Which permissions are provided as a JazzPrjAdmin
Hello,
Accepted answer
JazzProjectAdmins Administrators who have the same access as JazzUsers plus permission to perform the following operations:
- Create and modify all process templates.
- Create project areas and team areas.
- Modify the access control settings for project areas.
- Save project areas regardless of the role permission settings in the project areas, which include the ability to generate team member invitations. This override ability does not extend to project areas to which the user does not have read-access.
Comments
One other answer
As an answer so I have more space.
You are comparing two totally different concepts and there is an issue with understanding the various "Admins". It is important to understand the distinctions and I thought I had already provided that.
1. JazzProjectAdmin is a Repository Role. Such a role allows the user having it to do things on a repository level that other users are not allowed to. The JazzProjectAdmin role allows to create project areas and it allows to add themselves (and other users) to the list of project area administrators. As far as I can tell these activities are not permissions on a project area level. Even if no permissions are given to any role, the JazzProjectAdmin can do this. Users with only JazzUsers or JazzGuests can not do that. JazzProjectAdmin is more limited as JazzAmin.
2. Being in the list of Administrators of a project area provides these users an override for some actions. Even if no role was any permissions in the project area, these users can make themselves a member of the project area, give themselves roles and configure permissions for roles. It does only override a very specific set of operations. E.g. if you don't have a role that has permissions to create work items, you can be member of the Administrators and you still can't create a work item.
There are NO permissions or invisible roles or something like that involved being in the list of Administrators of a project area. If the member of the administrators does something they have no permission to do (from a role perspective) but are allowed as members of the Administrators, when saving the process (in Eclipse) the team advisor states that the user does NOT have the permission but an administrator override allows the operation nevertheless.