cancel
Showing results for 
Search instead for 
Did you mean: 

Organising authorisation

rosemeyer2
Champ in-the-making
Champ in-the-making
Hi,

I wonder about configuring the authorisation. The default installation puts "read" right to everyone, which is inherited by every folder beneath. Let's say I have group 1 and group 2 in a company. So I would create a folder "company" and beneath the folders "group1" and "group2". I want the group 1 just to see "group1" folder, group 2 should see "group2", as everybody inherits "read" for all, everybody can see everything.

How would you set this up?

Regards,
Rudolf
5 REPLIES 5

invictus9
Champ in-the-making
Champ in-the-making
I would trim the inherited permissions after I created the space. When you select Manage Space Users, there is a flag, Inherit Space Permissions. Turn this off, and then invite the particular group you want to give access to.

rosemeyer2
Champ in-the-making
Champ in-the-making
So is it a kind of default approach to remove "read" right for all from the root folder or is it recommended to leave it as it is and adjust inheritation for the subfolders?

invictus9
Champ in-the-making
Champ in-the-making
So is it a kind of default approach to remove "read" right for all from the root folder or is it recommended to leave it as it is and adjust inheritation for the subfolders?

I think that is up to you, since it depends so much on the general approach to security in your organization and the kinds of documents you want to share.

My organization:

/Files
  • Department 1
    • General Services

    • Group 1

    • Group 2

  • Department 2

  • Department 3

This allows people in the company to browse into Department 1, when they actually need to interact with Department 1, they will enter General Services, where are located various forms, work flows and other things that involve interaction between the person and Department 1.

Pruning of inherited viewing starts with Group 1, so nobody who hasn't been given permission can see into Group 1.

However, it is early days yet, and the proposed structure has not been vetted by our security officer or IT audit people.

rosemeyer2
Champ in-the-making
Champ in-the-making
So, you removed the "read" on root and started inheritance on department1 (so department1 does not inherit?)

I think it's a bit confusing for the users, when they see all the alfresco folders like dictionary and between them the organisational folders like department1 or do you have a folder "company" above that?

Thanks

invictus9
Champ in-the-making
Champ in-the-making
So, you removed the "read" on root and started inheritance on department1 (so department1 does not inherit?)

I think it's a bit confusing for the users, when they see all the alfresco folders like dictionary and between them the organisational folders like department1 or do you have a folder "company" above that?

Thanks

No, I actually started pruning inside the department spaces. General Services for Department1 might be different than General Services in another department.