Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

Status No Plans to Implement
Workspace Domino
Categories Administration
Created by Guest
Created on Oct 7, 2024

Managing access rights with single option without modifying Database ACL setting.

Can we have a single setting/ option with which we can grant Reader privileges to user account on All Notes database without modifying the ACL settings of the Notes database.

This option should be single point to control Access rights without modifying ACL of the individual Database ACL and it should take precedence over the ACL settings of the individual database.


  • Attach files
  • Guest
    Reply
    |
    Oct 8, 2024

    Hi

    Thank you for reply.

    I don't think the Group access will work for individual user. if individual user account is already available in DB ACL with higher access.

    The requirement is to not to Modify existing ACL settings and granting restricted access.

    This can be implemented to Reader access and not more than that higher access.

    There can be alternative to this requirement.


    1) Instead providing centralize option, is it possible to give a option / Setting in DB ACL which will allow user to restrict access to all users / Group available in DB ACL with restricted access (reader) without changing ACL settings.
    2) Additionally is it is possible to define DB names so this reader access will be applied to respective DB only. Whereas the DB ACL will not be changed.


    The goal is for this requirement is to have a option with which the access can be restricted without changing ACL settings. so it will not be difficult for the Administrator to revert the Changes.

  • Guest
    Reply
    |
    Oct 8, 2024

    Hi

    Thank you for reply.

    I don't think the Group access will work for individual user. if individual user account is already available in DB ACL with higher access.


    The requirement is to not to Modify ACL.

    This can be implemented to Reader access and not more than that.

    Additionally is it is possible to define DB names so this reader access will be applied to respective DB only. Whereas the DB ACL will not be changed.

  • Admin
    Thomas Hampel
    Reply
    |
    Oct 7, 2024
    Rejecting this idea because
    1. you can do this today by adding the same group to all ACLs. Modifying the group members will immediatly grant access to all databases then
    2. we have no plans to weaken the security model of Domino
  • Guest
    Reply
    |
    Oct 7, 2024

    But that's how Notes security works and I, and I suspect many others, wouldn't want this to be implemented. There would come a time when someone creates a DB with confidential information which is inadvertently shared.

    Can you not use a group and add that group to all your databases?