Aras Innovator Platform

Configuring Permissions

This section describes the out-of-the-box Permissions used in the Product Engineering (PE) application. Item Permissions define the Access Rights that Identities have for performing actions on an Item.

From the Permissions accordion tab on an ItemType form, you can define permissions for the ItemType. The Is Default check box indicates that a particular Permission is the default upon item’s creation.

Items may be associated with Life Cycle Maps. The Life Cycle Maps can change the Item Permissions at a particular Life Cycle state.

From the Can Add accordion tab on an ItemType form, you can configure the create Permissions.

The following table describes the out-of-the-box Permissions for the Part, Document, and CAD Document ItemTypes. The Life Cycle State column lists the life cycle states. The Add, Get, Update, Delete, and Change access columns list the associated Identities which are allowed those Permissions for each Life Cycle State.

The Promoted by column shows the Identities that can promote an Item to a given Life Cycle State. If this column shows Aras PLM, an internal system process promotes the Item automatically.

The Defining Permissions column refers to Permissions that manage Access Rights for a particular Life Cycle State.

Design permissions matrix

Life Cycle State

Add

Get

Update

Delete

Change access

Promoted by

Defining Permissions

Preliminary All Employees, World—Documents All Employees Manager, Owner, Creator, Aras PLM Owner, Creator, Aras PLM Owner, Creator, Aras PLM Starting State New Part New Document New CAD
In Review All Employees Aras PLM Aras PLM Aras PLM Aras PLM In Review Part In Review Document In Review CAD
Released All Employees Aras PLM Aras PLM Aras PLM Aras PLM, Owner Released Part Released Document Released CAD
In Change All Employees Aras PLM Aras PLM Aras PLM Aras PLM Released Part Released Document Released CAD
Manual Change All Employees Aras PLM Aras PLM Aras PLM Aras PLM Aras PLM Full
Obsolete All Employees Aras PLM Aras PLM Aras PLM Aras PLM Released Part Released Document Released CAD
Superseded All Employees Aras PLM Aras PLM Aras PLM Aras PLM Released Part Released Document Released CAD

Each of the Change Management ItemTypes has its own Permissions. Refer to the corresponding subsections of the Change Management section in the Aras Product Engineering 14 - User Guide for detailed descriptions of the Change Processes and Permissions.

There are two levels of access control for Effectivity. The Effectivity Management Permission defines the standard Access Rights to Effectivity. The effs_releasedPartPolicy Mandatory Access Control (MAC) Policy provides additional restrictions in addition to the Effectivity Management Permission.

Effectivity Management Permission

The Effectivity Management Permission provides Access Rights to Effectivity in Bill of Material (BOM) structures, Effectivity Scopes, Effectivity Variables, and [Effectivity] Models. The out-of-the-box Permission definition has the following Identities:

  • Effectivity Management can view, create, update, and delete Effectivity in BOM structures as well as Items of the Effectivity Scope, Effectivity Variable, and Model ItemTypes. This Identity can resolve BOM structures by Effectivity Criteria.
  • World can view Effectivity on BOM structures and resolve BOM structures using Effectivity Criteria.

MAC Policy to Control Effectivity Changes on Released Part BOMs

Out of the box, the Effectivity Management Identity can change Effectivity on BOM structures whose parent Parts are released. If necessary, changing Effectivity on released BOMs can be prevented by activating the effs_releasedPartPolicy Mandatory Access Control (MAC) Policy.

Refer to Aras Innovator - MAC Policies for information about activating and deactivating MAC policies.

Each of the Manufacturer, Manufacturer Part, and Vendor ItemTypes has the same-name default Permission. All these Permissions have the same Access Rights definition. The Manufacturer and Vendor Life Cycle Maps do not override these Permissions.