Security Model
You use the security model in Stack9 to protect the data integrity and privacy in a organization. The security model also promotes efficient data access and collaboration. The goals of the model are as follows:
- Grant users access that allows only the levels of information required to do their jobs.
- Categorize users and teams by security role and restrict access based on those roles.
- Prevent access to objects a user does not own or share.
You combine business units, role-based security, and record-based security to define the overall access to information that users have in your organization.
Security Roles
Security roles in Stack9 are a matrix of privileges and access levels for the various entities.
Privileges
Privileges are the basic security units that delineate what action a user can perform in the Stack9 system. These cannot be added or deleted but only modified. The common privileges in Stack9 for each entity are as follows:
- Create — Allows the user to add a new record
- Read — Allows the user to view a record
- Write — Allows the user to edit a record
- Delete — Allows the user to delete a record
- Comment - Allow the user to write a comment to the record
- Attach - Allows the user to attach files to a record
- Export - Allows the user to export list of records from a grid
- Workflow Step — Allows the user to edit a record when on a specific workflow step (not implemented)