Granting security access to WCM features

To grant access to major features

■    Full users who are members of at least one CAG can access Site Designer; the Content Designer tool; and the Tagging and Reports features in Content Management.

■    Full users who are members of at least one Master Admin CAG can access the Maintenance features in Content Management.

■    Even SysAdmin users must belong to at least one CAG, with the appropriate CAG permissions, to participate in web content authoring workflow.

Note: To access Surf-to-Edit, users must be logged on and must be a member of at least one content authority group (CAG).

To grant access to the maintenance features of WCM

Only members of the SysAdmin role and members of a MasterAdmin CAG can use the maintenance features of WCM (Content Management > Maintenance).

To grant access to content record commands

A Full user needs both the listed CAG permissions and Document System permissions to enable use of the listed Document System toolbar commands when working with content records.

Note: Casual and Public users can also work with content records through Surf-to-Edit, but their access is very limited compared to Full users. At the least, they must be a member of a CAG, which grants them the ability to request changes for a content record when in Surf-to-Edit mode. They can edit a content record when in Surf-to-Edit mode only if they have been granted Content Editor permissions in at least one CAG and they have been granted Edit Document System permissions on the content record that they want to edit.

Toolbar command

CAG permissions

Document System permissions

Organize > Refresh

none

none

Organize > Cut

Content Approver

Edit AND Delete

Organize > Copy

Content Editor

none

Organize > Paste

Content Editor

Add (on parent content folder)

Organize > Select All

none

none

Organize > Delete (request only)

Content Editor and NOT Content Approver

Edit

Organize > Delete

Content Approver

Delete

Organize > Properties

none

none

Organize > Empty the Recycle Bin

Content Approver

Delete

New > Website Content

Content Editor

Add (on parent content folder)

New > Website Content Folder

Folder Creator

Add

Edit

Content Editor

Edit

Import

Content Editor

Add (on parent content folder)

Export

member of a CAG

none

Versions

Content Editor

Edit

Run

none

none

Submit

Content Editor and NOT Content Approver

Edit

Publish

Content Approver

none

Preview

none

Read

Search

none

none

To grant access to content layout commands

A Full user needs both the listed CAG permissions and Document System permissions to enable use of the listed Document System toolbar commands when working with content layouts. Casual and Public users cannot work with content layouts.

Note: The Add Document System permissions listed in the following table must be set on the parent folder for content layouts. All other listed Document System permissions must be set on the objects within that parent folder by setting the same permissions on the parent folder and selecting the Apply changes to all descendants checkbox. (The easy way around all this is to ensure that the people working with content layouts are all members of the SysAdmin role.) The ContentLayouts parent folder must be accessed through the Document System, then drill into ContentManagement > DefaultSystem.

Note: Access the Recycle Bin through the Document System.

Toolbar command

CAG permissions

Document System permissions

Organize > Refresh

none

none

Organize > Cut

Layout Editor

Edit AND Delete (on parent folder)

Organize > Copy

Layout Editor

none

Organize > Paste

Layout Editor

Add (on parent folder)

Organize > Select All

none

none

Organize > Delete

Layout Editor

Delete (on parent folder)

Organize > Properties

none

none

Organize > Empty the Recycle Bin

Layout Editor

Delete (on parent folder)

New > Content Layout Definition

Layout Editor

Add (on parent folder)

Edit

Layout Editor

Edit (on parent folder)

Import

Layout Editor

Add (on parent folder)

Export

member of a CAG

none

Versions

Layout Editor

Add (on parent folder)

Search

none

none

To grant access to content type commands

A Full user must be either a member of the SysAdmin role or a member of at least one Master Admin CAG to enable use of the listed Document System toolbar commands when working with content types. Casual and Public users cannot work with content types.

Note: The parent folder for content types must be accessed through the Document System, then drill into ContentManagement > DefaultSystem.

Note: Access the Recycle Bin through the Document System.

To grant access to sitemap (navigation item) commands

A Full user needs both the listed CAG permissions and Document System permissions to enable use of the listed Document System toolbar commands when working with navigation items. Casual and Public users cannot work with navigation items.

Toolbar command

CAG permissions

Document System permissions

Organize > Refresh

none

none

Organize > Cut

Navigation Creator

Edit AND Delete

Organize > Copy

Navigation Creator

none

Organize > Paste

Navigation Creator

Add (on parent navigation item)

Organize > Delete

Navigation Creator

Delete

Organize > Properties

none

none

Organize > Empty the Recycle Bin

none

Delete

New > Website Navigation Item

Navigation Creator

Add (on parent navigation item)

Edit

Navigation Creator OR Navigation Editor

Edit

Import

Navigation Creator

Add

Export

member of a CAG

none

Versions

Navigation Creator or Navigation Editor

Edit

Run

none

Read

Publish

Navigation Creator or Navigation Editor

none

Preview

none

Read

Search

none

none

To grant access to tagged list format commands

A Full user needs both the listed CAG permissions and Document System permissions to enable use of the listed Document System toolbar commands when working with tagged list formats. Casual and Public users cannot work with tagged list formats.

Note: The Add Document System permissions listed in the following table must be set on the parent folder for tagged list formats. All other listed Document System permissions must be set on the objects within that parent folder by setting the same permissions on the parent folder and selecting the Apply changes to all descendants checkbox. (The easy way around all this is to ensure that the people working with tagged list formats are all members of the SysAdmin role.) The TaggedListFormats parent folder must be accessed through the Document System, then drill into ContentManagement > DefaultSystem.

Note: Access the Recycle Bin through the Document System.

Toolbar command

CAG permissions

Document System permissions

Organize > Refresh

none

none

Organize > Cut

none

Edit AND Delete

Organize > Copy

none

Read

Organize > Paste

none

Add (on parent folder)

Organize > Select All

none

none

Organize > Delete

none

Delete

Organize > Properties

none

none

Organize > Empty the Recycle Bin

none

Delete

New > Tagged List Format

none

Add (on parent folder)

Edit

none

Edit

Import

none

Add (on parent folder)

Export

none

Read

Preview

none

Read

Publish

none

Edit

Search

none

none

To grant access to site commands

A Full user needs both the listed CAG permissions and Document System permissions to enable use of the listed Document System toolbar commands when working with iMIS sites.

Note: You can grant Casual and Public users permissions to work with content records, but they can access content records through Surf-to-Edit only.

Toolbar command

CAG permissions

Document System permissions

Organize > Refresh

none

none

Organize > Cut

none

Edit AND Delete

Organize > Copy

none

Read

Organize > Paste

none

Add (on parent folder)

Organize > Delete

none

Delete

Organize > Properties

none

none

Organize > Empty the Recycle Bin

none

Delete

New > Folder

none

Add (on parent folder)

New > Website

none

Add (on parent folder)

Edit

none

Edit

Import

none

Add (on parent folder)

Export

none

Read

Versions

none

Edit

Run

none

Read

Publish

none

Edit

Preview

none

Read

Search

none

none

Troubleshooting

■    You must be a member of the SysAdmin role, and you must have authorization level 1 or greater in Sys Mgmt.

■    Remember: You can grant Casual and Public users permissions to work with content records, but they can access content records through Surf-to-Edit only.

Note: Membership in the SysAdmin security role effectively grants the full set of Document System permissions and the full set of CAG permissions (you are effectively a member of a MasterAdmin CAG too). However, to participate in web content authoring workflow, even members of the SysAdmin role must be an explicitly-listed member of at least one CAG.