D.A.M. Security Manager Workflow
Use this page as the map for D.A.M. Security Manager in Mission Control. It tells you which screen to open for each job, in what order, and which detailed guide to follow next.
Audience: Vista security administrators configuring DAM in Mission Control.
Where: Mission Control → D.A.M. Security Manager
What each area owns
DAM splits Vista security work into four domains. Configure each domain in Mission Control, then push it with Download SQL or Run Sync from Security Exports & Syncs.
| Domain | What you define | Where you configure it | Export / sync section |
|---|---|---|---|
| Role & duty security | Roles, duties, Forms / Reports / Attachments permissions, role↔duty links | Role & Duty Builder, Role & Duty Matrix | Role & Duty Security |
| User roles | Which users belong to which roles | User Setup, then User Roles | User Roles |
| Company access | Which companies each user can access | Company Setup, then Company Access | Company Access |
| PR group access | Which payroll groups each user can access | PR Group Setup, then PR Group Access | PR Group Access |
These domains are related but independent. Assigning a user to a role does not grant company or PR group access. Granting company access does not change form permissions.
Recommended order
Do the work in this order the first time you stand up or rework DAM for a team:
- Build roles and duties — create or import roles/duties and set security groups.
- Set permissions — Forms, Reports, Attachments (and duty assignments on roles) in Builder or Matrix.
- Review coverage (optional) — check module totals in Role & Duty Summary.
- Load users — maintain the DAM user list in User Setup.
- Assign user roles — toggle users onto roles in User Roles.
- Load companies → assign company access.
- Load PR groups → assign PR group access.
- Export or sync — Security Exports & Syncs for each domain you changed.
You can skip company or PR group work if your team does not use those access models. You should not skip export/sync if you need Viewpoint to match Mission Control.
Mission Control page map
| Nav item | Route | Use it to… |
|---|---|---|
| Role & Duty Builder | /missioncontrol/security/role-duty-builder | Work one role or duty at a time. Session-based edits with Save Changes / Cancel Changes. |
| Role & Duty Matrix | /missioncontrol/security/role-duty-matrix | Edit the same permissions across many roles or duties at once. Changes save immediately. |
| Role & Duty Summary | /missioncontrol/security/role-duty-summary | Read-only review: allowed vs total Forms / Reports / Attach by module. |
| User Setup | /missioncontrol/security/user-setup | Add, import, refresh, or delete DAM users (VPUserName). |
| User Roles | /missioncontrol/security/user-roles | Assign users to roles. |
| Company Setup | /missioncontrol/security/company-setup | Maintain the company catalog used by company access. |
| Company Access | /missioncontrol/security/company-access | Assign which companies each user can access. |
| PR Group Setup | /missioncontrol/security/pr-group-setup | Maintain the PR group catalog. |
| PR Group Access | /missioncontrol/security/pr-group-access | Assign which PR groups each user can access. |
| Security Exports & Syncs | /missioncontrol/security/export-sync | Download SQL and/or Run Sync for the four domains above. |
Builder vs Matrix
| Role & Duty Builder | Role & Duty Matrix | |
|---|---|---|
| Best for | Creating/importing roles and duties; deep edits on one subject | Comparing and changing many roles or duties side by side |
| Save model | Working session → Save Changes or Cancel Changes | Immediate save on toggle |
| Bulk edits | Apply To... on the filtered rows for the selected role/duty | Bulk column + Apply To... across visible subjects |
Use Builder when you are defining the catalog. Use Matrix when you already have roles/duties and need cross-role permission work.
Review coverage in Summary
After you change permissions, open Role & Duty Summary to spot gaps before you export.
- Switch between Roles and Duties.
- Filter by search, modules, or subject.
- Read cells as
allowed/totalfor Forms, Reports, and Attach per module.
Summary does not edit security. If a total looks wrong, fix it in Builder or Matrix, then return.
Catalogs vs assignment matrices
Setup pages and assignment pages look similar on purpose. Treat them as two steps:
| Step | Pages | Job |
|---|---|---|
| Catalog | User Setup, Company Setup, PR Group Setup | Add / Import / Refresh / Delete the rows that appear as people or columns later |
| Assignment | User Roles, Company Access, PR Group Access | Toggle access between users and roles / companies / PR groups |
Important: On User Setup, Refresh Users with Replace users can wipe existing user-role and company assignments. Prefer non-destructive refresh unless you intend a full rebuild.
Refresh vs Run Sync: Setup-page Refresh pulls catalog data into DAM from Vista configs/cache. Run Sync on Security Exports & Syncs writes DAM security assignments into Viewpoint through Azure Bridge. They are not the same action.
Export and sync last
When Mission Control matches the security you want:
- Open Security Exports & Syncs.
- Choose the section for the domain you changed (Role & Duty Security, User Roles, Company Access, or PR Group Access).
- Select what to include (roles/scopes, companies, or PR groups).
- Use Backup Tables when you want backup objects in the generated SQL.
- Download SQL to get Viewpoint SQL, or Run Sync to apply through Azure Bridge.
Configure first. Export/sync second. Do not treat the export page as the place to design roles or assignments.
Guides in this set
| Guide | Status |
|---|---|
| Build roles and duties | Drafted |
| Set form, report, and attachment permissions | Drafted |
| Edit permissions across many roles or duties | Drafted |
| Maintain DAM users | Drafted |
| Assign users to roles | Drafted |
| Assign company and PR group access | Drafted |
| Export and sync DAM security to Vista | Drafted |
Start with the Builder guides if you are defining security from scratch. Start with export/sync only if the Mission Control configuration is already correct and you need to push it to Viewpoint.