Understanding Managing Definition Group Security

There are three mechanisms for securing definition types and definition groups: secure by default, component row-level security, and permission lists.

Term Definition

Secure by Default (Definition Type)

When you enable “secure by default” for a definition type, definitions of the type are only accessible by the OPRID that last updated it (creator), or if it is associated with the primary permission list to which the OPRID belongs.

Note: When you enable secure by default for a definition type you must explicitly grant permission list access to users.

Use the Definition Types page described later in the topic to enable Secure by Default for definition types.

Component Row-Level Security (Definition Type)

Associate component row-level security with definition types to limit access to data.

You can specify dynamic views for a record for a definition type to control access.

Use the Definition Types page described later in the topic to specify dynamic views for definition types.

Permission Lists (Definition Group)

You can assign permission list access to definition groups, providing users assigned to a permission list full or read-only access to a definition group.

Use the Group Users page described later in this topic to view the permission lists and their associated users with access to a definition group.

Use the Group Permission page described later in this topic to define this access.