Universal Search reference

Permission sets

Every grant in the two Universal Search permission sets, BAA SEARCH and BAA SEARCH ADM, exactly as shipped in the current release, and who should get each one.

updated: applies-to: 1.0.0.1

This page applies to version 1.0.0.1; the current product version is 1.0.0.0.

Universal Search installs two assignable permission sets. This reference lists every grant in each set, exactly as shipped in the current release, so you can review them before assigning them or combine them with your own sets. For the step-by-step assignment, see Assign permissions.

Permission Sets list showing BAA SEARCH Universal Search - Use and BAA SEARCH ADM Universal Search - Admin
Both sets are assignable.

BAA SEARCH: Universal Search - Use

Object ID 14291940. Assign to every user who searches.

Object Permission
Table data BAA Search Setup Read
Table data BAA Search Index Config Read
Table data BAA Search Index Entry Read
Table data BAA Search Index Queue Read, Insert
Table BAA Search Setup Execute
Table BAA Search Index Config Execute
Table BAA Search Index Entry Execute
Table BAA Search Index Queue Execute
Page BAA Universal Search Execute
Codeunit BAA Search API Execute
Codeunit BAA Search Query Engine Execute
Codeunit BAA Search Tokenizer Execute
Codeunit BAA Search Change Capture Execute
Codeunit BAA Search Index Builder Execute

BAA SEARCH ADM: Universal Search - Admin

Object ID 14291941. Assign to administrators. It includes the BAA SEARCH permission set, plus:

Object Permission
Table data BAA Search Setup Read, Insert, Modify, Delete
Table data BAA Search Index Config Read, Insert, Modify, Delete
Table data BAA Search Index Entry Read, Insert, Modify, Delete
Table data BAA Search Index Queue Read, Insert, Modify, Delete
Page BAA Search Setup Card Execute
Page BAA Search Index Config List Execute
Page BAA Activation Wizard Execute
Codeunit BAA Search License Client Execute
Codeunit BAA Search Http Execute
Codeunit BAA Search Install Execute
Codeunit BAA Guided Experience Execute
Table data Job Queue Entry Read, Insert, Modify, Delete
Table data Job Queue Category Read, Insert, Modify
Table data NAV App Installed App Read

The three standard tables at the end are what an administrator who is not a SUPER user needs to run Start Indexing, which schedules the background job, and to complete activation, which reads the Business Central version sent with the request. See Start indexing.

Permissions the app carries itself

Two Universal Search codeunits carry their own permissions, so they work for users without either set:

  • BAA Search Change Capture can read and insert into the index queue, and read the index configuration and setup. Users who post documents in an indexed table therefore do not need a Universal Search permission set.
  • BAA Search Index Builder, the job queue codeunit, can read, insert, modify and delete index entries and queue rows, read and modify the index configuration, and read and insert the setup record.

What permissions do not change

Neither set gives access to Business Central's business tables. Both sets can read the app's own index table, which stores the text of every indexed field. Search results only include tables the searching user can already read, and opening a result checks the read permission on the record's table again. The check is per table, not per record; see Assign permissions for what that means for tables protected by security filters.

As defined in the app

The two definitions, verbatim from the current release:

permissionset 14291940 "BAA SEARCH"
{
    Caption = 'Universal Search - Use';
    Assignable = true;
    Permissions =
        tabledata "BAA Search Setup" = R,
        tabledata "BAA Search Index Config" = R,
        tabledata "BAA Search Index Entry" = R,
        tabledata "BAA Search Index Queue" = RI,
        table "BAA Search Setup" = X,
        table "BAA Search Index Config" = X,
        table "BAA Search Index Entry" = X,
        table "BAA Search Index Queue" = X,
        page "BAA Universal Search" = X,
        codeunit "BAA Search API" = X,
        codeunit "BAA Search Query Engine" = X,
        codeunit "BAA Search Tokenizer" = X,
        codeunit "BAA Search Change Capture" = X,
        codeunit "BAA Search Index Builder" = X;
}
permissionset 14291941 "BAA SEARCH ADM"
{
    Caption = 'Universal Search - Admin';
    Assignable = true;
    IncludedPermissionSets = "BAA SEARCH";
    Permissions =
        tabledata "BAA Search Setup" = RIMD,
        tabledata "BAA Search Index Config" = RIMD,
        tabledata "BAA Search Index Entry" = RIMD,
        tabledata "BAA Search Index Queue" = RIMD,
        page "BAA Search Setup Card" = X,
        page "BAA Search Index Config List" = X,
        page "BAA Activation Wizard" = X,
        codeunit "BAA Search License Client" = X,
        codeunit "BAA Search Http" = X,
        codeunit "BAA Search Install" = X,
        codeunit "BAA Guided Experience" = X,
        tabledata "Job Queue Entry" = RIMD,
        tabledata "Job Queue Category" = RIM,
        tabledata "NAV App Installed App" = R;
}

The shipped BAA SEARCH ADM file also contains a comment above the last three lines explaining why they are needed; it is omitted here.

What's next

Return to the guide: Assign permissions, or see the field reference.

// next step

Ready to try Universal Search?