{"id":37938,"date":"2023-01-20T12:03:31","date_gmt":"2023-01-20T04:03:31","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=37938"},"modified":"2024-07-05T10:03:48","modified_gmt":"2024-07-05T02:03:48","slug":"how-object-access-works","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/","title":{"rendered":"How Object Access Works"},"content":{"rendered":"\n<p class=\"left-bar\">This article applies to versions 4.9.1 and later of IFS OI Explorer. For more, see <a href=\"#Release_History\">Release History<\/a>.<\/p>\n<p class=\"intro-text\">Objects in IFS OI Explorer are the lowest level of granularity that can be secured.<\/p>\n<p class=\"intro-text\">An object is an individual, identifiable instance of a resource, such as Workspace 1 or Entity A.\u00a0 Object security is performed inside the module itself, rather than in the Security module of Server Management.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-security-works\/\">How Security Works<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/\">workHow Roles Work<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">What Can Be Secured<\/h2>\n<p class=\"intro-text\">Every resource has corresponding objects, however not all objects can be secured individually. Generally speaking, resources that have a View privilege also have objects that can be secured, while those without a View privilege can only be secured at the resource level.<\/p>\n<h3>Server<\/h3>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Objects that can be secured<\/strong><\/td>\n<td><strong>Objects that cannot be secured<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Calculations<\/td>\n<td>Digital States<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Datasources<\/td>\n<td>Images<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Entities<\/td>\n<td>Units<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Hierarchies<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Named List Items<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Links<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Templates<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/securing-a-server-object\/\">Securing Server Objects<\/a><\/p>\n<h3>Explorer<\/h3>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Objects that can be secured<\/strong><\/td>\n<td><strong>Objects that cannot be secured<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Forms<\/td>\n<td>Styles<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Workbooks<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Workspaces<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/securing-an-explorer-object\/\">Securing an Explorer Object<\/a><\/p>\n<h3>Sentinel<\/h3>\n<table>\n<tbody>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\"><strong>Objects that can be secured<\/strong><\/td>\n<td><strong>Objects that cannot be secured<\/strong><\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">Workspaces<\/td>\n<td>Events<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td style=\"padding-left: 5px;\">\u00a0<\/td>\n<td>User Processes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/sentinel-security\/\">Sentinel Security<\/a><\/p>\n<h3>Commentary<\/h3>\n<p class=\"intro-text\">The Commentary module can only be secured at the resource level.<\/p>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/comments-security\/\">Security for Comments<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Object Privileges Matrix<\/h2>\n<p class=\"intro-text\">As with module- and resource-level privileges, object privileges are assigned to roles, rather than individual users.<\/p>\n<p class=\"intro-text\">Object-level privileges can only be changed by a user with Admin privileges for the relevant module (e.g. Server Admin for securing hierarchy objects, or Explorer Admin for securing workspace objects).<\/p>\n<h3>Assigning Object Privileges<\/h3>\n<p class=\"intro-text\">You can assign object privileges by directly clicking the privilege against the object, from within the containing module\/resource. For example, to manage privileges for a workspace, go to workspaces in IFS OI Explorer, and open the workspace for which you want to change the privileges. The available privileges are the same as those available for the resource.<\/p>\n<p class=\"intro-text\">Note that privileges cascade here too, with the highest level privilege generally on the right, and the lowest on the left. When you assign a high level privilege, such as <strong>Delete,<\/strong> lower level privileges are also automatically granted when that privilege is required to perform the action. This is shown by a green circle with a dot.<\/p>\n<p class=\"intro-text\">For object-level privileges, privileges are either granted explicitly or inherited from a resource. If a privilege is not granted via one of these methods, it is denied. Note that the Everyone role shows the actual default View privilege as being granted, whereas Edit and Delete are denied at the object level.\u00a0<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38037\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object.png\" alt=\"\" width=\"583\" height=\"199\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object.png 583w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-150x51.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-24x8.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-36x12.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-48x16.png 48w\" sizes=\"auto, (max-width: 583px) 100vw, 583px\" \/><\/a><\/p>\n<h3>What the Colours Mean<\/h3>\n<p class=\"intro-text\">As with resource-level security, the privileges matrix is colour-coded to indicate the cascading nature of privileges. The colours are:<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-grey.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37926\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-grey.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Grey: Privilege not granted<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37927\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Green tick: Privilege is explicitly granted, associated privileges will also be automatically granted. <br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green-dot.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37931\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-green-dot.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Green dot: Privilege is granted because a higher level privilege has been granted on the resource.<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-blue.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37928\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/sec-blue.png\" alt=\"\" width=\"20\" height=\"20\" \/><\/a>\u00a0Blue: Privilege is granted because it is inherited by a resource privilege.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/locking-down-an-object\/\">Locking Down an Object<\/a><\/p>\n<hr \/>\n<h2>Release History<\/h2>\n<ul class=\"intro-text\">\n<li class=\"overview\">How Object Access Works (this release, 4.9.1):\n<ul class=\"overview\">\n<li>Named List item privileges<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"intro-text\">\n<li><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/how-object-access-works-4-6\/\">How Object Access Works (4.6)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Objects in IFS OI Explorer are the lowest level of granularity that can be secured. This article describes how object security works in IFS OI Explorer 4.9.1 and later.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":37939,"parent":3652,"menu_order":5,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[11],"tags":[639,196],"class_list":["post-37938","page","type-page","status-publish","has-post-thumbnail","hentry","category-tutorial","tag-object-security","tag-security","Version-4-9-1","Product-srv"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=37938"}],"version-history":[{"count":4,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37938\/revisions"}],"predecessor-version":[{"id":67805,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/37938\/revisions\/67805"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/37939"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=37938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=37938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=37938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}