aP Pro Out-of-box Access Control Model¶
When you first install aP Pro, any user in system admin, Digital Factory admin, or the super-user group can open and edit any data, or access and configure any associated tools. It is not that fresh installation does not include an Access Control model for these groups but aP Pro ships with an out-of-box (OOB) Access Control Model that includes a set of permissions that is designed to make it appear as if there is no access control for these groups.
Access control allows admins to grant or deny access and editing rights to tools and features in the System Admin Toolset and Digital Factory Toolset. The OOB Access Control model is updated accordingly so that the default behavior for aPrioriPro is preserved. That is, system admin, Digital Factory admin, or super-user group users have access (OOB) to the tools or features in any associated toolsets.
Note Because the OOB Access Control Model denies absolutely no permissions, it is not a good starting point for implementing a custom Access Control model.
The Root Access Control Model is a better starting point for implementing a custom Access Control Model because it includes a set of permissions that provide a “best practice” Access Control baseline model. At your request, the aPrioriServices team can deploy the Root Access Control Model and add extensions to meet the specific requirements of your organization. For information on the aP Pro Root Access Control Model, see Root Access Control Model for aP Pro .
These OOB permissions and associations are required:
aP.VPEToolset.Open: Grants Digital Factory toolset access to All Users.aP.VPEToolset.Edit: Grants Digital Factory toolset access to Digital Factory Admins.aP.SystemAdmin.OE: Grants System Administrator toolset access to System Admins.aP.SystemAdmin.OE.StrongGrant: Grants System Administrator toolset access to Super UsersaP.VPEToolSet.OE.StrongGrant: Grants Digital Factory toolset access to Super Users