0 Helpful

Understanding automatic permission rules (auto-inherit)

Administrator
Σχετικές Εφαρμογές

What are auto-inherit rules?

An auto-inherit rule is a system-level configuration that automatically grants a permission to users who meet a defined condition — for example, "all members of group STRUCTURED_USERS receive the intranet permission".

These rules are evaluated periodically by the system. When a user gains or loses the qualifying condition (e.g., they join or leave a group), their permission is added or revoked automatically without any administrator action.

How to identify auto rules in Manage Permissions

On a permission's detail page, the description header shows an Automatic Access Rules block listing all active rules for that permission. Each rule appears as a colored badge:

  • Structured Staff — all members of the structured staff group
  • Heads of Unit — all area managers and department leaders
  • …and other organization-specific rules

If a badge shows a warning icon, it means some users who qualify for the rule have been given a manual override (different value). Click the icon tooltip to see who.

Auto vs Manual in the active authorizations table

In the Active Authorizations table, rows for auto-rule members are highlighted with a colored background. Their source column shows an auto badge. You cannot disable or edit these rows directly — access is controlled by the rule condition itself.

Manual override of an auto permission

If a user meets an auto rule but you need to give them a different value (e.g., a higher access level), you can issue a Manual Grant on top of the auto rule:

  1. Click New Authorization and select the user.
  2. Set the override value.
  3. The active table will show both the auto row and your manual row, with a warning indicating the manual override takes precedence.
Note: If the user later loses the auto-rule condition (e.g., leaves the group), the manual override remains active. You will need to revoke it manually if access should be removed entirely.

Losing auto access (revocation)

When a user no longer meets an auto-rule condition, the system logs a lost event in the auto-log and the permission is removed from their active grants automatically. The Inactive tab will show a auto-revoked row for auditing. You can restore the permission manually if needed by clicking the restore button.


Βρήκατε αυτό το άρθρο χρήσιμο;
Το 0 από το 0 το βρήκε χρήσιμο

divider

Σχετικά Άρθρα

ευγενική χορηγία
arrow-up icon
ESC