Previous Topic: Preconditions for Object Access in AreasNext Topic: Replication


Area Permissions Derived

Area permissions can be set or are derived in the following ways:

Area permission from security profile

If the creation user is valid when a secured object is created, then the area permissions are derived from the user who created the object.

(Security level: Creation User)

Area permission from a group

This case only applies when the secured object is member of a group and inheritance is enabled.

(Security level: Group)

Area permission set manually

A user may set the area permission for a certain object manually.

(Security level: Object)

Area permission by default

If a secured object is created and the creation user is not set or could not be found in the user list, then the area permissions are derived from the global configuration settings (global default permissions).

(Security level: Global Settings)

The following illustration shows the different ways an object’s area permission can be derived:

Graphic showing where an area permission can derive from