MaxQuickLoad · Security & control
You still decide who can change what.
MaxQuickLoad has no permission model of its own. What a person can read or write is decided by the Maximo API key they sign in with, and the MIF applies that key's security to every call — the same passthrough your other integrations already run on. Nothing is added on the way through. Your own administrator can further limit which object structures MaxQuickLoad offers for loading.
The short answer
Nobody gets a right they didn't already have
Three things this tool cannot do — not because we blocked them, but because the MIF never offered them.
Passthrough
Your Maximo security, applied unchanged
There is no MaxQuickLoad permission model for your data. The Maximo API key carries the rights; the MIF enforces them on every call. What Maximo refuses on screen it refuses here, for the same reason.
Path
No route around Maximo
Every transaction goes REST / OSLC through the Integration Framework and takes Maximo's full validation on the way in. No direct database writes — not as a fallback, not for speed.
Record
Nothing changes quietly
Every upload is logged, and the full run history travels inside the load package. Weeks later, on another machine, you can still see what changed.
License levels
Your daily loaders can't reshape your environment.
Every license carries one of two levels, set when it is issued rather than configured in the app — so nobody raises their own. An Operator does the whole loading job and touches nothing that defines the environment; those tools aren't disabled and visible, they aren't there.
Administrator
Configures server connections and object structures, and can export a settings file to stand up another workstation.
Operator
Packages, spreadsheets, templates, and local preferences — the entire loading job, start to finish.
The fence
Three things only an Administrator can do
| Administrator only | Why it's fenced |
|---|---|
| Server connections — add, edit, delete | Which Maximo an upload can reach. |
| Schema Manager — object structures | Which objects and fields are loadable. |
| Export / import the settings file | How an environment reaches another machine. |
The settings export moves connections and object structures, never API keys — each person's key is entered on their own machine. An Operator can replace a key on a server you already approved, which keeps environment refreshes off your desk, but cannot add, rename, retype, or delete one.
Scope
You choose which data anyone here can touch
Object structures decide what is on the table at all, and they are gated twice, independently. A load has to clear both.
Gate one · in the app
Only the objects you publish
An Administrator publishes object structures onto the workstation. If one was never added, there is nothing for an Operator to select.
Gate two · in Maximo
Your object structure security still rules
Maximo enforces it regardless of what the app offers. A published structure is still only as open as the signed-in user's own rights make it.
Recommended practice
Give loading its own security group
Our advice, not a product behavior: define the loading role as a Maximo security group — a Data Loader, an Asset Data Manager — so the rights are written down once and reviewed like any other group you own.
Security & control
Watch it say no.
The convincing part of a demo isn't the load that works — it's the tool declining an action the signed-in user isn't authorized to perform. Bring whoever owns Maximo security.