Manage Security Overrides for Files, Folders, and Custom Objects

You can specify which users have access to files, folders, and custom objects as well as the access level by assigning members to the Access Control List (ACL) for that Vault object. Once any members are assigned to the ACL, any users requiring access to that file, folder, or custom object must be assigned to ACL for that Vault object.

Note: You must be an Administrator to override file, folder, or custom object security.

Whether a Vault object has role-based security (no ACL defined) or object-based security, the security can be overridden. An override of security means that the system ACL still exists on the object but is being overriden by a newly defined ACL. This is an Override Access Control List or an Override ACL. As long as an override ACL exists, the system ACL will be ignored. If the user removes the Override ACL then the system ACL will become the new security.

Both the system ACL and the override ACL can be modified using the same dialog, regardless of whether an override exists on the selected object or not. For example, the user may choose to edit the system ACL while an override ACL already exists. This way the new system ACL is respected if the Override ACL is ever removed.

Create Security Overrides

There are two ways to create a security override. They can be set manually through the security dialog or automatically by using the lifecycle state's security.

Manual Security Override

Follow these steps to manually override the security of a file, folder, or custom object:

  1. Right-click a file, folder, or custom object in the vault and select Details.

    You can also access the Details dialog by selecting Details from the File menu.

  2. Select the Security tab on the Details dialog.
  3. ​Notice the Security Mode field indicates that there is either role-based security or object-based security on the selected Vault object. If the value is object-based security, then an ACL has been defined for selected Vault object.

  4. Select the Security Override check box.
  5. Configure the override access control list using the Add and Remove buttons.
  6. Select OK.
  7. Notice the Security Mode field now says System or overriden security. This indicates that there is an Override ACL configured on the Vault object.

State-Based Security Override

State-based security overrides are configured in the Lifecycle Definitions dialog from the Behaviors tab of the Vault Settings dialog. For more information on how to configure the security of a lifecycle state, see Edit Lifecycle State Security.

To apply state-based security, a state change needs to occur at the folder level. Follow these steps:

  1. Select a folder.
  2. If the folder is not already assigned to a category, choose the Change Category command and assign a category.
  3. By assigning a category, a default state is assigned to the folder.
  4. Select the folder and choose the Change State command.
  5. Choose a state that has security configured on it. For example, the released state has an ACL defined for it out-of-the-box.
  6. Right-click on the folder and select Details.
  7. Select the Security tab.

    The ACL displayed by default is the override ACL that was applied by the lifecycle state.

Edit a Security Override

Once an override ACL has been applied, it can be edited or overriden by another override. For example, assume that a folder has an override ACL that was assigned by a lifecycle state. The user can view the override and modify it by changing the entries in the list and/or modifying the permissions of the access control entries.

  1. Right-click a file, folder, or custom object in the vault and select Details.

    You can also access the Details dialog by selecting Details from the File menu.

  2. Select the Security tab and notice the Security Override check box is enabled.
  3. Make edits to access control list as desired.

Rule: There can never be more than one override ACL on any Vault object and the last override ACL is always used, regardless of whether the override was manually applied or applied by a lifecycle state.

Delete a Security Override

If a file, folder, or custom object has an override, it can be removed to revert back to the system or user ACL.

  1. Right-click a file, folder, or custom object in the vault and select Details.

    You can also access the Details dialog by selecting Details from the File menu.

  2. Select the Security tab on the Details dialog.

    Notice the Security Override check box is selected and the Security Mode indicates that there is an override.

  3. Clear the Security override check box.

The override is removed from the Vault object. At this point, any user ACL that was defined is relevant again. Otherwise, role-based security applies.