Rights for Roles Security Overview
Setting Up the Software 3-11
■
Predefined user roles, discussed in detail in Section 5.2, Roles.
Each of these predefined roles comes with a default set of permissions and rights, but these can
be modified to suit specific needs. These include the following roles:
– rma
, generally assigned to basic users. It allows them to perform basic management tasks. In this documentation, Records User is a term used to
designate the person given this role.
– rmalocalrecordsofficer
, generally assigned to users who need access to additional functionality for example, creating triggers or folders, and
modifying content attributes. In this documentation, Records Officer is a term used to designate a person given this role. In previous versions of this
product, this was the Records Privileged role.
– rmaadmin
, generally assigned to administrators who set up and maintain the infrastructure and environment. In this documentation, Records
Administrator is a term used to designate the person given this role.
– pcmrequestor
, generally assigned to users who have all the permissions assigned to basic users without a PCM role but are also granted additional
rights to perform some functions not allowed for basic users for example, making reservations for physical items. Users with the pcmrequestor role
have read and write permissions RW for the special RecordsGroup security group. In this documentation, PCM Requestor is a term used to designate a
person given this role.
– pcmadmin
, generally assigned to administrators who are responsible for setting up and maintaining the physical content management infrastructure
and environment. These users have the widest range of rights to perform physical content management tasks for example, setting up the storage space,
editing and deleting reservations, and printing user labels. Users with the PCM Administrator role have read, write, delete, and admin permissions
RWDA for the special RecordsGroup security group. In this documentation, PCM Administrator is a term used to designate a person given this role.
■
Rights control access to functions assigned to user roles. The predefined roles have
a default set of rights assigned to them, but the rights can be modified to restrict or expand their access to functions. For details, see
Section 5.11, Assigning Rights to User Roles.
■
Security groups define security on a group of content. This software comes with a
predefined security group called RecordsGroup. Users with the predefined Records User or Records Officer roles have read and write permission RW to the
RecordsGroup security group. Users with the Records Administrator role have read, write, delete, and admin permission RWDA to this security group. For
details, see
Section 5.6, Security Groups.
■
Access control lists ACLs manage the security model on dispositions ACLs are
an optional feature available during configuration.ACLs can be assigned to folders, triggers, and retention categories. ACLs are used to control user and
group access permissions for triggers, categories, and folders. The ACL can be assigned for each category, folder, and trigger that is created. For details, see
Section 5.8, Access Control Lists ACLs.