Hi,
We have configured the access security to an ARIS database in the following way.
ARIS Connect: Access rw-
ARIS Architect: no access in some groups.
The display in ARIS Connect is correct, only the groups that have been allowed access are visible and not those that have been restricted with ARIS Architect. The problem appears when searching in ARIS Connect for a model located in an inaccessible group (without permissions), it is presented on the screen.
How is it possible to avoid this problem?
Best regards
M. Zschuckelt on
Hello Isidre,
your description is a bit awkward - maybe resulting from a misunderstanding:
ARIS Connect and ARIS Architect are client products. They have nothing to do with the authorizations to resources a user has received. In fact: The same user should see the same content whether he uses ARIS Connect Portal or ARIS Architect.
Access to content is based on groups (let me call them "folders" for now in order to avoid mixing them with the term "user group") of the database. Each folder knows a set of access permissions. Every user or user group (as defined in the UMC) can be granted permissions such as RW for each single folder. A user that is a member of a user group gets all permissions granted to this user group as well as the permissions granted to him individually. If he is a member of multiple user groups, his permissions add up from all those.
So in the Connect Portal Search the user will see results from all groups where he has at least a read permission - either individually or through at least one of the user groups he is a member of.
If you have a user, who has the "system" privilege on the database or who has the function privilege "Database administrator" on the ARIS tenant, he can see the entire content of the database - no matter which privileges were assigned to him individually or via user groups.
I hope this clarifies things a little bit. It always boils down to the question of which privileges the individual user has for a particular database folder where the object in question (object or model) resides.
Regards,
M. Zschuckelt