User manual

Table Of Contents
Chapter 6 | Protecting databases 142
1 If you need to share a database file with others and provide varying levels of file access to
different users, you need to plan the security for the file. Consider listing the types of users and
their privileges:
* You can provide limited access to some features, for example deleting records, by using record-
by-record privileges. For more information on record-by-record privileges, see Help.
You can additionally protect a file by requiring authorization of any file that attempts to access its
tables, layouts, value lists, and scripts. For more information, see
“Authorizing access to files” on
page 148.
To plan the security for a shared file:
1. Determine the privilege sets that you need for the file.
Make a list of the areas of the file that you want to protect, such as particular tables, fields,
records, layouts, value lists, and scripts. Plan the number of privilege sets you need to enforce
the varying levels of file access that you require.
2. Determine whether you need individual accounts for each user, or group accounts that multiple
users can share.
3. Decide if you want to enable the Guest account, which permits users to open the file without
specifying account information.
4. Create the privilege sets that you need in the file.
5. Determine if you need to enable any extended privileges for certain privilege sets.
Don’t enable extended privileges unless they’re needed.
6. Create the accounts you need in the file, and assign the appropriate privilege set to each account.
For more information, see the next section. If you’re using the Guest account, assign a privilege
set to it as well. Otherwise, disable the Guest account.
7. Open the file using different accounts and test each privilege set that you created. Make sure
the restrictions work the way you want, and make any needed corrections to your privilege sets.
8. Optionally limit other files from accessing the schema of your file by using the File Access tab.
For more information, see
“Authorizing access to files” on page 148.
Managers Marketing Sales HR Legal Guests
View records
Yes Yes Yes Yes Yes Yes
Create records
Yes Yes Yes Yes No No
Edit records
Yes Yes Yes Yes No No
Delete records
Yes Limited* Limited* Yes No No
Modify scripts
Yes Limited* No Yes No No
Execute scripts
Yes Yes Yes Yes Yes No
Modify value lists
YesNoNoNoNoNo
Menus
All Editing only Editing only All Minimum Minimum