Access to KPI Composer
Summarize
Summary of Access to KPI Composer
Access to KPI Composer in ServiceNow controls whether users can create, edit, or only view KPI Composer projects, as well as which projects and underlying records they can access. Access is governed by combinations of user roles, assigned responsibilities, and project sharing permissions.
Show less
User Roles
There are two primary roles related to KPI Composer access:
- KPI Composer Admin (snkpicomposer.admin or admin paviewer): Has full access to all KPI Composer components and projects, including records. Admins can share projects, assign responsibilities, and link indicator and breakdown definitions to Performance Analytics entities.
- KPI Composer User (snkpicomposer.user): Can only access projects they have created or those shared with them with edit rights. Users can access design tabs and artifact properties but cannot add Performance Analytics indicators or breakdowns. Additional Performance Analytics roles are required to implement designs in Performance Analytics.
Responsibility for Projects
Users designated as responsible for a project have edit access equivalent to KPI Composer users but without needing a specific role. Responsible users can view, edit, share, and assign responsibility for the project, but cannot add Performance Analytics indicators or breakdowns. Responsibility is assigned in project properties and implies oversight and implementation duties distinct from simple access rights.
Shared Projects
Projects can be shared with two access levels:
- Edit Access: Equivalent to responsibility or user role access but does not require a specific role or imply oversight responsibilities.
- View Access: Allows users to view project designs, properties, and definitions and use utilities like search and filter, but restricts any changes except adding journal entries.
Practical Implications for ServiceNow Customers
- Assign roles carefully to control who can create, edit, or only view KPI Composer projects.
- Use project responsibility assignments to designate oversight without relying on roles.
- Leverage sharing options to manage collaboration with clear distinctions between editing and viewing permissions.
- Ensure users who need to implement KPI Composer designs in Performance Analytics have the appropriate Performance Analytics roles.
The level of access to KPI Composer determines whether a user can create, edit, or only view a KPI Composer project. It also determines which projects a user can access and whether they can access the underlying records or only the UI.
- User role
- Responsibility
- Access granted during sharing
Role-based access
| Role | Contains | Description |
|---|---|---|
| sn_kpi_composer.admin or admin | pa_viewer |
|
| sn_kpi_composer.user | None |
A user with this role may have access to more projects based on responsibility or on projects being shared with them. |
The appropriate Performance Analytics roles are also necessary to implement KPI Composer designs in Performance Analytics.
Responsibility for projects
- Can view and edit the projects.
- Can share or assign responsibility for the projects.
- Can access only the design tabs, artifact properties, indicator definitions, and breakdown definitions of those projects.
- Cannot add Performance Analytics indicators or breakdowns to the respective definitions.
This level of access is equivalent to what the sn_kpi_composer.user role grants. It is also equivalent to having a project shared with edit rights. Responsibility differs first in being independent of any role. The second difference is procedural, not technical: Responsible users are understood to be in charge of oversight and implementation of the project. Even the creator of a project is therefore not automatically responsible for it.
Responsible users are named in the project properties. Any user with edit rights can name responsible users. For more information about naming responsible users, see Define properties for a project.
Shared projects
Any user with edit rights can share a project. When you share a project, you grant one of two levels of access:
- Edit access
- This level of access is technically the same as the access of a responsible user, or a user with the sn_kpi_composer.user role. The first difference is that no role is required. The second difference is that there is no implication of responsibility to oversee or implement the project.
- View access
- A user with view access can read the design tabs, artifact properties, indicator definitions, and breakdown definitions of the shared project. They can use all viewing utilities, like search and filter. However, they cannot change anything in the project. The only thing they can add is a journal entry.
For more information, see Share a KPI Composer project.