Creating rules on permissions
Who is this article for?Administrators responsible for user management.
Administration module access is required.
Permission rules allow you to modify some permissions to change their behaviour depending on set criteria.
For example, the Document Read permission gives users the ability to read every Document in the system. You can add a rule that allows the users to only read Documents with a particular Document Type instead.
1. Creating rules
To create a rule:
- Access the Administration module.
- Select Security.
- Choose Groups.
- Open the group you need to add a rule to.
- Click Edit (Pencil icon).
- Open the permission you want to modify.
- Set the rule.
- Click OK.
- Click Save (Tick icon).
You can apply more than one of the same rule to cover multiple scenarios, like giving read permissions to two different Document Types. To do this, repeat the above process as many times as necessary until you've set all the required rules.
Using dynamic security groups?
Although you can add rules to permissions in dynamic groups, this is not recommended.
Dynamic permissions are only granted when the user needs the access to do complete a specific task. Adding a rule to these permissions can introduce situations where the user is denied access and cannot perform the task they need.
1. Creating rules
To create a rule:
- Access the Administration module.
- Select Groups (under Security).
- Open the group you need to add a rule to.
- Click Edit next to the permission you want to modify.
- Set the rule.
- Click OK.
You can apply more than one of the same rule to cover multiple scenarios, like giving read permissions to two different Document Types. To do this, repeat the above process as many times as necessary until you've set all the required rules.
Using dynamic security groups?
Although you can add rules to permissions in dynamic groups, this is not recommended.
Dynamic permissions are only granted when the user needs the access to do complete a specific task. Adding a rule to these permissions can introduce situations where the user is denied access and cannot perform the task they need.
Further reading