Troubleshooting guide
2 — 5620 SAM user security
Alcatel-Lucent 5620 Service Aware Manager 2-21
5620 SAM
System Administrator Guide
Blocked Edit and Blocked View spans restrict access to a subset of the objects in
another span in the same profile. For example, when multiple span of control profiles
each contain the Default Service Span, you can add a customer-specific Blocked View
or Blocked Edit span to each profile so that the user group associated with a profile can
view or configure only the services of specific customers.
A Blocked Edit or Blocked View span takes precedence over other spans. For example,
when a user has an Edit Access span that contains all services and a Blocked View span
that contains Customer A and Customer B, the user cannot view or configure the
services that belong to Customer A and Customer B.
To ensure that span conflicts do not interfere with network troubleshooting, the
5620 SAM allows a user to execute tests on NEs and service sites that are not in an Edit
Access span of the user. However, activities such as policy distribution, software
upgrades, and statistics collection can be performed only by a user with Edit Access
spans that contain the target objects.
1 Using an account with an assigned security scope of command role, choose
Administration→Security→5620 SAM User Security from the 5620 SAM main menu.
The 5620 SAM User Security - Security Management (Edit) form opens.
2 Click on the Span of Control tab.
3 Click Create and choose Profile. The Span of Control Profile (Create) form opens.
4 Configure the required parameters.
5 Assign one or more spans to the profile:
i Click on the Spans tab. The predefined spans are listed.
ii Click Add and choose an access type. The Select access_type Spans form
opens.
iii Select one or more spans in the list and click OK.
6 Save your changes and close the form.
Caution — Alcatel-Lucent recommends that you consider the effects
of combining customer, service, and NE spans in a span of control
profile. For example, a user can modify a service only when the service,
customer, and participating NEs are in one or more Edit Access spans of
the user, and none of the objects is in a Blocked Edit or Blocked View
span.
Note — You cannot delete a span of control profile that is assigned to
a user group that contains users.
Release 13.0 R2 | May 2015 | 3HE 09815 AAAB TQZZA Edition 01