User Management: Defining and Managing the Authorization System

Planning the authorization policy is one of the first things to do when setting up your system. This and the following topics describe the objects involved in it and provide examples of how to do it.

Building up an efficient and secure authorization system comprises the objects and definitions listed below. It is not mandatory to use all of them, though. In accordance to the size, structure and policy of your company, you may opt for a simple authorization system (authorizations and privileges granted at User level; this is only feasible for very small systems with a small number of users with also few roles), for complexer systems (User Groups depicting roles in the company, User Catalogs to facilitate their access to functions, etc.) or for highly complex landscapes in which additional authorizations are defined at object level.

See also: