Home Search

DriveWorks Pro 24
Security Settings

Send Feedback

This section is specific to DriveWorks 24 onwards, for earlier DriveWorks versions please see Security Settings.

Security Settings

The security settings task provides the ability to administer Users, Teams and Roles in order to control who can login to the group.

The Security Settings task lists all Users, Teams and Roles that have been added to the Group.

When a group is created the following security details are created:

  • Administrators (Team)

    Allows editing and running of all projects added to the group.

  • Admin (User)

    Belongs to the Administrators team.

These defaults adopt a simplistic security model, based on a flat team structure where permissions are granted for each project.

A more scalable, hierarchical model can also be adopted where permissions are assigned to Roles.

Permission Based Security

With a permissions based security model Teams can have a hierarchical structure, for example:

This is important when defining the scope for a Role.

With Roles the required actions and scope are applied to securable features to form a permission.

A securable feature can be the following:

  • Project

    Projects can have the following actions applied:

    • Specify
    • Update
  • Business Objects (for instance when using CPQ Sales Portal)

    Business Objects can have many other actions applied such as:

    • Create
    • Read
    • Update
    • Delete
    • Plus others

The scope tells the Role where the permission is allowed in the Team hierarchy.

  1. Anywhere
  2. Team
  3. Team's Descendants
  4. Team and Descendants

When a user logs into a group, DriveWorks will determine what securable feature the user can access.

This is decided by both the user and the securable feature existing in the Team hierarchy.

For instance:

If a User and a Project (the securable feature) are in the same Team, the Role will say the user has access to the Project because they are in the same Team.

Roles can be applied to Teams and Users and each can have one or more Roles.

Access is given if any applied Role grants the permission.

For example:

In the image below the User will have Specify and Update permissions granted.

  1. Role applied to a Team
    • Action - Specify
  2. Role applied to a User
    • Action - Update

Add Team

The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Teams.

To add a new team:

  1. Click the Add Team button from the command bar.
  2. Enter a name.

    Each Team Name must be unique

    Team Names must be alphanumeric but can contain _ or a space.

    See Info: DriveWorks Limits for more information.

  3. Click OK.
  4. Setup any additional options on the Edit Team dialog.
  5. Click OK.

Edit Team

The Edit Team dialog launches immediately after a team is added.

To edit an existing team:

  1. Select the team to be edited from the Security Settings list.
  2. Click Edit from the command bar.

The Edit Team dialog can also be launched by double clicking on any property (excluding the Name) in the list view.

The Edit Team dialog has six tabs that allow options to be selected:

General

  • Team Name

    This is the name given when the team was created.

    The team name cannot be changed.

    The team must be recreated to apply a new name.

  • Display Name

    The team display name can be surfaced in various security functions.

  • Administer Group Security:

    Determines if members of the Team can use the Security Settings task to administer group security.

  • Administer DriveApps:

    Determines if members of the Team can administer DriveApps.

    This setting requires the Group to be re-opened for the changes to be applied.

  • Members Can Capture:

    Determines if members of the Team can use the SOLIDWORKS addin to administer captured information in the group.

  • Members Can View and Edit All Specifications:

    Determines whether members of the Team can see and edit all specifications created in the group, even if they are created by members of other Teams.

    Checking this setting will override any Team permissions applied in the Specification Flow.

    See To Edit Teams for an Operation or Transition for more information.

  • Parent Team

    If the team is to be a child of another team select the parent from the drop down box.

    A Role given to a team will observe the applied scope.

Users

This allows users to be added to the team

When adding users the following can be applied:

  • User

    The user must exist in order to add it to the team memberships.

  • Role for a User

    This allows a Role to be assigned to the user in the Team.

    Roles can also be assigned to a Team (see Roles) in which case the Role will apply to each user in the team.

    The Role must exist in order to add it to the user memberships.

To add a membership:

  1. With the Users tab of the Edit Team dialog selected, click Add Memberships.
  2. Select the Role to be applied to the user in the team.

    This is optional select (None) to not apply a role.

  3. Select the user or users to add to the team.
  4. Click Add.

To edit a role applied to a user:

  1. Select the existing user from the list.

    Ctrl select to edit multiple existing users.

  2. Click Edit Selected...
  3. Select the require Role.
  4. Click Apply.

To remove a membership

  1. Select the existing membership from the list.

    Ctrl select to edit multiple existing users.

  2. Click Remove Selected.

Roles

All roles added to the Security Settings will be displayed in the list.

  1. Select the role or roles to apply to the team.

    For example:

  2. Click OK if the team setup is complete, or proceed to another tab.

Projects

All projects that exist in the group will be displayed in the list.

  1. Select the project or projects the team is to have access to.

    For example:

  2. Click OK if the team setup is complete, or proceed to another tab.

Project Permissions (Legacy)

This is a legacy setting from versions prior to DriveWorks 24.

When implementing role based security please disregard this setting.

Group Table Permissions

To change permissions for Group Table access:

  1. Select the Group Table from the list and then check the permission option for that table.

    Available permissions are:

    • None - The Team cannot View or Edit the Group Table
    • View - The Team can view the Group Table only.
    • Edit - The Team can View and Edit the Group Table.

Rename a Team (Display Name)

The Team Name cannot be changed.

The team must be recreated to apply a new Team Name.

To change the display name:

  1. Select the team to be renamed from the Security Settings list.
  2. Click Rename from the command bar.
  3. Enter the new name.

The display name can also be changed by:

  • Double clicking the team name from the security settings list.

    Or

  • From the Edit Team dialog.

Delete Team

A team can be deleted from the system by:

  1. Select the team from the list.

    Ctrl select to delete multiple teams.

  2. Click the Delete button from the command bar.
  3. Click Yes from the Delete confirmation dialog.

    Clicking No will cancel the operation.

Add Role

The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Roles.

To add a new role:

  1. Click the Add Role button from the command bar.
  2. Enter a name.

    Each role name must be unique

    Role names must be alphanumeric but can contain _ or a space.

    See Info: DriveWorks Limits for more information.

  3. Click OK.
  4. Setup any additional options on the Edit Role dialog.
  5. Click OK.

Edit Role

The Edit Role dialog launches immediately after a team is added.

To edit an existing role:

  1. Select the role to be edited from the Security Settings list.
  2. Click Edit from the command bar.

The Edit Role dialog can also be launched by double clicking on any property (excluding the Name) in the list view.

The Edit Role dialog has two tabs that allow options to be selected:

General

  • Role Name:

    This is the name given when the role was created.

Permissions

This tab displays all the permissions that can be applied for the role.

The view is split into the Actions that can be applied, and the Scope for that action.

Typically the view will only show Project actions.

More action types will be displayed if, for instance, CPQ Sales Portal is being used (in which case all actions that can be applied to Business Objects will be shown).

A Role (for a project) has two actions:

  • Specify

    This allows the role to specify projects.

    Access to individual projects is defined in the team. (See Edit Team - Projects)

  • Update

    This allows the role to update projects.

    Access to individual projects is defined in the team. (See Edit Team - Projects)

Each action can have a scope applied.

  • Anywhere

    The action will apply anywhere in the team hierarchy (parent of the team, the team and descendants (children) of the team).

  • Team

    The action will apply to the team only.

  • Team's Descendants

    The action will apply to descendants (children) of the team.

  • Team and Descendants

    The action will apply to the team and its descendants (children).

To configure permissions for the role:

  1. Check the target action or actions required for the role.

    For example:

  2. Select the target action and select the scope required for the role.

    For example:

  3. Click OK when the required permissions have been configured.

Add User

The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Users or Reset and Clear User Passwords.

Each user required to have access to the group must be added individually.

  1. Click the Add User button from the command bar.
  2. Enter a name.

    This is the Login name.

    Each login name must be unique.

    Login names must only contain alpha or numeric characters.

    See Info: DriveWorks Limits - User Name for more information.

  3. Click OK.
  4. Setup any additional options in the Edit User dialog.
  5. Click OK.

Edit User

The Edit User dialog launches immediately after a user is added.

To edit an existing user:

  1. Select the user to be edited from the Security Settings list.
  2. Click Edit from the command bar.

The Edit User dialog can also be launched by double clicking on any property (excluding the Name) in the list view.

The Edit User dialog has two tabs that allow options to be selected:

General Tab

The General tab displays the following:

  • Login Name

    This is the name given when the user was created.

    The Login name cannot be changed.

    The user must be recreated to apply a new login name.

    The Login Name of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserName

  • Display Name (optional)

    The Display Name of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserDisplayName

  • Email Address (optional)

    The Email Address of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserEmailAddress

  • Team Leader

    A Team Leader (checked) can see all specifications (in the Specification Explorer or History page of DriveWorks Live) created by other users in the same Team.

    When unchecked only specifications created by this user will be visible.

  • Enabled

    When checked the user is active and will be able to login to the group.

    Uncheck to disable a user from logging in.

Teams Tab

This allows the users memberships to be added, edited or removed.

The user can be assigned memberships of the following:

  • Team

    The Team must exist in order to add it to the users memberships.

  • Role in a Team

    This allows a Role to be assigned to the user in a Team.

    Roles can also be assigned to a Team (see Edit Team) in which case the Role will apply to each user in the team.

    The Role must exist in order to add it to the users memberships.

To add a membership:

  1. With the Teams tab of the Edit User dialog selected, click Add Memberships.
  2. Select the Role to be applied to the user in the team.

    This is optional select (None) to not apply a role.

  3. Select the team or teams the user is to be a member of.
  4. Click Add.

To edit a role applied to a membership

  1. Select the existing membership from the list.

    Ctrl select to edit multiple existing memberships.

  2. Click Edit Selected...
  3. Select the require Role.
  4. Click Apply.

To remove a membership

  1. Select the existing membership from the list.

    Ctrl select to edit multiple existing memberships.

  2. Click Remove Selected.

Rename a User (Display Name)

The Login name cannot be changed.

The user must be recreated to apply a new login name.

To change the display name:

  1. Select the user to be renamed from the Security Settings list.
  2. Click Rename from the command bar.
  3. Enter the new name.

The display name can also be changed by:

  • Double clicking the user name from the security settings list.

    Or

  • From the Edit User dialog.

Delete User

A user can be deleted from the system by:

  1. Select the user from the list.

    Ctrl select to delete multiple users.

  2. Click the Delete button from the command bar.
  3. Click Yes from the Delete confirmation dialog.

    Clicking No will cancel the operation.

Reset Password

This will apply a password or an existing password can be reset for a user.

  1. Select the user from the list.
  2. Click the Reset Password button from the command bar.
  3. Enter the password in the New Password field.

    There are no limits or restrictions to the length or characters that can be used for a password.

    See Info: DriveWorks Limits - User Password for more information.

  4. Repeat the password in the Repeat Password field.
  5. Click OK.

The default Admin password can be changed and we do recommend this is done.

However, once changed this is irretrievable if lost or forgotten.

Please take care to remember the Admin password.

It can be reset by DriveWorks Ltd. However this may incur a charge.

The Specification Task Update User Password can be used to implement password update in a project.

Clear Password

The password for any user can be cleared.

This will allow the user to login without a password.

  1. Select the user from the list.
  2. Click the Clear Password button from the command bar.
  3. Click Yes from the Clear Password confirmation dialog.

    Clicking No will cancel the operation.

  4. Click OK.

Refresh

The list of Teams and Users is refreshed by clicking the Refresh button from the command bar.

When a Project in the Group uses any of the Security Tasks (for example Add New Team) the Team and User data can become out of sync.

Use the Refresh button to get the latest Security data.

Filter and Sort the Security Settings List

The Security Settings list can be be filtered by using the filter at the top of the list.

Please see the topic How To Use Filters for more advanced filtering information.

To filter on a specific column include the column name followed by a colon and the filter term, for example:

Type:Team

Will filter the list to display all Teams only.

Each column can be sorted by clicking on the column heading.

Each click will step through sorting the column by ascending, descending or no sorting.

More Information

Single Sign-On

DriveWorks Pro Server supports Microsoft Entra ID Single Sign-On.

Using this authentication method, users added to the Security Settings view are mapped to Microsoft Entra ID Accounts.

Permissions to edit and run projects are administered in Security Settings.

Security Functions

The following functions return information about security settings:

Security Special Variables

The following special variables return information from security settings:

Security Specification Tasks

The following specification tasks can be used administer security settings:

The user logged into the group that uses these tasks must be a member of a team that can administer group security.

Users are added to teams to control their access to projects. Each user has a name and a password which they use to log on to a group.

Teams are groups of users. Each team has a configurable set of permissions which govern whether the users in that team can capture models, and edit and/or specify certain projects in the group.