Operation permissions

Use the screen Operation permissions (ADMINISTRATION  Operation permissions  Operation permissions) to view or edit the permissions granted to individual users, groups or roles.

image401

Permission filter

The upper part of the screen contains filter controls, which can help you find specific permission grants. The quick filter field offers filtering by username, group or role name.

Or you can click the Filter button to display a dialog with several tabs. The Filter tab provides the following options:

  • User, group or role name – you can fill in a name or a part of it.

  • Domain – select a domain from the list; permissions of users (groups, roles) from that domain will be displayed,

  • Operation – select a system operation from the list.

  • Object type – search for all objects or a specific domain, group of users, container, document class, rank, folder.

  • Privilege – EXECUTE, GRANT or REVOKE.

Click Use to apply the filter and display matching entries in the Operation Permissions screen. For more details on filtering, see chapter Filtering.

List of permissions and revoking permissions

The table with existing (granted) permissions is displayed based on the filter settings in the Operation Permissions screen. The table shows the following:

  • Actions – use the popelnice button to revoke the permission from the subject.

  • Graphical subject type indicator – image402 enabled internal user or image403 role.

  • Subject name – name of the user, group or role who is granted the permission.

  • Operation the permission applies to.

  • Object type and Object, if applicable for the operation.

  • Privilege, meaning whether the permission is to perform the action (EXECUTE), grant the permission (GRANT) or remove it (REVOKE).

image404

Granting a permission

The button Grant permission is placed above the list of granted permissions. Click the button to display the permission granting dialog.

  • In Privilege, specify whether it is a permission to EXECUTE (perform the operation), GRANT (assign the operation permission) or REVOKE (remove the operation permission).

  • In the Subject field, select a user, group or role, who will be granted the permission.

  • Then use the Operation field to select the required operation from the list (to view the whole list, see chapter List of operation permissions).

  • Then select the Object type. If the operation does not apply to any objects, only the option “NONE (none)” is available. If it applies to objects, the option “ALL (all)” is available, meaning that the permission will apply to all objects, and, if applicable, also one or more types (the permission will be granted to the selected type objects only, such as those from the given domain).

image405

Confirm the dialog by clicking Grant permission.