Skip to content

IMan Service & WebAPI Application Pool Permissions

This section describes the access the IMan services and the WebAPI application pool need. See IMan Architecture for what each of them does.

Integration Services

When you design an integration, IMan reads the schema of each Read transform's data source, fills in the connector screens from the connected system and answers the Test and Check buttons. Integration Services does this work. It needs access to the files, databases and systems being queried.

Data Preview & Scheduler Services

The Data Preview Service runs the transforms when you press Refresh in the Designer. The Scheduler Service starts IntManEng.exe for each run, and the engine runs as the Scheduler Service's account. Both run part of an integration or a whole integration from end to end. Both need access to every local or remote resource the integrations use, including any that use Windows authentication.

WebAPI Application Pool

The WebAPI runs its endpoints' integrations inside the IManWebAPI application pool. The pool's identity needs the same access to the integrations' resources as the Scheduler Service.

Log Services

Log Services writes the audit log. It must have write access to the IMan database.

Message Broker

The Message Broker runs as LocalSystem and needs no access to the database or to the integrations' resources. The IMan services and the WebAPI application pool connect to it with a broker password the installer creates.

IMan Database Security

All six IMan services and the WebAPI application pool need read and write access to the IMan database.