User manual

Table Of Contents
Chapter 6 | Protecting files 115
1 If you need to share a database file with others and provide varying levels of file access to
different users, you need to plan the security for the file. Consider listing the types of users and
their privileges:
* You can provide limited access to some features, for example deleting records, by using record-
by-record privileges.
You can additionally protect a file by requiring authorization of any file that attempts to access its
tables, layouts, value lists, and scripts. See
“Authorizing access to files” on page 120.
To plan the security for a shared file:
1. Determine the privilege sets that you need for the file.
Make a list of the areas of the file to protect, such as particular tables, fields, records, layouts,
value lists, and scripts. Plan the number of privilege sets you need to enforce the varying levels
of file access that you require.
2. Determine whether you need individual accounts for each user, or group accounts that multiple
users can share.
3. Decide if you want to enable the Guest account, which permits users to open the file without
specifying account information.
4. Create the privilege sets that you need in the file.
5. Determine if you need to enable any extended privileges for specific privilege sets.
Don’t enable extended privileges unless they’re needed.
6. Create the accounts you need in the file, and assign the appropriate privilege set to each account.
For information, see the next section. If you’re using the Guest account, assign a privilege set
to it. Otherwise, disable the Guest account.
7. Open the file using different accounts and test each privilege set that you created. Make sure
the restrictions work the way you want, and make any needed corrections to your privilege sets.
8. Optionally, limit other files from accessing the solution’s schema. For more information, see
“Authorizing access to files” on page 120.
Managers Marketing Sales HR Legal Guests
View records
Yes Yes Yes Yes Yes Yes
Create records
Yes Yes Yes Yes No No
Edit records
Yes Yes Yes Yes No No
Delete records
Yes Limited* Limited* Yes No No
Modify scripts
Yes Limited* No Yes No No
Execute scripts
Yes Yes Yes Yes Yes No
Modify value lists
Yes No No No No No
Menus
All Editing only Editing only All Minimum Minimum