Delegated tenant administration
System administrators can delegate tenant administration tasks to members of the Tenant Administrators role.
If the Tenant Bounding Set Mapping property is configured, Tenant Administrators can access only tenants that are defined in their bounding set. They are further restricted by the Cognos® BI security policies assigned to the content by system administrators. In this situation, Tenant Administrators are considered bounded tenant administrators.
If the Tenant Bounding Set Mapping property is not configured, Tenant Administrators bypass tenancy checking and are restricted only by the Cognos BI security policies assigned to the content by system administrators. In this situation, Tenant Administrators are considered unbounded tenant administrators.
Tenant Administrators can perform the following administration tasks for one or multiple tenants:
- Manage system security, content, jobs, schedules, activities, and events.
- Impersonate tenants.
- Search the tenant content.
Tenant Administrators cannot perform the following tasks:
- Access the Multitenancy tab in IBM® Cognos Administration.
- Create, delete, deploy, and disable tenants.
- Manage tenant user profiles and terminate user sessions.
- Change tenancy on objects in the content store.
- Perform server administration tasks, such as tuning and indexing, and running content store utilization tasks and content store consistency checks.
For information about the role of System Administrators in a multitenant environment, see Tenant administration.