User Guide
270 Chapter 19: Working with Users and Groups
3.
If the user acquires View, Publish, or Manage permissions through user-specific permissions,
these are additive to the corresponding group-acquired permissions. In addition, these override
any group-acquired Denied permission.
4.
If the user is specifically assigned the Denied permission setting through user-specific
permissions, the user is denied access regardless of any group-acquired permissions.
5.
If the user is a member of the Administrator group, the administrator permission applies,
regardless of any other individual or group setting.
6.
If there are no permissions applied by either user or group (and none is inherited from a parent
folder), the user cannot access or perform any actions on the folder or file.
The following table illustrates the way that group and user permissions apply:
Here are some facts to keep in mind about permission precedence:
Setting user permissions Keep in mind that user-specific permissions are additive to the
corresponding group-acquired permissions and override any group-acquired Denied permissions.
Individual Denied permissions also override any group-acquired permissions.
User permissions take precedence over all group-acquired permissions. For example, to ensure
that a specific user gets Manage permission for a content presentation, you can set the Manage
permission for that specific user. This permission always applies, regardless of any other group
permissions that are set.
Setting group permissions Use group permissions to set rules for groups of users.
Ensuring that access is denied To ensure that access is denied, the Denied permission must be
set for the specific user. This permission overrides any group-acquired permissions.
Ensuring access To ensure that a specific user is given at least Publish permission for a given
content presentation, you must set their user-specific permission to Publish. Any group-acquired
permissions are only additive; they cannot deny access.
Group G1
permissions
Group G2
permissions
Union (G1, G2)
permissions
User permissions Resulting
permissions
View Publish Publish Manage Publish+Manage
Manage None Manage Publish Publish+Manage
Denied Publish Denied Manage Manage
View Manage Manage View Manage
Manage None Manage Denied Denied
None None None None None