Introduction

Schneider Electric provides the Security Editor configuration tool that lets you manage access to the Control Expert software installed on a workstation. Using he Security Editor configuration tool to manage access to the Control Expert software is optional.

NOTE: Access management relates to the hardware – typically a workstation – on which Control Expert software is installed and not to the project, which has its own protection system.

For more information, refer to EcoStruxure™ Control Expert, Security Editor, Operation Guide.

NOTE: Safety user profiles also require rights to access the process part of the safety application. When you create or modify a user profile, it is your responsibility to confirm that all necessary modifications are properly made.

Categories of Users

The Security Editor supports two categories of users:

  • Super User (Supervisor):

    The super user is the only person to manage access security for the software. The super user specifies who can access the software and their access rights. During installation of Control Expert on the workstation, only the super user can access the security configuration without any limitation of rights (without a password).

    NOTE: The user name reserved for the super user is Supervisor.
  • Users:

    Software users are defined in the list of users by the super user, if Control Expert access security is active. If your name is in the user list, you can access a software instance by entering your name (exactly as it appears on the list) and your password.

User Profile

The user profile comprises all of the access rights for a user. The user profile can be custom-defined by the super user, or can be created by applying a preconfigured profile that comes with the Security Editor tool.

Preconfigured User Profiles

The Security Editor offers the following preconfigured user profiles, which apply to either the safety program or the process program:

Profile

Applicable program type

Description

Process

Safety

ReadOnly

The user can only access the project in read mode, except for the PAC address, which can be modified. The user can also copy or download the project.

Operate

The user has the same rights as with a ReadOnly profile, with the added possibility of modifying process program execution parameters (constants, initial values, task cycle times, etc.).

Safety_Operate

The user has similar rights as with the Operate profile, but with respect to the safety program, except that:

  • Transferring data values to the PAC is not permitted.

  • Commanding the safety program to enter maintenance mode is permitted.

Adjust

The user has the same rights as with an Operate profile, with the added possibility of uploading a project (transfer to the PAC) and modifying the PAC operating mode (Run, Stop, ...)

Safety_Adjust

The user has similar rights as with the Adjust profile, but with respect to the safety program, except that:

  • Transferring data values to the PAC is not permitted.

  • Commanding the safety program to enter maintenance mode is permitted.

Debug

The user has the same rights as with an Adjust profile, with the added possibility of using the debugging tools.

Safety_Debug

The user has similar rights as with the Debug profile, but with respect to the safety program, except that:

  • Stopping or starting the program is not permitted.

  • Updating initialization values is not permitted.

  • Transferring data values to the PAC is not permitted.

  • Forcing inputs, outputs or internal bits is not permitted.

  • Commanding the safety program to enter maintenance mode is permitted.

Program

The user has the same rights as with a Debug profile, with the added possibility of modifying the program.

Safety_Program

The user has similar rights as with the Program profile, but with respect to the safety program, except that:

  • Stopping or starting the program is not permitted.

  • Updating initialization values is not permitted.

  • Transferring data values to the PAC is not permitted.

  • Restoring the project to the PAC from a saved backup is not permitted.

  • Forcing inputs, outputs or internal bits is not permitted.

  • Commanding the safety program to enter maintenance mode is permitted.

Disabled

User cannot access the project.

Assigning a Preconfigured User

The super user can assign a preconfigured user, derived from a preconfigured profile, to a specific user in the Users tab of the Security Editor. The following preconfigured user selections are available:

  • safety_user_Adjust

  • safety_user_Debug

  • safety_user_Operate

  • safety_user_Program

  • user_Adjust

  • user_Debug

  • user_Operate

  • user_Program

Refer to the topic User Functions for more information about how a super user can assign a preconfigured profile to a user.