If users need to create reports and other content from a Data Module in IBM Cognos Analytics, you may want them to be able to use the Data Module without being able to edit it.
In this guide, we’ll show you how to restrict access to Data Modules in IBM Cognos Analytics on Cloud On-Demand, while still allowing users to use them to author content.
There are three main steps:
- Create a user group for those who need restricted access.
- Give the group read-only access to the folder containing your Data Modules.
- Deny Web-based modelling so members of the group cannot open or edit the Data Modules.
For this example, we’ll use a group called Secured Data Modules.
1. Create a user group #
From the main menu in IBM Cognos Analytics, go to:
Manage > People > Accounts > Cognos
Select Create group.

Give your group a suitable name, such as Secured Data Modules, and add a description if required.
Select Next > Add members, find the users you want to restrict and add them to the group.
Select Apply, followed by Create.

Your restricted user group is now ready.
2. Set the Data Module folder permissions #
Next, we’ll prevent members of the group from saving changes to the folder containing the Data Modules.
Navigate to the relevant Data Module folder and open Properties > Permissions.
Select Override parent permissions and remove the existing entries.

Select + to add a new entry and navigate to Cognos.
Choose the Secured Data Modules group and select Add.
The group should now appear with Read permission.
Select Apply to all children to apply these permissions to all Data Modules within the folder, then select Save and Close.

Tip: You can apply these permissions to individual users instead, but using a group generally makes access easier to manage.
Members of the group can now access the folder, but they cannot save changes to it.
However, at this stage they can still open a Data Module. We therefore need to make one further change.
3. Deny Web-based modelling #
Return to the Data Module folder and open:
Properties > Capabilities > Set capabilities
Turn on Override capabilities and select Add.
Navigate to Cognos, select the Secured Data Modules group and choose Apply.

Select Override child capabilities so the setting is inherited by the Data Modules within the folder.
Select the Secured Data Modules group and find Web based modelling in the capabilities list.
Set Web based modelling to Deny.
Select Save and Close.

The Data Modules within the folder will inherit these capabilities. Members of the restricted group will therefore be unable to open or edit the secured Data Modules.
What happens to new Data Modules? #
Any Data Modules subsequently added to the secured folder will inherit the folder permissions. Members of the Secured Data Modules group will therefore be unable to edit them or save changes to the folder.
Important #
Users can still copy a secured Data Module into another folder where they have full permissions, such as My content, and edit their own copy.
They cannot, however, overwrite the secured Data Module held within the protected Team content folder.
Need help with IBM Cognos Analytics? #
If you need help managing security, access or your wider IBM Cognos Analytics setup, get in touch with the Aramar team.