Rights and permissions
PLA 3.0 provides the features you need to control access to your data in a sophisticated and compliant manner. It combines role-based user rights with resource-based permissions, which enables you to exercise fine-grained control over who can perform particular tasks in a given context and which tasks are allowed with particular data.
Account management
Use the account management feature of PLA 3.0 to set up users and groups directly in PLA 3.0 and assign global roles for database tasks such as setting up database policies or managing user sessions. The global roles you assign to users and groups are valid for the entire database.
Set up document roles for document tasks such as editing documents or applying electronic signatures. Assign document roles to users and groups to define security contexts, and apply these security contexts to folders or folder trees. Users and groups can be part of more than one security context. So, the document roles of a particular user or group can vary from folder to folder or from folder tree to folder tree. For details, see the Account management topic.
Folder properties
Use the folder properties feature of PLA 3.0 to assign security contexts to folders and restrict the content of particular folders to documents generated from particular document templates. For details, see the Folder properties topic.
Directory service
The directory service feature of PLA 3.0 allows you to use directory services based on secure LDAP (LDAPS: Lightweight Directory Access Protocol over SSL/ TLS). Instead of setting up users and groups directly in PLA 3.0, you map PLA 3.0 groups and their roles to user groups defined elsewhere on your network. For details, see the Directory service topic.