Help > Setting up XBOUND > Privileges and rights > Setting up role-based privileges

Setting up role-based privileges

Normally an XBOUND system should be protected from unauthorized use. This is done using roles, privileges, and rights.

This topic describes how to use the Security Wizard to assign roles to your users and then assign privileges to those roles.

Warning: If you use the Security Wizard after already setting up and adjusting privileges, the existing settings will be overwritten.

An alternative to using the wizard is to assign privileges manually.

Tip: You can also add your own privilege definitions that can be queried by custom applications, and transfer them between XBOUND systems by exporting and importing them.

The wizard starts automatically after you click OK in the Initialize XBOUND Platform dialog.

You can also start the Security Wizard as follows:

  1. Using the XBOUND Management Center, open a console containing the Security Manager.

  2. In the Console pane, expand Security Manager and then select Privilege Manager.

    (If the Console pane is not visible on the left, select View > Console view.)

  3. Click the Security Wizard button ().

When the Security Wizard starts

  1. Click Next in the initial dialog.

  2. In the next dialog, the predefined roles are listed in the left column.

    For each role, click in the Edit column. In the Windows dialog that is displayed, select at least one user and/or user group and click OK.

  3. Click Next.

  4. Click Next to use the default privilege assignments.

    Alternatively, select Set privileges manually and click Next to Closedadjust the privilege assignments:

    The Role Configuration dialog is displayed.

    Each cell contains one of the following symbols. Click the symbols to toggle them.

     – privilege granted to the role

     – privilege denied

    – not specified

    Note: Privileges are organized in a hierarchy. For example, Move Documents to Other Process Steps is under System Management. In order for users to be able to move documents to other process steps, they must have both privileges.

    Important: Privileges granted take precedence over privileges denied. If a user is assigned to two or more roles, and a privilege is granted to one of those roles but denied to the other(s), then the user is still granted that privilege. This is in contrast to permission handling in Windows.

    The same is true when user groups are assigned to two or more roles.

    Ensure that the Administrator role is not locked out and that each privilege that is mapped to one role is mapped to all of the roles.

  5. Click Finish.

Adding or changing a privilege definition

Assigning rights

Security in XBOUND: Overview

Setting up XBOUND: Overview