openapi: 3.2.0 info: title: Visier Administration Users V1 API description: Visier APIs for managing your tenant or tenants in Visier. license: name: Apache License, Version 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 version: 22222222.99201.3040 security: - ApiKeyAuth: [] BearerAuth: [] - ApiKeyAuth: [] CookieAuth: [] - ApiKeyAuth: [] OAuth2Auth: [] tags: - name: Users V1 x-displayName: Users V1 description: 'Manage users within an organization, such as assigning permissions to users and retrieving user permission assignments and application logs. **Tip:** Visier recommends that administrating tenant users focus primarily on managing users at the administrating tenant level. These users likely belong directly to your organization, such as customer support, customer value managers, account executives, and customer success. These users work with clients to manage their day-to-day solution needs' paths: /v1/admin/permissions/users: put: tags: - Users V1 summary: Assign permissions to users description: 'This API allows you to assign a permission to specific users. Administrating tenant users can assign permissions to users in the administrating tenant and in the analytic tenants those users belong to. To assign permissions to users in a project for the administrating tenant, provide a project UUID in the `ProjectID` request header. Administrating tenants can assign permissions to users in analytic tenants by providing a tenant code and project ID in the request body.' operationId: UsersV1_AssignPermissions parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean - name: SessionBasedPermissions in: header description: If `true`, the API call assigns user permissions that are only valid for the specified `SessionRepoId` without creating a new production version. When a user signs in to your application with the `SessionRepoId`, their session-based permissions are valid until the user session ends. Cannot be `true` if `NonVersioned` is `true`. Default is `false`.
**Note:** This header is in **limited availability**. If you are interested in using it, please contact your Customer Success Manager (CSM). schema: type: boolean - name: SessionRepoId in: header description: Optionally, specify a session repository ID to overwrite the user's permissions that are associated with the `SessionRepoId`. Only valid with `SessionBasedPermissions`. If omitted and `SessionBasedPermissions` is `true`, the API creates a new `SessionRepoId`. schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/servicing.AssignRevokePermissionsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.AssignRevokePermissionsResponseDTO' delete: tags: - Users V1 summary: Remove permissions from users description: 'This API allows you to remove a permission from specific users. Administrating tenant users can remove permissions from users in the administrating tenant and in the analytic tenants those users belong to. To remove permission from users in a project for the administrating tenant, provide a project UUID in the `ProjectID` request header. Administrating tenants can remove permissions from users in analytic tenants by providing a tenant code and project ID in the request body.' operationId: UsersV1_RemovePermissions parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean requestBody: content: application/json: schema: $ref: '#/components/schemas/servicing.AssignRevokePermissionsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.AssignRevokePermissionsResponseDTO' /v1/admin/permissions/{permissionId}/users: get: tags: - Users V1 summary: Retrieve users that are assigned a specific permission description: 'This API allows you to retrieve all the users that are assigned a specified permission. You must know the ID of the permission you want to retrieve users for. To specify the project in which to retrieve users assigned to a specific permission for the login tenant, provide a project UUID in the `ProjectID` request header. If omitted, the request retrieves users assigned to a specific permission from production.' operationId: UsersV1_GetPermissionAssignedUsers parameters: - name: permissionId in: path description: The unique identifier of the permission you want to retrieve users for. required: true schema: type: string - name: includeUserGroups in: query description: "If `true`, the response returns a list of all users that are assigned the permission, including users that are\n assigned the permission through a user group.\n If `false`, the response returns a list of the users that are directly assigned the permission." schema: type: boolean - name: tenantFilter in: query description: Specify the tenant to retrieve the list of users from. schema: type: string - name: limit in: query description: The number of results to return. The maximum number of tenants to retrieve is 100. schema: type: integer format: int32 - name: start in: query description: The index to start retrieving results from, also known as offset. The index begins at 0. schema: type: integer format: int32 - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.PermissionAssignedUsersDTO' /v1/admin/user-groups: get: tags: - Users V1 summary: Retrieve a list of all user groups description: 'This API allows you to retrieve the full list of user groups in a tenant. To specify the project in which to retrieve user groups for a tenant, provide a project UUID in the `ProjectID` request header. If omitted, the request retrieves user information from production.' operationId: UsersV1_GetAllUserGroups parameters: - name: tenantCode in: query description: Specify the tenant to retrieve the list of user groups from. schema: type: string - name: limit in: query description: The number of results to return. The maximum number of users to retrieve is 1000. schema: type: integer format: uint32 - name: start in: query description: The index to start retrieving results from, also known as offset. schema: type: integer format: uint32 - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.UserGroupsGetAPIResponseDTO' /v1/admin/user-groups/permissions: put: tags: - Users V1 summary: Assign permissions to user groups description: 'This API allows you to assign a permission to specific user groups. This assigns the permission to all users in the user group. To assign permissions to user groups in a project, provide a project UUID in the `ProjectID` request header.' operationId: UsersV1_AssignPermissionsToUserGroups parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/admin.PermissionsToUserGroupsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.PermissionsToUserGroupForTenantDTO' delete: tags: - Users V1 summary: Remove permissions from user groups description: 'This API allows you to remove a permission from specific user groups. To remove permissions from user groups in a project, provide a project UUID in the `ProjectID` request header.' operationId: UsersV1_RevokePermissionsFromUserGroups parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/admin.PermissionsToUserGroupsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.PermissionsToUserGroupForTenantDTO' /v1/admin/user-groups/users: put: tags: - Users V1 summary: Assign users to user groups description: 'This API allows you to assign users to specific user groups. To assign users to user groups in a project for the administrating tenant, provide a project UUID in the `ProjectID` request header. Administrating tenants can assign users to user groups in multiple analytic tenants by providing a tenant code and project ID in the request body. We recommend that administrating tenants set the analytic tenant in which to execute the API call using the `TargetTenantID` request header.' operationId: UsersV1_AddUsersToUserGroup parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean - name: Prefer in: header description: 'When `NonVersioned: true`, use `Prefer` to optionally specify if API calls should be subject to locking. Locking prevents incremental changes in multiple API calls from overwriting each other. The `Prefer` header works alongside a tenant feature flag. When enabled, the default is `nvLock=global`. When disabled, the default is not to lock API calls. Contact Visier Technical Support to enable the tenant feature flag. Valid values for the `Prefer` header: * `nvLock=global`: Run API calls sequentially. Sequential API calls prevent calls from unintentionally overwriting each other. * `nvLock=artifact`: Allow API calls in parallel. Parallel API calls only work if the calls do not conflict with each other. If a change wasn''t applied, the request fails and returns the HTTP 409 conflict error. Run the request again until successful. * `nvLock=none`: Disable the global lock if the tenant feature flag is enabled.' schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/admin.UsersToUserGroupsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.SecurityAssignmentResponseDTO' delete: tags: - Users V1 summary: Remove users from user groups description: 'This API allows you to remove users from specific user groups. To remove users from user groups in a project for the administrating tenant, provide a project UUID in the `ProjectID` request header. Administrating tenants can remove users to user groups in multiple analytic tenants by providing a tenant code and project ID in the request body. We recommend that administrating tenants set the analytic tenant in which to execute the API call using the `TargetTenantID` request header.' operationId: UsersV1_RemoveUsersFromUserGroup parameters: - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean - name: Prefer in: header description: 'When `NonVersioned: true`, use `Prefer` to optionally specify if API calls should be subject to locking. Locking prevents incremental changes in multiple API calls from overwriting each other. The `Prefer` header works alongside a tenant feature flag. When enabled, the default is `nvLock=global`. When disabled, the default is not to lock API calls. Contact Visier Technical Support to enable the tenant feature flag. Valid values for the `Prefer` header: * `nvLock=global`: Run API calls sequentially. Sequential API calls prevent calls from unintentionally overwriting each other. * `nvLock=artifact`: Allow API calls in parallel. Parallel API calls only work if the calls do not conflict with each other. If a change wasn''t applied, the request fails and returns the HTTP 409 conflict error. Run the request again until successful. * `nvLock=none`: Disable the global lock if the tenant feature flag is enabled.' schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/admin.UsersToUserGroupsRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.SecurityAssignmentResponseDTO' /v1/admin/user-groups/{userGroupId}/users: get: tags: - Users V1 summary: Retrieve a list of user group users description: 'This API allows you to retrieve the list of users explicitly assigned to a user group. Users that are implicitly included in the user group through the user group''s dynamic filters are not returned by this endpoint. To specify the project in which to retrieve user group users for the login tenant, provide a project UUID in the `ProjectID` request header. If omitted, the request retrieves user group users from production.' operationId: UsersV1_GetUserGroupUsers parameters: - name: userGroupId in: path description: The ID of user group. required: true schema: type: string - name: tenantFilter in: query description: Specifies the tenant to retrieve the list of users from. schema: type: string - name: limit in: query description: The number of results to return. The maximum number of tenants to retrieve is 100. schema: type: integer format: uint32 - name: start in: query description: The index to start retrieving results from, also known as offset. The index begins at 0. schema: type: integer format: uint32 - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.UserGroupsUsersDTO' /v1/admin/users: get: tags: - Users V1 summary: Retrieve a list of all users description: 'This API allows you to retrieve the full list of users and their current states. To specify the project in which to retrieve user information, provide a project UUID in the `ProjectID` request header. If omitted, the request retrieves user information from production.' operationId: UsersV1_GetAllUsers parameters: - name: tenantCode in: query description: Specify the tenant to retrieve a list of users from. schema: type: string - name: assignedProfiles in: query description: If true, the response returns a list of the user's assigned profiles. schema: type: boolean - name: assignedPermissions in: query description: If true, the response returns the user's assigned permissions. schema: type: boolean - name: assignedUserGroups in: query description: If true, the response returns the user's assigned user groups. schema: type: boolean - name: limit in: query description: The number of results to return. The maximum number of users to retrieve is 1000. schema: type: integer format: uint32 - name: start in: query description: The index to start retrieving results from, also known as offset. The index begins at 0. schema: type: integer format: uint32 - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.AllUsersGetAPIResponseDTO' post: tags: - Users V1 summary: Add a user description: Create a new user. Administrating tenant users can specify the tenant in which to add a user. operationId: UsersV1_AddUser parameters: - name: tenantCode in: query description: Specify the tenant to create a user in. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/servicing.UserCreationAPIRequestDTO' required: true responses: '201': description: OK content: application/json: schema: $ref: '#/components/schemas/UserCreationAPIResponseDTO' default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' /v1/admin/users/{userId}: get: tags: - Users V1 summary: Retrieve a user's details description: 'This API allows you to retrieve all details for a specified user. To specify the project in which to retrieve user information, provide a project UUID in the `ProjectID` request header. If omitted, the request retrieves user information from production.' operationId: UsersV1_GetUserDetail parameters: - name: userId in: path description: The ID of the user you want to retrieve. required: true schema: type: string - name: tenantCode in: query description: Specify the tenant to retrieve a user from. schema: type: string - name: assignedProfiles in: query description: If true, the response returns a list of the user's assigned profiles. schema: type: boolean - name: assignedPermissions in: query description: If true, the response returns the user's assigned permissions. schema: type: boolean - name: assignedUserGroups in: query description: If true, the response returns the user's assigned user groups. schema: type: boolean - name: ProjectID in: header description: Optionally, specify a project in which to make the request. If omitted, the request uses the production version. schema: type: string format: uuid - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string - name: NonVersioned in: header description: If `true`, the API call executes on non-versioned artifacts and create/update actions take effect without a new production version. If `false`, the API call executes on versioned artifacts and create/update actions release a new production version. Default is `false`. schema: type: boolean responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.UserGetAPIResponseDTO' put: tags: - Users V1 summary: Update a user description: Update an existing user's information, such as their display name or if the user is enabled in Visier. operationId: UsersV1_UpdateUser parameters: - name: userId in: path description: The ID of the user you want to update. required: true schema: type: string - name: tenantCode in: query description: Specify the tenant to update a user in. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/servicing.UserUpdateAPIRequestDTO' required: true responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/servicing.UserUpdateAPIRequestDTO' delete: tags: - Users V1 summary: Delete a user description: Delete an existing user. Administrating tenant users can specify the tenant from which to delete a user. operationId: UsersV1_DeleteUser parameters: - name: userId in: path description: The ID of the user you want to delete. required: true schema: type: string - name: tenantCode in: query description: Specify the tenant to delete a user in. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' '200': description: OK content: application/json: schema: $ref: '#/components/schemas/admin.DeleteUserResponse' /v1/admin/users/reports/application-logs: get: tags: - Users V1 summary: Retrieve the Application Logs description: 'This API allows you to export the Application Logs for a tenant. The Application Logs track information about your users and how they are using the application. Performing regular audits will help you identify potential security issues and keep your data safe. As part of user management, download the Application Logs to monitor user activity and logon events to ensure your users are performing authorized activities. Application logs are retained in the system for 180 days. Administrating tenant users can export application logs for the administrating tenant and the analytic tenants those users belong to.' operationId: UsersV1_GetApplicationLogsXLSX parameters: - name: startTime in: query description: An inclusive date-time in milliseconds to start retrieving Application Logs from. schema: type: string examples: startTime: value: 1738368000000 description: The start time 2025-02-01:00:00:00 GTM in milliseconds. - name: endTime in: query description: An exclusive date-time in milliseconds to stop retrieving Application Logs from. schema: type: string examples: endTime: value: 1740787200000 description: The end time 2025-03-01:00:00:00 GTM in milliseconds. - name: tenantCode in: query description: Specify the tenant to retrieve Application Logs from. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: '200': description: An XLSX file. content: application/vnd.ms-excel: schema: type: string format: binary default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' /v1/admin/users/{userId}/reports/data-security: get: tags: - Users V1 summary: Retrieve the Data Security Report description: 'This API allows you to export the data security report of a user. The Data Security Report provides information about a specific user to see which populations and properties that user has access to as a result of the permissions assigned to them. Administrating tenant users can export the report for users in the administrating tenant and the analytic tenants those users belong to.' operationId: UsersV1_GetDataSecurityReportXLSX parameters: - name: userId in: path description: The ID of the user to retrieve the report for. required: true schema: type: string - name: tenantCode in: query description: Specify the tenant to retrieve the Data Security Report from. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: '200': description: An XLSX file. content: application/vnd.ms-excel: schema: type: string format: binary default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' /v1/admin/users/reports/profile-assignments: get: tags: - Users V1 summary: Retrieve user profile assignments in XLSX format description: 'This API allows you to export the profiles assigned to each user. This report details the profiles assigned to each user and the profile validity period. Administrating tenant users can export profile assignments for the administrating tenant and the analytic tenants those users belong to.' operationId: UsersV1_GetProfileAssignmentsXLSX parameters: - name: tenantCode in: query description: Specify the tenant to retrieve profile assignments from. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: '200': description: An XLSX file. content: application/vnd.ms-excel: schema: type: string format: binary default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' /v1/admin/users/reports/permission-assignments: get: tags: - Users V1 summary: Retrieve user permissions in XLSX format description: 'This API allows you to export the user permission assignments for a tenant. The permission assignments report provides a summary of the permissions your users have been assigned and how each permission is being used across your user base, as well as the users that do not have any permissions assigned to them. Administrating tenant users can export permission assignments for the administrating tenant and the analytic tenants those users belong to.' operationId: UsersV1_GetUserPermissionsXLSX parameters: - name: tenantCode in: query description: Specify the tenant to retrieve the permission assignments report from. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: '200': description: An XLSX file. content: application/vnd.ms-excel: schema: type: string format: binary default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' /v1/admin/users/reports/permissions-list: get: tags: - Users V1 summary: Retrieve a list of all permissions in XLSX format description: 'This API allows you to export the list of permissions in a tenant. This report includes the permission name, permission description, and permission ID for all permissions in the tenant. Administrating tenant users can export permissions lists for the administrating tenant and the analytic tenants those users belong to.' operationId: UsersV1_GetAllPermissionsXLSX parameters: - name: tenantCode in: query description: Specify the tenant to retrieve permissions from. schema: type: string - name: TargetTenantID in: header description: Optionally, specify the tenant that you want to execute the API call on. This defines the tenant that you're logged into. If omitted, the request uses the administrating tenant as the login tenant. schema: type: string responses: '200': description: An XLSX file. content: application/vnd.ms-excel: schema: type: string format: binary default: description: Default error response content: application/json: schema: $ref: '#/components/schemas/Status' components: schemas: admin.TargetProjectForTenantsListDTO: type: object properties: targetProjectForTenants: type: array items: $ref: '#/components/schemas/admin.TargetProjectForTenantDTO' description: "Administrating tenants can specify the tenants and projects in which to make assignments to users. Specify one `projectId` per `tenantCode`.\n If omitted, the request is immediately published to production or applied to the `ProjectID` in the request header, if available, for the administrating tenant or TargetTenantID, if available." servicing.AllUserGroupsAssignedForLocalTenantDTO: type: object properties: assignedUserGroups: type: array items: $ref: '#/components/schemas/servicing.UserGroupAssignedForLocalTenantDTO' description: A list of objects representing the available user groups. admin.DeleteUserResponse: type: object properties: {} servicing.AllPermissionsAssignedForLocalTenantDTO: type: object properties: assignedPermissions: type: array items: $ref: '#/components/schemas/servicing.PermissionAssignedForLocalTenantDTO' description: A list of objects representing the user's permissions. admin.UserSecurityAssignmentsDTO: type: object properties: id: type: string description: The unique identifier associated with the user group. name: type: string description: The name of the user group. users: type: array items: $ref: '#/components/schemas/admin.SimpleUserDTO' description: A list of objects representing the users assigned to or removed from the user group. admin.PermissionsToUserGroupForTenantDTO: type: object properties: tenantCode: type: string description: The unique identifier associated with the tenant. status: type: string description: The state of the permission assignment or removal. Valid values are Succeed or Failed. message: type: string description: A detailed description of the request outcome, if available. userGroups: type: array items: $ref: '#/components/schemas/admin.UserGroupGetAPIResponseDTO' description: A list of objects representing user groups and the permissions to assign to or remove from them. admin.SecurityAssignmentResponseDTO: type: object properties: tenants: type: array items: $ref: '#/components/schemas/admin.TenantAssignmentsDTO' description: A list of objects representing the tenants and users that were assigned to or removed from user groups. Status: type: object properties: localizedMessage: type: string description: Localized error message describing the root cause of the error. code: type: string description: Error classification. message: type: string description: Not used. rci: type: string description: Optional root cause identifier. userError: type: boolean description: Indicates whether the error is a user error. description: The response structure for errors. servicing.AllProfileAssignedForLocalTenantDTO: type: object properties: assignedProfiles: type: array items: $ref: '#/components/schemas/servicing.ProfileAssignedForLocalTenantDTO' description: A list of objects representing the user profiles assigned to the user and their validity range. servicing.AdditionalCapabilitiesDTO: type: object properties: additionalCapabilities: type: array items: type: string description: The additional capabilities assigned to this profile. admin.UserGroupsUsersDTO: type: object properties: tenants: type: array items: $ref: '#/components/schemas/admin.UserGroupsUsersForTenantDTO' description: A list of objects representing the users that are explicitly assigned to the user group, organized by the tenants the users belong to. limit: type: integer description: The limit of results to return. The maximum value is 1000. format: uint32 start: type: integer description: The index to start retrieving values from, also known as offset. The index begins at 0. format: uint32 UserCreationAPIResponseDTO: type: object properties: userId: type: string description: The unique identifier associated with the user. username: type: string description: The user's username. This is typically the user's email, such as john@jupiter.com. displayName: type: string description: An identifiable name to display within Visier. For example, "John Smith". employeeId: type: string description: If applicable, and if available, the user employee ID in the data. accountEnabled: type: string description: If true, the user account is enabled. email: type: string description: The user's email address. servicing.AssignRevokePermissionByTenantDTO: type: object properties: tenantCode: type: string description: The unique identifier associated with the tenant. permissions: type: array items: $ref: '#/components/schemas/servicing.AssignRevokePermissionByPermissionDTO' description: A list of objects representing the assigned or removed permissions. status: enum: - Unknown - Succeed - Failed type: string description: The state of the permission assignment. Valid values are Succeed or Failed. format: enum message: type: string description: A detailed description of the request outcome, if available. projectId: type: string description: The ID of the project that the change was made in, if applicable. description: The permissions organized by tenant. servicing.AssignRevokePermissionsRequestDTO: type: object properties: permissions: type: array items: $ref: '#/components/schemas/servicing.AssignRevokePermissionRequestDTO' description: A list of objects representing the permissions to assign to or remove from users. targetProjectForTenantsList: allOf: - $ref: '#/components/schemas/admin.TargetProjectForTenantsListDTO' description: "Administrating tenants can specify the tenants and projects in which to assign permissions to users or remove permissions from users. Specify one `projectId` per `tenantCode`.\n If omitted, the request is immediately published to production or applied to the `ProjectID` in the request header, if available, for the administrating tenant or TargetTenantID, if available." description: "Set permissions request\n List of permissionId with assign to user Ids" servicing.UserCreationAPIRequestDTO: type: object properties: username: type: string description: The user's username. This is typically the user's email, such as john@visier.com. displayName: type: string description: An identifiable name to display within Visier. For example, "John Smith". employeeId: type: string description: If applicable, and if available, the user employee ID in the data. accountEnabled: type: string description: If false, the user account is disabled. email: type: string description: The user's email. This is used if the user's email is different from their username. For example, "john.doe@visier.com". admin.TargetProjectForTenantDTO: type: object properties: tenantCode: type: string description: The tenant code. projectId: type: string description: The project in which to make changes for the tenant. servicing.CapabilitiesDTO: type: object properties: capability: type: string description: The name of the capability. accessLevel: type: string description: The access level of the profile for the given capability. viewLevel: type: string description: The view level of the profile for the given capability. admin.UserGroupGetAPIResponseDTO: type: object properties: userGroupId: type: string description: The unique identifier associated with the user group. displayName: type: string description: An identifiable user group name to display in Visier, such as "Leadership User Group". permissions: type: array items: $ref: '#/components/schemas/admin.PermissionResponseDTO' description: A list of objects representing the user's permissions. admin.PermissionsToUserGroupsRequestDTO: type: object properties: userGroups: type: array items: $ref: '#/components/schemas/admin.PermissionsToUserGroupRequestDTO' description: A list of objects representing the user groups and permissions to assign or remove. servicing.AssignRevokePermissionByUserDTO: type: object properties: userId: type: string description: The unique identifier associated with the user. username: type: string description: The user's username. This is typically the user's email, such as john@visier.com. message: type: string description: A meaningful message about the user permission. description: The results of the permission assignment or removal by user. admin.SimpleUserDTO: type: object properties: userId: type: string description: The unique identifier associated with the user. username: type: string description: The user's username. This is typically the user's email, such as john@visier.com. admin.TenantAssignmentsDTO: type: object properties: tenantCode: type: string description: The unique identifier associated with the tenant. status: enum: - Unknown - Succeed - Failed type: string description: The state of the user group assignment. Valid values are Succeed or Failed. format: enum message: type: string description: A detailed description of the request outcome, if available. assignments: type: array items: $ref: '#/components/schemas/admin.UserSecurityAssignmentsDTO' description: A list of objects representing the user group and user assignments. projectId: type: string description: The ID of the project that the change was made in, if applicable. servicing.PermissionAssignedUsersDTO: type: object properties: tenants: type: array items: $ref: '#/components/schemas/servicing.PermissionAssignedByTenantDTO' description: A list of objects representing the users that are assigned the specific permission, organized by the tenants the users belong to. limit: type: integer description: The number of results to return. The maximum number of tenants to retrieve is 100. format: uint32 start: type: integer description: The index of the tenant to start retrieving results from, also known as offset. The index begins at 0. format: uint32 description: Users that are assigned a specific permission. servicing.AssignRevokePermissionRequestDTO: type: object properties: permissionId: type: string description: The unique identifier associated with a permission. userIds: type: array items: type: string description: A list of strings representing unique user IDs. description: "Set permission detail\n permissionId with assign to userIds" servicing.UserGetAPIResponseDTO: type: object properties: userId: type: string description: The unique identifier associated with the user. username: type: string description: The user's username. This is typically the user's email, such as john@jupiter.com. displayName: type: string description: An identifiable name to display within Visier. For example, "John Smith". employeeId: type: string description: If applicable, and if available, the user employee ID in the data. accountEnabled: type: boolean description: If false, the user account is disabled. profiles: allOf: - $ref: '#/components/schemas/servicing.AllProfileAssignedForLocalTenantDTO' description: A list of objects representing the list of available profiles. Not returned if the user has no profiles. permissions: allOf: - $ref: '#/components/schemas/servicing.AllPermissionsAssignedForLocalTenantDTO' description: A list of objects representing the user's permissions. userGroups: allOf: - $ref: '#/components/schemas/servicing.AllUserGroupsAssignedForLocalTenantDTO' description: A list of objects representing the available user groups. lastLogin: allOf: - $ref: '#/components/schemas/servicing.LastLoginDTO' description: An object that represents the time that the user last logged into Visier. email: type: string description: The user's email address. servicing.AssignRevokePermissionByPermissionDTO: type: object properties: permission: $ref: '#/components/schemas/servicing.PermissionAssignedForLocalTenantDTO' users: type: array items: $ref: '#/components/schemas/servicing.AssignRevokePermissionByUserDTO' description: A list of objects representing the users that was permission was assigned to or removed from. description: The results of the permission assignment or removal. servicing.AllUsersGetAPIResponseDTO: type: object properties: users: type: array items: $ref: '#/components/schemas/servicing.UserGetAPIResponseDTO' description: A list of available users. limit: type: integer description: The number of results to return. The maximum number of users to retrieve is 1000. format: uint32 start: type: integer description: The index to start retrieving results from, also known as offset. The index begins at 0. format: uint32 servicing.AssignRevokePermissionsResponseDTO: type: object properties: tenants: type: array items: $ref: '#/components/schemas/servicing.AssignRevokePermissionByTenantDTO' description: A list of objects representing the users that were assigned permissions, organized by the tenants the users belong to. sessionRepoId: type: string description: The results of the permission assignment or removal. servicing.PermissionAssignedForLocalTenantDTO: type: object properties: permissionId: type: string description: The unique identifier associated with the permission. displayName: type: string description: An identifiable permission name to display in Visier, such as "Diversity Access". description: type: string description: A user-defined description of the permission. admin.PermissionResponseDTO: type: object properties: permissionId: type: string description: The unique identifier associated with the permission. displayName: type: string description: An identifiable permission name to display in Visier, such as "Diversity Access". servicing.UserUpdateAPIRequestDTO: type: object properties: displayName: type: string description: An identifiable name to display within Visier. For example, "John Smith". employeeId: type: string description: If applicable, and if available, the user employee ID in the data. accountEnabled: type: string description: If true, the user account is enabled. email: type: string description: The user's email address. username: type: string description: The user's username. This is typically the user's email, such as john@jupiter.com. If a user's username changes, they must authenticate using the new username. admin.UserGroupsGetAPIResponseDTO: type: object properties: userGroups: type: array items: $ref: '#/components/schemas/admin.UserGroupGetAPIResponseDTO' description: A list of user groups. limit: type: integer description: The number of results to return. The maximum number of users to retrieve is 1000. format: uint32 start: type: integer description: The index to start retrieving results from, also known as offset. format: uint32 servicing.LastLoginDTO: type: object properties: timestamp: type: string description: The time that the user last logged into Visier. servicing.UserGroupAssignedForLocalTenantDTO: type: object properties: userGroupId: type: string description: The user group ID. displayName: type: string description: An identifiable user group name to display in Visier, such as "Leadership User Group". admin.UsersToUserGroupRequestDTO: type: object properties: userGroupId: type: string description: The unique identifier associated with the user group. userIds: type: array items: type: string description: A list of strings representing unique user IDs to assign to or remove from the user group. The maximum number of `userIds` per user group is 100. servicing.PermissionAssignedByTenantDTO: type: object properties: tenantCode: type: string description: The unique identifier associated with the tenant. users: type: array items: $ref: '#/components/schemas/servicing.PermissionAssignedUserDTO' description: A list of objects representing the users that the permission is assigned to. description: The users assigned a specific permission, grouped by tenant. admin.UsersToUserGroupsRequestDTO: type: object properties: userGroups: type: array items: $ref: '#/components/schemas/admin.UsersToUserGroupRequestDTO' description: A list of objects representing the user groups and users to assign or remove. targetProjectForTenantsList: allOf: - $ref: '#/components/schemas/admin.TargetProjectForTenantsListDTO' description: "Administrating tenants can specify the tenants and projects in which to assign users to user groups or remove users from user groups. Specify one `projectId` per `tenantCode`.\n If omitted, the request is immediately published to production or applied to the ProjectID in the request header, if available, for the administrating tenant or TargetTenantID, if available." admin.PermissionsToUserGroupRequestDTO: type: object properties: userGroupId: type: string description: The unique identifier associated with the user group. permissionsIds: type: array items: type: string description: A list of strings representing the unique permission IDs to assign. servicing.ProfileAssignedForLocalTenantDTO: type: object properties: profileId: type: string description: The unique identifier associated with the profile. displayName: type: string description: An identifiable profile name to display in Visier, such as "Partner Service Manager". validityStartTime: type: string description: An inclusive date-time when this profile is active. validityEndTime: type: string description: An exclusive date-time when this profile is no longer active. capabilities: type: array items: $ref: '#/components/schemas/servicing.CapabilitiesDTO' description: A list of objects representing the access that this profile has for the capabilities of this profile. additionalCapabilities: allOf: - $ref: '#/components/schemas/servicing.AdditionalCapabilitiesDTO' description: A list of the additional capabilities that are assigned to this profile. admin.UserGroupsUsersForTenantDTO: type: object properties: tenantCode: type: string description: The unique identifier associated with the tenant. users: type: array items: $ref: '#/components/schemas/admin.SimpleUserDTO' description: A list of objects representing the users in the user group. servicing.PermissionAssignedUserDTO: type: object properties: userId: type: string description: The unique identifier associated with the user. username: type: string description: The user's username. This is typically the user's email, such as john@visier.com. permissionFrom: type: string description: "The method through which the user was assigned the permission. The permission may be assigned through\n the following options:\n - User: The permission was directly assigned to the user.\n - UserGroup: The permission was assigned because the user belongs to a user group that is assigned the permission.\n - UserAndUserGroup: The permission was directly assigned to the user and assigned because the user belongs to\n a user group that is assigned the permission." description: The user and the method through which the user was assigned the permission. securitySchemes: CookieAuth: type: apiKey name: VisierASIDToken in: cookie ApiKeyAuth: type: apiKey name: apikey in: header BearerAuth: type: http scheme: bearer OAuth2Auth: type: oauth2 flows: authorizationCode: authorizationUrl: /v1/auth/oauth2/authorize tokenUrl: /v1/auth/oauth2/token scopes: read: Grants read access write: Grants write access password: tokenUrl: /v1/auth/oauth2/token scopes: read: Grants read access write: Grants write access x-tagGroups: - name: administration tags: - Projects - ProductionVersions - UsersV3 - UsersV2 - UserGroupsV2 - UsersV1 - Profiles - Permissions - TenantsV2 - TenantsV1 - ConsolidatedAnalytics - Sources - SystemStatus - EmailDomains - EncryptionKeys - NetworkSubnets - SidecarSolutions - ReleaseVersionConfiguration - VeeConfiguration