Árvore de páginas

Index


Speaking of defining security criteria for folder or for document...

The platform offers security settings options to define access permissions and restrictions, as well as actions on folders and documents. These security criteria can be configured specifically for each user, user groups, or all active users on the platform. Therefore, the same user can be configured with several types of permissions and restrictions for a given folder or document, considering the highest permissions and restrictions defined for this user.

Restrictions are used to override permissions; therefore, a restriction without a permission does not generate any results. 

Example of when a restriction can be used: a user group was granted full permission to a document. However, one of the users belonging to the group should have view-only permission. Therefore, a Modification type restriction must be registered for this particular user, which will only enable the user to view the document, and not make any changes.

Users must have full permission for the folder or document in order to define or change its security criteria.

Whenever the security settings of a folder or document are changed in the platform, such changes are not automatically applied to users connected to Fluig Connect. To apply the changes, click “Reload Fluig Connect” in order to update all remote directory settings.



Access security configuration


01. Click the Documents menu.

02. Find the folder or document whose security has to be configured.

03. Click the More actions button for the folder or document and select the Properties option.

04. Click the Security tab.


Inherit security from the parent folder


This option is only available for subfolders or documents created within folders where security criteria is configured.


01. Go to the Security tab as shown in the Access security configuration item.

02. Check the Inherits security from parent? option. 

When the option Inherits security from parent? is checked, all safety criteria of the parent folder are assigned to the folder or document. If the parent folder also inherits the same security criteria, these criteria (from the "grandparent" folder) are applied to the folder or document, and so on consecutively.

Even if the security criteria are defined as inherited, you can include other criteria that will be exclusive to the folder or document.


Add permission


01. Go to the Security tab as shown in the Access security configuration item.

02. Click on 1 – Permissions.

The permissions area allows you to configure access to the folder or document being created or edited.

03. Define the permission criteria.

Collaborator
Define permission criteria for a specific user.

Group
Define permission criteria for a user group.

All
Define permission criteria for all platform users.

04. In Group rules, select the option that determines the rule that will be considered for user groups.

Depending on the option selected, the security treatment for groups will be different. The available options are:

ALL group users: when selected, all group users for whom you have defined permission criteria will have access to the document/folder. This access is limited to the security level defined for the group. This option works with the concept of union of all groups.

ONLY group common users: when selected, only group common users for whom you have defined permission criteria will have access to the document/folder. This access is limited to the security level defined for the group. This option works with the concept of intersecting users of groups.

For all options, the higher permission is always considered.

These rules are only applied when there is more than one group.

05. Define the permission criteria for the user or group in the columns.

List content
When checked, this option determines that the folder or form content will be displayed in document browsing. When this option is not checked, the content can only be accessed from its link, even if the user has read and write permission, as the user will not be able to view the folder or form content. This option is only displayed for folders and forms.

Download and printing
When checked, this option determines that the user can download and print the document or the folder content, as long as the document or folder allows it, i.e., the field Allows download and printing, located on the General information tab – for documents – or in the Inherited properties – for folders – is checked.

All versions
When checked, this option determines that the security level (read, write, modification or total) will be valid for all versions of the folder or document.

Security level
Actions that the user will be allowed to perform on the folder or document. The available options are:
- L: Read. When checked, this option determines that the user can only view the folder or document;
- G: Write. When checked, this option determines that the user can add content inside the folder or to fill out a form; however, the user can't change the properties of the folder or of the form itself. This option is only displayed for folders and forms.
M: Modify. When checked, this option determines that the user can modify the item in question, in addition to the actions allowed under Read and Write. In case of a folder, in addition to being able to view it and write content inside it, the user can also modify its properties. In case of a document, the user can modify its properties and content. However, the user cannot change the security criteria of folders and documents.
T: Total. When checked, this option determines that the user has full permission for the item, i.e., the user can perform all the previously mentioned actions, as well as change the security criteria.

To exclude a user from the permission criteria, click on the bin icon located in the Delete column.

06. After making the necessary changes, click Confirm to save.


Add restrictions


Restrictions are used to override permissions. Therefore, a restriction without permission does not have any effect in the security definition rule. 


01. Go to the Security tab as shown in the Access security configuration item.

02. Click on 2 - Restrictions.

03. Define the restriction criteria.

Collaborator
Define restriction criteria for a specific user.

Group
Define restriction criteria for a user group.

All
Define restriction criteria for all platform users.

04. In Group rules, select the option that determines the rule that will be considered for user groups.

Depending on the option selected, the security treatment for groups will be different. The available options are:

ALL group users: when selected, all group users for whom you have defined restriction criteria will have access to the document/folder. This access is limited to the security level defined for the group and to the result between permission versus constraint. This option works with the concept of union of all groups.

ONLY group common users: when selected, only group common users for whom you have defined restriction criteria will have access to the document/folder. This access is limited to the security level defined for the group and to the result between permission versus constraint. This option works with the concept of intersecting users of groups.

For all options, the higher permission is always considered.

These rules are only applied when there is more than one group.

05. Define the restriction criteria for the user or group in the columns.

List content
When checked, this option determines that the folder or form content will not be displayed in document browsing. This option is only displayed for folders and forms.

Download and printing
When checked, this option determines that the user cannot download nor print the document or the content of the folder.

Security level
Actions that the user will be allowed to perform on the folder or document. The available options are:
- R: Read. When checked, this option determines that the user can not view the folder or document;
- W: Write. When checked, this option determines that the user cannot add content to the folder or modify the characteristics of the folder itself; this permission only allows the user to view the folder. This option is only displayed for folders.
- M: Modify. When checked, it determines that the user cannot modify the item in question, but can perform all the actions mentioned earlier with previous level permissions. That is, in case of a folder, the user can only view it and write content, but cannot modify its properties or its security criteria. In case of a document, the user can only view it, without modifying its properties and content.
- T: Total. When checked, this option determines that the user has full restriction for the item, i.e., the user can perform all the previously mentioned actions – with previous level permissions – except for changing the security criteria for the item.

To exclude a user from the restriction criteria, click on the bin icon located in the Delete column.

06. After making the necessary changes, click Confirm to save.


External sharing


When checked, this option allows sharing internal platform documents externally with people who do not have a platform account. For more information, see External sharing.



Please note!

This documentation is valid as of the Lake (1.7.0) update. If you use a previous update, it may contain information different from what you see on your platform.