We would like to understand whether there is a configuration option available, or alternatively request an enhancement to ARIS permission handling.

Currently, users can see the folder structure and folder names even when they do not have access permissions to the contents of those folders. While access to the objects and models is correctly restricted, the visibility of folder names can still reveal information about other areas of the organisation.

For example, we maintain a Business Units folder containing separate folders for multiple business units. Users are granted access only to their own business unit's folder and its contents. However, they can still see the names of all other business unit folders despite having no access to them.

Our requirement is that users should only be able to see folders for which they have explicit access. Folder names and folder structures outside their permission scope should be completely hidden.

Can anyone advise:

  1. Whether this behaviour can already be configured within ARIS?
  2. If not, whether this could be considered as a future product enhancement?

Thank you.

 or register to reply.

Notify Moderator