IMan Service & WebAPI Application Pool Permissions¶
This section describes the access the IMan services and the WebAPI application pool need. See IMan Architecture for what each of them does.
Integration Services¶
When you design an integration, IMan reads the schema of each Read transform's data source, fills in the connector screens from the connected system and answers the Test and Check buttons. Integration Services does this work. It needs access to the files, databases and systems being queried.
Data Preview & Scheduler Services¶
The Data Preview Service runs the transforms when you press Refresh in the
Designer. The Scheduler Service starts IntManEng.exe for each run, and the
engine runs as the Scheduler Service's account. Both run part of an integration
or a whole integration from end to end. Both need access to every local or
remote resource the integrations use, including any that use Windows
authentication.
WebAPI Application Pool¶
The WebAPI runs its endpoints' integrations inside the IManWebAPI application pool. The pool's identity needs the same access to the integrations' resources as the Scheduler Service.
Log Services¶
Log Services writes the audit log. It must have write access to the IMan database.
Message Broker¶
The Message Broker runs as LocalSystem and needs no access to the database or to the integrations' resources. The IMan services and the WebAPI application pool connect to it with a broker password the installer creates.
IMan Database Security¶
All six IMan services and the WebAPI application pool need read and write access to the IMan database.