Previous Topic: Connection Pool

Next Topic: Primary Views Definitions

Security Models

Prior to r12.5 it was only possible to have a single RLS model. In order to change these required a one time running of scripts to change the RLS model which would apply to all user. Now it is possible for multiple RLS models to exist and different reviewers can apply RLS using different models. Setting up these models is done via the ACon (see Acon help for details). Below we give a brief description of the models.

In addition to the models below it is also possible to create "Hybrid" models which are combinations of one Management Group model and one Policy based model. Again this can be done using the Administration Console.

Management Group (Standard) model

This is the default management group row level security model.

Management Group (Standard, Self exclude) Model

This is an extension of the Management Group default row level security model, but it excludes events from being returned that include the logged on user as a participant on the event.

Management Group (Sender) model

This applies row level security so that when a reviewer runs an event search, they can only view events where the sender was in their management group when the event was captured. This contrasts with the Management Group default row level security model, whereby reviewers are permitted to view events where at least one participant was in their management group.

Management Group (Sender, Self exclude) model

This is an extension of the sender row level security model, but it excludes events from being returned that include the logged on user as the sender of the event.

Policy (Standard) model

This the row level security model based on policies the reviewer is allow to see.

Policy (Standard, Self exclude) model

This the row level security model based on policies the reviewer is allow to see but it excludes events from being returned that include the logged on user as the sender of the event.