Access rules
Least privilege · attributes layered on top of roles, evaluated at every retrieval
Least privilege enforcedDeny wins over allow
—
Active rules
—
Deny rules
—
Roles covered
—
Attributes used
—
Awaiting check
Rule set
Each rule pairs a role with a document type and an attribute condition
Nobody is signed in
Maker and checker on the access configuration itself
Where the document class requires it, a rule you create goes to a second administrator for approval before it takes effect. Your change is accepted and held until they sign it.
—
A count of rules waiting for approval is not recorded. You see the state of a rule when you submit it
Rule builder
Choose an attribute to build a condition
Role
Not recordedDocument type
Not recordedAttribute
This document type declares no metadata fields, so there is no attribute to compare against. The list comes from the fields the type itself declares.
Operator
Value
Effect when the condition holds
Choose the role the rule applies to.
Simulation
Not run yet
The simulator shows what a rule would grant and withhold without saving it, and where an existing deny would override it. Use it to see what a rule does before it goes live. Nothing is written, so a simulation can never change who sees what.