MaxQuickLoad · Security & control

You still decide who can change what.

MaxQuickLoad has no permission model of its own. What a person can read or write is decided by the Maximo API key they sign in with, and the MIF applies that key's security to every call — the same passthrough your other integrations already run on. Nothing is added on the way through. Your own administrator can further limit which object structures MaxQuickLoad offers for loading.

The short answer

Nobody gets a right they didn't already have

Three things this tool cannot do — not because we blocked them, but because the MIF never offered them.

Passthrough

Your Maximo security, applied unchanged

There is no MaxQuickLoad permission model for your data. The Maximo API key carries the rights; the MIF enforces them on every call. What Maximo refuses on screen it refuses here, for the same reason.

Path

No route around Maximo

Every transaction goes REST / OSLC through the Integration Framework and takes Maximo's full validation on the way in. No direct database writes — not as a fallback, not for speed.

Record

Nothing changes quietly

Every upload is logged, and the full run history travels inside the load package. Weeks later, on another machine, you can still see what changed.

License levels

Your daily loaders can't reshape your environment.

Every license carries one of two levels, set when it is issued rather than configured in the app — so nobody raises their own. An Operator does the whole loading job and touches nothing that defines the environment; those tools aren't disabled and visible, they aren't there.

ADM

Administrator

Configures server connections and object structures, and can export a settings file to stand up another workstation.

OPR

Operator

Packages, spreadsheets, templates, and local preferences — the entire loading job, start to finish.

The fence

Three things only an Administrator can do

Administrator onlyWhy it's fenced
Server connections — add, edit, deleteWhich Maximo an upload can reach.
Schema Manager — object structuresWhich objects and fields are loadable.
Export / import the settings fileHow an environment reaches another machine.

The settings export moves connections and object structures, never API keys — each person's key is entered on their own machine. An Operator can replace a key on a server you already approved, which keeps environment refreshes off your desk, but cannot add, rename, retype, or delete one.

Scope

You choose which data anyone here can touch

Object structures decide what is on the table at all, and they are gated twice, independently. A load has to clear both.

Gate one · in the app

Only the objects you publish

An Administrator publishes object structures onto the workstation. If one was never added, there is nothing for an Operator to select.

Gate two · in Maximo

Your object structure security still rules

Maximo enforces it regardless of what the app offers. A published structure is still only as open as the signed-in user's own rights make it.

Recommended practice

Give loading its own security group

Our advice, not a product behavior: define the loading role as a Maximo security group — a Data Loader, an Asset Data Manager — so the rights are written down once and reviewed like any other group you own.

Where the line sits License levels reduce what can go wrong on a workstation. They are not a substitute for Maximo security and we won't present them as one. What can be written into your Maximo is still decided by the API key you issue and the object structure security you control.

Security & control

Watch it say no.

The convincing part of a demo isn't the load that works — it's the tool declining an action the signed-in user isn't authorized to perform. Bring whoever owns Maximo security.