generated: '2026-09-12' method: searched source: https://www.gevernova.com/software/documentation/uaa/version2025/index.html docs: https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_historian_groups_in_uaa.html note: >- Proficy Authentication (Cloud Foundry UAA) is the OAuth2 authorization server for the on-premises Proficy products. GE Vernova publishes the assignable scope list per product as reference tables in the Proficy Authentication documentation; the scopes below are transcribed verbatim from those tables. There is no OpenAPI document to derive these from — no GE Vernova Electrification Software product publishes a machine-readable contract — so this file is searched, not derived. schemes: - name: ProficyAuthentication type: oauth2 source: https://www.gevernova.com/software/documentation/uaa/version2025/index.html flows: - flow: password - flow: clientCredentials scopes: - scope: historian_rest_api.read description: Provides read access to the Historian public REST API. product: Proficy Historian sources: [https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_historian_groups_in_uaa.html] - scope: historian_rest_api.write description: Provides write access to the Historian public REST API. product: Proficy Historian - scope: historian_rest_api.admin description: Provides read/write access to the Historian public REST API. product: Proficy Historian - scope: historian_enterprise.admin description: Provides read/write access to Configuration Hub APIs. product: Proficy Historian - scope: historian_enterprise.user description: Allows access to Configuration Hub APIs. product: Proficy Historian - scope: historian_visualization.admin description: Provides access to Trend Client and the Web Admin console. product: Proficy Historian - scope: historian_visualization.user description: Allows access to Trend Client. product: Proficy Historian - scope: ih_archive_admins description: Provides the ability to create, modify, and remove archives. product: Proficy Historian - scope: ih_audited_writers description: Allows data writes and produces a message each time a data value is added or changed. product: Proficy Historian - scope: ih_collector_admins description: Allows the ability to add collector instances and change their destination. product: Proficy Historian - scope: ih_readers description: Provides the ability to read data and system statistics, and access to Historian Administrator. product: Proficy Historian - scope: ih_security_admins description: Historian power security users; rights to all Historian functions. product: Proficy Historian - scope: ih_tag_admins description: Ability to create, modify, and remove tags; tag-level security can override other groups. product: Proficy Historian - scope: ih_unaudited_logins description: Allow connections to the Data Archiver without creating login-successful audit messages. product: Proficy Historian - scope: ih_unaudited_writers description: Ability to write data without creating any messages. product: Proficy Historian - scope: iqp.clouduser description: Assigned to users who want to use the REST API, mainly the M2M Device RESTful APIs. product: Proficy Operations Hub sources: [https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_opshub_groups_in_uaa.html] - scope: iqp.developer description: Assigned to developer users; an associated application user account is generated automatically. product: Proficy Operations Hub - scope: iqp.user description: Assigned to application users; access only to the applications they are granted. product: Proficy Operations Hub - scope: iqp.nodered description: Assigned to users who need access to the Dataflow Editor. product: Proficy Operations Hub - scope: iqp.studioAdmin description: Access to the Administrator Console to configure global settings for an Operations Hub instance. product: Proficy Operations Hub - scope: iqp.tenantAdmin description: Administrative authority at the tenant or system level. product: Proficy Operations Hub - scope: proficy_client.manage description: Controls who can delete clients within Proficy Authentication. product: Proficy Authentication sources: [https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_uaa_groups_in_uaa.html] - scope: scada.fix_shared_IFIX_PROFICY_AUTH_ADMIN description: Allows access to all iFIX application features. product: Proficy iFIX sources: [https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_ifix_groups_in_uaa.html] - scope: scada.fix.shared.APPLICATION_DESIGNER description: Access to Configuration Hub and iFIX connection, database and model features. product: Proficy iFIX - scope: scada.fix.shared.OPERATORS description: Run-mode-only access for a user in iFIX. product: Proficy iFIX - scope: scada.fix.shared.SUPERVISORS description: WorkSpace run and configure mode, background task exit, and iFIX system shutdown. product: Proficy iFIX - scope: scada.proficy.admin description: Access to the iFIX Projects panel and Deploy operations from Configuration Hub. product: Proficy iFIX plant_applications_scopes: note: >- Plant Applications publishes a scope-per-application table (mes..user). Transcribed verbatim; the "applies to" column names the Web Client application each scope unlocks. source: https://www.gevernova.com/software/documentation/uaa/version2025/r_proficyauth_plantapps_groups_in_uaa.html scopes: - {scope: mes.activities.user, applies_to: Activities} - {scope: mes.alarms.user, applies_to: Alarms / Alarm Notifications} - {scope: mes.analysis.user, applies_to: Analysis} - {scope: mes.approval_cockpit.user, applies_to: Approval Cockpit} - {scope: mes.autolog.user, applies_to: Autolog} - {scope: mes.bom_editor.user, applies_to: BOM Editor} - {scope: mes.configuration_management.user, applies_to: Configuration} - {scope: mes.downtime.user, applies_to: Downtime} - {scope: mes.engineeringChangeOrder.user, applies_to: Engineering Change Orders} - {scope: mes.equipment.user, applies_to: OEE Dashboard} - {scope: mes.genealogy.user, applies_to: Genealogy} - {scope: mes.lineoverview.user, applies_to: Line Overview} - {scope: mes.my_machines.user, applies_to: My Machines} - {scope: mes.ncm_management.user, applies_to: Non Conformance} - {scope: mes.operations.user, applies_to: Unit Operations} - {scope: mes.operatorlog.user, applies_to: Operator Log} - {scope: mes.order_management.user, applies_to: Work Order Manager} - {scope: mes.process_orders.user, applies_to: Process Orders} - {scope: mes.property_definition.user, applies_to: Property Definition} - {scope: mes.receiving_inspection.user, applies_to: Receiving Inspection} - {scope: mes.reports.user, applies_to: Reports} - {scope: mes.route_management.user, applies_to: Route Editor} - {scope: mes.security_management.user, applies_to: Security} - {scope: mes.time_booking.user, applies_to: Time Booking} - {scope: mes.waste.user, applies_to: Waste} - {scope: mes.work_queue.user, applies_to: Work Queue}