A user is an individual to whom you give permission to access AR System and BMC Helix ITSM applications. Users can be members of multiple groups or no group at all. Users in BMC Helix ITSM range from an administrator who maintains the entire system to employees who submit requests or view data.
You can manage users inAR System by using the User form and in BMC Helix ITSM by using the CTM:People form.
User and group access overview
in AR System documentation
You can assign users to groups according to their need to access information. For example, you might create a group called Help Desk whose members are permitted to view and change only certain fields on a Help Desk form. You might have another group called IT Data Access whose members are permitted to view and change all fields on the Help Desk form.
User and group access overview
in AR System documentation
in AR System documentation
Every field on a form has access control. You can set field level permissions when you define the field properties in Developer Studio. Each field can have a list of groups that can access the field and the data entered into it.
Access control overview
in AR System documentation
You can assign user permissions to control how people access and interact with the BMC Helix ITSM. You assign user permissions on the People form. There are different aspects to the user permissions, which together make up the permission model: Permission groups and Support groups.
In BMC Helix ITSM applications, access permissions are based on roles. Like groups, roles have permissions to access forms, fields, ticket data, and so on. However, unlike groups, roles are defined for an application and are then associated with groups on the server where the application is deployed.
You can assign users to groups, and then associate the groups with roles.
Permission groups are used to grant users access to applications, modules, and sub-components in BMC Helix ITSM.
![]()
Support groups control access to data. Support groups play an important role in the BMC Helix ITSM permission model by controlling access to data. A user can modify only those records that are assigned to the support groups that the user is a member of.
For example, if a user is assigned the role of Service Desk Analyst and is a member of the Hardware support group, then the user can modify only incident requests that are assigned to the Hardware support group. The user can view other incident requests but cannot modify them.
![]()
Each ticket or a record is referred to as a row in BMC Helix ITSM. The ticket data access is granted to individuals (for example, submitter, on behalf of, and assignee) and support groups associated with a ticket. The Row-level security feature restricts ticket data access to only those users who require it.
You can configure a hierarchical relationship between groups to allow the parent group to inherit the permissions of the child group.
Functional roles
Functional roles provide extended access to an application, module, and sub-component functions.
For example, Support staff that are assigned the Broadcast Submitter functional role can create and modify broadcast messages.
In a multitenant environment, the ticket data is accessible to users based on the following two options:
Unrestricted: Users with the BMC Helix ITSM Unrestricted Access role have access to all ticket data.
Row-level: In the Applications Permissions Model setting, you can choose to provide ticket data access at support group level or support group and company level.
People form
People information is stored on the CTM:People form. Always configure people records by opening the ITSM People form from the Application Administration Console. Information that you add or modify on the BMC Helix ITSM People form is automatically updated to the AR System User form, but information updated on the User form is not updated to the People form.
Visibility groups
(Knowledge Management)
BMC Helix ITSM: Knowledge Management uses visibility groups to restrict access to knowledge base content. You can specify the audience for your article by assigning one or more visibility groups to the article.
You can create visibility groups for a specific company or for the Global company. A knowledge article is visible to users according to this configuration.
How knowledge articles are found
in Knowledge Management documentation
For the users to use their existing credentials to authenticate into BMC Helix Portal, the BMC SaaS Operations team needs to perform some configurations to sync the BMC Helix ITSM users into BMC Helix Portal. For more information, contact BMC Support.