- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report
Good day,
To preface, I am not a Vault expert. I just happen to be the most experienced person on our team, therefore a lot of Vault related tasks get delegated to me.
We are trying to create a permissions structure within our Vault that accomplishes a couple of things:
- We want to prohibit the moving of files and folders
- We want to prohibit the renaming of folders (preferable to limit file renaming as well, but not a necessity)
Simply put, this is our fundamental folder structure and desired permissions:
I have very limited experience working with Vault groups and roles. I have been doing some testing this morning:
- I created a test Vault account with a spare license to try out these changes
- I created two new roles, for simplicity's sake we can call these:
- General Access Role - This role is a copy of an existing role that essentially allows full functionality of Vault (read/write files and folders, rename files/folders, move files/folders, etc.)
- Limited Access Role - This role is essentially the same as the General Access role, with the exception that the File Rename, File Move, and Folder Rename permissions have been omitted.
- I created two new groups, for simplicity's sake we can call these:
- General Access Group
- Limited Access Group
- I then set the Object-based security permissions for the "Limited Access File and Folder Structure" to:
- General Access Group - Read = Allow, Modify = Blank, Delete = Blank, Download = Allow
- Limited Access Group - Read = Allow, Modify = Allow, Delete = Blank, Download = Allow
I then tested these permissions out with the test account, and found that I could still rename folders, rename files, and move files/folders.
I am a bit stumped, and feel like I could easily go in the wrong direction, and am looking for some potential aid. It is very possible that without diligent research I could cause more harm than good, and if it is necessary to get a more experienced individual contracted to help, then I can push for that with my superiors.
I appreciate any input!
Solved! Go to Solution.
