> For the complete documentation index, see [llms.txt](https://interfacing.gitbook.io/interfacing-help-files/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://interfacing.gitbook.io/interfacing-help-files/administration-and-configuration/system-administrators/permission-and-security-management.md).

# Permission & Security Management

Learn how to manage access, protect content, and apply security settings to keep your system secure and in control.

Security in the New Experience provides flexible, role-based control over who can access, edit, or manage content. Whether you're assigning permissions to individual users, groups, or objects, this guide explains the key concepts and tools available to help you keep your environment secure.

***

## What Are the Security Levels?

Security consists of three components: **Licenses**, **Authorizations**, and **Permissions**.

<table><thead><tr><th width="170.5">Components</th><th>Options</th></tr></thead><tbody><tr><td><strong>Licenses</strong></td><td><ul><li><strong>System Admins</strong><br>Full access and control across the system.</li><li><strong>Environment Admin</strong><br>Full access and control within a single environment.</li><li><strong>Access to </strong><mark style="color:blue;"><strong>Latest</strong></mark> <strong>database</strong><br>Full access to all object versions. Intended for document control specialists, process analysts, and other content managers.</li><li><strong>Access to </strong><mark style="color:blue;"><strong>Published</strong></mark> <strong>database</strong><br>View-only access to published versions. Intended for general end-users.</li></ul></td></tr><tr><td><strong>Authorizations</strong></td><td><ul><li><strong>Publish</strong><br>Available only to users with <strong>Access to Latest Database</strong>.</li><li><strong>Merge</strong><br>Requires <strong>Delete</strong> permission and <strong>Access to Latest Database</strong> license.</li><li><strong>Import</strong><br>Available only to <strong>Environment Admins</strong>.</li><li><strong>Export</strong><br>Available only to <strong>Environment Admins</strong>.</li><li><strong>Download</strong></li><li><strong>Print</strong><br>Requires <strong>Download</strong> authorization.</li></ul></td></tr><tr><td><strong>Permissions</strong></td><td><ul><li><strong>Read Published</strong><br>View published versions only (no editing or drafts).</li><li><strong>Read Latest</strong><br>View all versions (no editing or deleting).</li><li><strong>Write</strong><br>View and edit all versions (no deleting).</li><li><strong>Delete</strong><br>View, edit, delete, and manage object security.</li></ul></td></tr></tbody></table>

***

## Who Can Manage Security?

**Security** management is available to **Admins** and certain **users with access to the Latest database**, depending on their permissions.

| Role                                                                                                                                                                                               | Security Management Scope                                  |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| **System Admin**                                                                                                                                                                                   | Manages security for environments *and* objects.           |
| **Environment Admin**                                                                                                                                                                              | Manages security for objects within their environment.     |
| **Users with&#x20;**<mark style="color:blue;">**Access to Latest**</mark> <mark style="color:blue;">**Database**</mark>**&#x20;+&#x20;**<mark style="color:blue;">**Delete**</mark> **Permission** | Manages security for objects they are permitted to delete, |

***

## How to Manage Security

In **Phase 1**, security management is not yet available in the platform. All security actions must be performed in EPC.&#x20;

For instructions on managing security in EPC, refer to the following topics:

* [Managing Environment Permissions & Admin License](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-3-6-1-managing-user-group-security-per-environment)
* [Managing Security on Individual Objects](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-3-6-2-managing-security-on-individual-objects)
* [Permission & Security Management (overview of rules, concepts, and how it works)](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-5-6-security)

***

## How to Manage Licenses & Authorizations

In **Phase 1**, license and authorization management must also be completed in EPC.

For instructions, refer to the following topics:

* [Assign Licenses and Authorizations to Users and Groups](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-3-6-3-managing-user-licenses-system-environment-admin)
* [Managing Environment Permissions & Admin License (Environment Admin License)](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-3-6-1-managing-user-group-security-per-environment)
* [Permission & Security Management (overview of rules, concepts, and how it works)](https://www.manula.com/manuals/interfacing-technologies/epc10-webapp/15.4/en/topic/12-1-5-6-security)

***

## Rules of Security

### What Happens When...

| Action                                            | Result                                                                                                      |
| ------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| You have different permissions via group and user | You receive the **highest** permission (e.g., group has **Delete**, user has **Read** → you get **Delete**) |
| An object is **moved**                            | It **retains** its current permissions.                                                                     |
| A new object is **created**                       | It **inherits** permissions from its parent.                                                                |
| An object is **merged**                           | It receives the **permissions of the destination** object.                                                  |
| An object is **copied**                           | It inherits permissions from the new parent.                                                                |

### How Do I Grant a User...

<table><thead><tr><th width="187">Type of Access</th><th>License </th><th>Permission</th><th>Authorization</th></tr></thead><tbody><tr><td><strong>Publish</strong></td><td>Access to Latest DB</td><td>Write or Delete</td><td>Publish</td></tr><tr><td><strong>Merge</strong></td><td>Access to Latest DB</td><td>Delete</td><td>Merge</td></tr><tr><td><strong>Import</strong></td><td>Environment Admin</td><td>—</td><td>Import</td></tr><tr><td><strong>Export</strong></td><td>Environment Admin</td><td>—</td><td>Export</td></tr><tr><td><strong>Read-Only</strong></td><td>Access to Published DB</td><td>Read Published</td><td>—</td></tr><tr><td><strong>Latest</strong></td><td>Access to Latest DB</td><td>Read Latest</td><td>—</td></tr><tr><td><strong>Write</strong></td><td>Access to Latest DB</td><td>Write</td><td>—</td></tr><tr><td><strong>Delete</strong></td><td>Access to Latest DB</td><td>Delete</td><td>—</td></tr></tbody></table>

***

## Understanding Download & Print Authorizations

The rules for **Download** and **Print** authorizations apply **only when** the `DOCUMENT_CONTROL_COPIES` [system setting](/interfacing-help-files/administration-and-configuration/system-administrators/advanced-system-settings.md) is enabled.&#x20;

With this setting turned on, you can control whether users can download original files, access previews, or print documents based on their assigned permissions.

<details>

<summary><strong>Office (.docx, .xlsx, etc.) &#x26; PDF files</strong></summary>

* To **print**, users must also be allowed to **download**.
* If a user is **allowed to download but not print**, the system provides a **non-printable PDF preview**.

**Here's a table to better show these rules:**

| Download Auth. | Print Auth. | Can download?     | Can Print? | File Preview    |
| -------------- | ----------- | ----------------- | ---------- | --------------- |
| ✅              | ✅           | ✅ Original file   | ✅          | Unprintable PDF |
| ✅              | ❌           | ✅ Unprintable PDF | ❌          | Unprintable PDF |
| ❌              | ✅           | ❌                 | ❌          | Unprintable PDF |
| ❌              | ❌           | ❌                 | ❌          | Unprintable PDF |

{% hint style="info" %}
Admins always have full access and cannot be denied **Download** or **Print** authorizations.
{% endhint %}

</details>

<details>

<summary><strong>Other files (Images, ZIPs, etc.)</strong></summary>

* To **print**, users must also be allowed to **download**.
* If a user is **allowed to download but not print**, they can still access and open the **original file.**

**Here's a table to better show these rules:**

| Download Auth. | Print Auth. | Can download?   | Can Print? | File Preview |
| -------------- | ----------- | --------------- | ---------- | ------------ |
| ✅              | ✅           | ✅ Original file | ✅          | Unprintable  |
| ✅              | ❌           | ✅ Original file | ❌          | Unprintable  |
| ❌              | ✅           | ❌               | ❌          | Unprintable  |
| ❌              | ❌           | ❌               | ❌          | Unprintable  |

{% hint style="info" %}
Admins always have full access and cannot be denied **Download** or **Print** authorizations.
{% endhint %}

</details>

<details>

<summary><strong>Object Book Generation</strong></summary>

* If the user can **download and print**, the object book is generated as a **Word document**.
* If the user can **download but not print**, it is generated as a **non-printable PDF**.
* If the user **cannot download**, they cannot generate the object book at all.

**Here's a table to better show these rules:**

| Download Auth. | Print Auth. | Book Generation                   |
| -------------- | ----------- | --------------------------------- |
| ✅              | ✅           | ✅ Generated as Word file          |
| ✅              | ❌           | ✅ Generated as an unprintable PDF |
| ❌              | ✅           | ❌                                 |
| ❌              | ❌           | ❌                                 |

{% hint style="info" %}
Admins always have full access, so their object books will be generated as Word files.
{% endhint %}

</details>

***

## Security Best Practices

* Use **groups** to simplify permission management.
* Review and clean up permissions regularly.
* In high-security environments, always use **object-level** permissions for sensitive items.

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://interfacing.gitbook.io/interfacing-help-files/administration-and-configuration/system-administrators/permission-and-security-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
