Access rules

Least privilege · attributes layered on top of roles, evaluated at every retrieval

Least privilege enforcedDeny wins over allow

—

Active rules

—

Deny rules

—

Roles covered

—

Attributes used

—

Awaiting check

Rule set

Each rule pairs a role with a document type and an attribute condition

Nobody is signed in

Sign in to see these records. Until then every read is refused. Choose who you are signed in as on the dashboard.
Correlationc_52c528ff70ab459a8be9da1f0a9f8226

Maker and checker on the access configuration itself

Where the document class requires it, a rule you create goes to a second administrator for approval before it takes effect. Your change is accepted and held until they sign it.

—

A count of rules waiting for approval is not recorded. You see the state of a rule when you submit it

Rule builder

Choose an attribute to build a condition

Draft

Role

Not recorded

Document type

Not recorded

Attribute

This document type declares no metadata fields, so there is no attribute to compare against. The list comes from the fields the type itself declares.

Operator

Value

Effect when the condition holds

Choose the role the rule applies to.

Simulation

Not run yet

The simulator shows what a rule would grant and withhold without saving it, and where an existing deny would override it. Use it to see what a rule does before it goes live. Nothing is written, so a simulation can never change who sees what.