Configure Jazz Model ACLs

Modified on 2017/05/16 18:59 by Charles — Categorized as: Jazz, Jazz Administration, Roles


Configure Jazz Model ACLs

This page explains how to use configure and assign predefined Access Rules to a class of Jazz record.

Here is an example of a Task and how Access Rules can be defined for the task when it is created.

Define the Access Rules Task Example

1. Define how all users interact with tasks.
2. Define who gets to edit the task.
Figure 1: Jazz Dynamic Access Rules

These three statements for Access Rules can be achieved in Figure 1.

Define the Access Rules for more Users

Workflows are used by people to manage all kinds of work. Often, users are included in the workflow. e.g. for a Task, there may be a Project Manager, worker and supervisor - all that need to edit the task.

Figure 2: Jazz Dynamic Access Rules - adding other users

Figure 2 shows two additional Access Rules:

Define the Access Rules Using Roles Example

The Task example provides edit access only to the owner of the task. How do you provide additional users edit access?

Figure 3: Jazz Dynamic Access Rules with Roles

From a configuration perspective, the simplest approach is to define a group that has access, e.g. the supervisors who manage the day-to-day operations. Figure 3 shows Roles added to the Access Rules.

Hints about Assigning Access Rules

There are two basic approaches to assigning Access Rules. 1. Restrict access to a Jazz record. 2. Be open and flexible in providing access to a Jazz Record.

Restrict access to a Jazz Record

This approach takes the following course:
This approach may lead to "I cannot see the record" from your users. The solution to this issue may be:
Restrictive Access Rules is the approach taken in the example above:

Open and Flexible access to a Jazz Record

The approach takes the following course:
This approach may lead to allowing users to see information that either they should not see or is a distraction. Today's work environment tends to provide open access to information. In most cases this is the best approach. However, there are some classes of information, e.g. Personnel Records and Pay where restrictive access is warranted.

Access Rules for Properties

In Figure 3, there is a column labelled 'Members'. This refers to properties or fields that are in the Jazz Record. By adding a semi-colon list of properties, the Access Rule now is tailored to just those members.

e.g. Add 'DueDate;AssignedTo' to the 'Supervisor' Role Access Rule.