User Profile Page

The User Profile page allows users to access helpful information, such as profile information, cost control preferences, lists of projects, expenses, and OCLI tokens.

On the Profile Tab, your name, username, organization name, Orion role, and email can be viewed. Depending on the organization’s Orion settings, non-SSO passwords associated with the Orion account can be updated here. For SSO passwords, please contact your organization’s administrator for help.

Orion Roles and Capabilities

There are several user roles and capabilities on Orion. Each user has one role. The role, like the user, is associated with an organization and is defined by a set of capabilities. Capabilities allow users to perform actions on Orion resources. Contact OpenEye, Cadence Molecular Sciences customer support to request one of these roles for a user login.

Some roles include programmatic access through the OCLI (Orion command line interface) in addition to the web UI. Orion is deployed as either a Managed Service stack or a Multitenant (SaaS) stack. Some roles can be used on both types of stack; others are intended for one type only. The following tables list the roles used in each environment and describe the capabilities of each. MT in a role name refers to Multitenant (SaaS) customers.

The user roles and capabilities for basic roles that can be used on both stacks are shown in Table 1.

Table 1. User roles and capabilities in Orion that can be used on both Managed Service and Multitenant (SaaS) stacks.

User Role

Title

Capabilities

Chemist

chemist

Upload or download datasets, run existing floes, analyze
datasets, share datasets, view Shared Views, and
view their own job and storage costs.
Standalone
Search User

standalone-search-user

Access and use Molecule Search and view the databases.

Search
Admin

standalone-search-admin

The same capabilities as a Standalone Search User,
plus the ability to create and delete search databases
and to see other users’ jobs and costs.
Search
Admin
with API
(Read‑Only)

standalone-search-admin-api-read-only

The same capabilities as a Standalone Search Admin,
plus limited access to OCLI.
Search
Admin
with API

standalone-search-admin-api-read-only

The same capabilities as a Search Admin with API (Read‑Only),
plus access to OCLI.

Collaborator

collaborator

Upload or download datasets, analyze datasets, share
datasets, and view Shared Views.
Collaborator
with Search

collaborator-with-search

The same capabilities as a Collaborator, plus the
ability to use Molecule Search.
Table 2. User roles and capabilities only on Managed Service stacks.

User Role

Title

Capabilities

Modeler

modeler

The same capabilities as a Chemist (Table 1), plus the
ability to create new floes.
Organization
Admin

org-admin

The same capabilities as a Modeler, plus the ability
to see other users’ jobs and costs.
Stack
Admin

stack-admin

The same capabilities as all other user roles, plus
the ability to manage Auto Scaling Groups (ASGs).

MT refers to Multitenant (SaaS) customers. There is a quick start guide about OCLI for SaaS users in the Orion Programming Guide.

Table 3. User roles and capabilities only on Multitenant (SaaS) stacks.

User Role

Title

Capabilities

MT
Modeler

mt-modeler

The same capabilities as a Chemist (Table 1), plus
the ability to read the Floe Editor.
MT
Modeler
with API
(Read‑Only)

mt-modeler-api-read-only

The same UI capabilities as an MT Modeler, plus
limited access to OCLI.
MT
Modeler
with API

mt-modeler-api

The same UI capabilities as an MT Modeler with API (Read‑Only),
plus access to OCLI.
MT
Organization
Admin

mt-org-admin

The same capabilities as an MT Modeler, plus the
ability to see other users’ jobs and costs.
MT
Organization
Admin
with API
(Read-Only)

mt-org-admin-api-read-only

The same capabilities as an MT Modeler with API (Read‑Only),
plus the ability to see other users’ jobs and costs.
MT
Organization
Admin
with API

mt-org-admin-api

The same capabilities as an MT Modeler with API, plus
the ability to see other users’ jobs and costs.

Note

MT customers should contact OpenEye, Cadence Molecular Sciences customer support (support@eyesopen.com) to have OCLI access enabled for a user login. See the Tokens Tab documentation below for creating an OCLI token once the role is assigned.

OCLI Access by Role

On Managed Service stacks, OCLI (the Orion Client) is available to all roles, and each role’s OCLI capabilities match what the same user can do in the web UI.

On Multitenant (SaaS) stacks, OCLI is disabled by default and is enabled only when a user is assigned one of the SaaS-only OCLI roles listed in Table 3 (mt-modeler-api, mt-modeler-api-read-only, and associated admin roles).

The following summarizes what each Multitenant role can and cannot do with OCLI:

  • MT Modeler API grants full OCLI access for datasets, files, collections, jobs, floes, and Molecule Search: everything an MT Modeler can do in the web UI.

  • MT Modeler API (read-only) grants limited OCLI access. This role cannot start or delete jobs, cannot create, update, or delete Molecule Search queries, and cannot create, load/unload, or delete Molecule Search databases from OCLI. It can list and read information and download these resources.

  • MT Modelers and MT Organization Admins do not have OCLI access; they may use the web UI only.

For more information on installing and configuring OCLI, see the Orion Programming Guide on authenticating with Orion. A Quick Start guide provides a brief introduction to OCLI for SaaS users.

Additional User Profile Tabs

The Projects Tab lists projects that you do not own but that are shared with you. The number of datasets, records, files, and collections for a project is listed here, as well as the project owner. Please note that these numbers are updated hourly. For each project, clicking the “Leave Project” icon under the Action column will open a pop-up window asking for confirmation to leave the project. After a user leaves a project, the project admin must add them again for the user to access that project.

Global settings can be found on the Preferences Tab. The “Notification” section features two toggles. The first one allows you to disable or enable pop-up notifications. It is set to Off by default. The second toggle filters all Orion notification windows for your current project. If you want to focus on a single project, this option prevents notifications for jobs in other projects. The “Task” section offers four options. The first allows you to receive email notifications for completed Orion tasks such as job completions or failures. It is important to note that this email address is the one listed on the Profile Tab of Orion. You can also choose to hide deprecated floe warnings. The remaining toggles allow you to set the direct upload feature for adding data to Orion; you can also set whether to automatically upload files with their corresponding datasets when using direct upload. The default for these two options is On. All settings on the Preferences Tab can be reset by clicking the red “Reset” button. “Job Cost Limits” can be set globally for both email notification and job termination when a job reaches a specific threshold. Any cost threshold that is set for the global preferences on this page can be overwritten on the Job Form or under the Jobs Tab of the Floe page. For best practices concerning global job cost limits, contact your organization’s Orion administrator or contact OpenEye, Cadence Molecular Sciences customer support.

Note

It is highly recommended to set a global cost limit for the email notification.

Caution

If a job reaches the job cost termination limit, the job will not shut down cleanly, and the results may not be recoverable.

_images/profile_preferences.png

Figure 1. The Preferences Tab.

The Expenses Tab displays the total costs for each project and for storage in the past 24 hours, 7 days, 1 month, 3 months, and 1 year. This information includes deleted project costs when applicable.

The Tokens Tab provides information for OCLI users. All of a user’s tokens are listed here, whether they were created from this tab or through OCLI. The table lists ID, creation date, expiration date, a description, config, and actions. Tokens are created by default when a profile is configured via OCLI without an existing token. To create a token from this tab, click the “Create Token” button and proceed as directed. To copy a token, click the “Eye” icon to make the token visible and then click the “Clipboard” icon, which will turn green with a checkmark to indicate that the token has been copied to your clipboard. Once the token is copied, paste it into the OCLI config file; it can also be provided using:

ocli config profile --with-token

By default, tokens expire approximately 90 days after creation and users will be notified by email seven days before token expiration. These settings are configurable for your organization. For tokens that were created prior to the 2026.4 deployment, the 90 days will start from the date of deployment and NOT the token creation date.

For more information concerning tokens and how to use them, see the Orion Programming Guide configuration commands for Orion profiles and the Quick Start guide on authenticating with Orion.

Orion Administrator View

Users with an Admin role in Orion have the additional Organization Tab. From this tab, Admins can make changes that affect every user within the organization. On the left, an image of the organization’s logo or name can be uploaded. On the right, the name of the organization can be updated. Additionally, similar to the cost thresholds described above, an Admin can set organization-level thresholds. These thresholds will become the default for everyone within the organization. However, users may still change these thresholds on a personal level (as described above) or the job level (see the Floe page).

_images/Admin_ScreenShot.png

Figure 2. Tabs on the Profile Page for Admins.