Learn about PI AF object and local machine permissions
- Last UpdatedFeb 12, 2025
- 1 minute read
- PI System
- PI Server 2024 R2
- PI Server
When installing against a PI AF server, the PI Analysis Service setup process using the PI Server install kit creates the PI AF identity, Asset Analytics, maps the PI Analysis Service account to that identity, and grants that identity the PI AF object permissions shown in the following tables.
By default, the Asset Analytics identity grants these permissions on all AF objects on the AF server: Read/Write, Read/Write Data, Execute, and Annotate.The AF server grants Read access to all Library objects.
Note: If an account has administration privileges on the PI AF server, then the account has all security rights to all objects within the PI AF server, including all databases. This is true whether the account is granted or denied specific rights on individual objects.
The setup process also grants the PI Analysis Service account permission to access the local machine directory.
Configuration database
|
PI AF object |
Permissions |
|---|---|
|
Database |
Read/Write |
|
Elements |
Read/Write, Read/Write Data |
Production databases: PI AF databases containing analyses
|
PI AF object |
Permissions |
|---|---|
|
Database |
Read/Write |
|
Elements |
Read/Write, Read/Write Data |
|
Analyses |
Read/Write, Execute |
|
Event Frames |
Read/Write, Annotate |
Local machine permissions
|
Local machine directory |
Permissions |
|---|---|
|
%ProgramData%\OSIsoft\PIAnalysisNotifications |
Read, Write, Modify |