Business Areas and Jobstreams Not Visible for EEM Users in AAI 24.4
search cancel

Business Areas and Jobstreams Not Visible for EEM Users in AAI 24.4

book

Article ID: 447521

calendar_today

Updated On:

Products

Automation Analytics & Intelligence

Issue/Introduction

After upgrading to Automation Analytics & Intelligence (AAI) version 24.4, users authenticated via EEM (Embedded Entitlements Manager) report that Business Areas and Jobstreams are not visible in the Web UI.

Users may see the following message:

"You do not have permission to view Business Areas or Jobstreams."

Environment

AAI 24.4.x

EEM

Cause

In AAI 24.4, the security evaluation logic for Business Area policies has changed. If an EEM Business Area policy has no explicit resources defined (displaying "[All Resources]" in the EEM UI), AAI fails to apply the policy correctly.

Unlike previous versions, the "[All Resources]" placeholder is no longer treated as a catch-all grant by the AAI authorization engine, resulting in a total denial of access for members of that policy.

Resolution

To restore visibility, the EEM policy must be updated to include an explicit resource list or the wildcard character.

  1. Log into the EEM UI (typically as EiamAdmin).
  2. Navigate to the Policies tab.
  3. Locate the affected Business Area policy (e.g.,BusinessArea).
  4. In the Resources section:
    • To grant specific access: Add the names of the Business Areas explicitly (e.g., AUTO).
    • To grant global access: Enter a single asterisk * as the resource.
  5. Click Save.
  6. Have the user log out of the AAI Web UI and log back in to refresh the security token.