Migrating or importing ACM from a pre-2019 R2 Release¶
If you are migrating or exporting an access control model (ACM) from a release that is earlier than 2019 R2 to the current release, you must manually add the required OOB permissions for the current release. For example, to create and associate required OOB permissions for the current release, as indicated in the table:
| Required Permission Name | Resource | Actions | Actions | Grant | Deny | Deny | Associated Group |
|---|---|---|---|---|---|---|---|
| aP.VPEToolset.Open | Digital FactoryToolset | - Use - Open - Always |
Normal | Normal | All Users | ||
| aP.VPEToolset.Edit | Digital FactoryToolset | - Use - Edit - Always |
Normal | Normal | Digital FactoryAdmins | ||
| aP.SystemAdmin.OE | System Admin | - Use - Open - Edit - Always |
Normal | Normal | System Admins | ||
| aP.SystemAdmin.OE. StrongGrant |
System Admin | - Use - Open - Edit - Always |
Strong | Normal | Super Users | ||
| aP.VPEToolSet.OE. StrongGrant |
Digital FactoryToolset | - Use - Open - Edit - Always |
Strong | Normal | Super Users |
- Log in as a super user
- Open the Permissions tab. From the aP Pro menu bar, click Tools > System Admin Toolset > System Administrator > Permissions.
-
Create the required permissions. For each permission:
-
In the Permissions tab, create and configure the new permission:
-
In the Input tab, for Permission Name enter the permission name, as indicated by the second column of the table, and then click OK.
-
In the Permissions tab, for:
-
Description: Reenter the name of the permission. For example, for the
aP.VPEToolset.Openpermission, enteraP.VPEToolset.Openfor the description. -
Resource: From the drop-down menu, select the value indicated by the Resource column of the table.
-
Action: Select the actions indicated by the Action column of the table. Then, for:
-
Subject: SelectCONSTANT.
-
Property: Select true.
-
For every one of these required permissions, the generated rule is true.
-
Grant: Select the value that by indicated in the Grant column in the table.
-
Deny: Select the value that is indicated by the Deny column in the table.
-
-
-
Associate the new permissions to the appropriate groups, as indicated by the name of the group in the last column of the table.
-
In the Groups tab, in the groups list, select group directory for the group that you want to associate with a permission
-
In Associated Permissions, select the Add Permissions to Group,
, button. -
In the Search Permissions window, for Name, enter the name of the permission that you want to associate to the group and then click Find.
-
In the Available Permissions list, select the name of the permission that you want to associate to the group and then click OK.
-
Root Access Control Model for aP Pro¶
The Root Access Control Model includes a set of permissions that provide a “best practices” baseline configuration for implementing a custom Access Control Model. At your request, the aPriori Services team can deploy the Root Access Control Model and add extensions to meet the specific requirements of your organization.
