
  4. In the Edit Users window, note the User License value. Then, click Cancel.
  5. Open the License Modules tab. In the aPriori System Administrator window click License Modules.
  6. To determine which modules the APrioriCIGenerateUser account has, examine the modules that are included for the User License that is specified for the account.

Component Schema Access Requirements for APrioriCIGenerateUser Accounts

The APrioriCIGenerateUser accounts requires access to all requisite component schemas. For general information about component schemas, see the Managing Deployments in the aPriori System Administration Guide.

To Examine Component Schema Access for the APrioriCIGenerateUser Account:

  1. Open the aPriori System Administrator window. From the aP Pro (via AppStream) menu bar, click Tools > System Admin Toolset. Then, in the System Admin Toolset, click System Administrator.
  2. Open the Users tab. In the aPriori System Administrator window click Users.
  3. Open the Edit Users window. In the Users tab, in the Login ID column, select APrioriCIGenerateUser and then click Edit Users.
  4. In the Edit Users window, examine the Schema Privileges value. Then, click Cancel.

For more information about component schemas, see Managing deployments.