Hi Mark,
I have not been in a situation where there's an admin-like person who can see and monitor a server but has no ability to manage/modify that server (or associated/link objects to it). However, if I understand your requirement correctly then those people would need an effective permission pattern of +RM, -WM, +A. That could be accomplished with the use of a Protect ACT (see Baseline ACTs and Protect Server Definitions) to set the baseline permissions for the server object(s), plus the application of an ACT/ACE to provide +WM to those groups of people that need to associate objects (assign libraries, stored processes etc), plus an ACT/ACE to provide only +A (without WM) to those groups of people that need to monitor but not modify.
I hope this helps. Please let us know how you go.
Cheers Paul
... View more