CONFIGURING


Using administration roles in the Domino Directory ACL

The Domino® Directory ACL includes Creator and Modifier roles that you assign to administrators so they have the authority to create and edit specific types of documents. By assigning one or more roles along with general access levels, you can limit an administrator's access to some types of documents but allow greater access to other types of documents.

About this task

Roles are useful when groups of administrators have specialized responsibilities. If all of the administrators in your organization have identical administrative responsibilities, assign them to all roles. The access defined in the ACL by a role never exceeds a general access level. For example, even if you give the UserCreator role to an administrator who has Reader access in the ACL, the administrator cannot use the Create menu to create Person documents.

Creator roles

About this task

Assign creator roles to control who can create documents in the Domino Directory. To create documents in the Domino Directory, administrators must have:


Table 1. Creator roles
RoleAllows
GroupCreatorAdministrators to create Group documents
NetCreatorAdministrators to create all documents except Person, Group, Policy, and Server documents
PolicyCreatorAdministrators to create Policy documents
ServerCreatorAdministrators to create Server documents
UserCreatorAdministrators to create Person documents

CAUTION: Assigning Creator roles does not provide true security because Domino sometimes ignores Creator roles when administrators add documents to the directory programmatically.

Modifier roles

About this task

Rather than assigning Editor access which allows administrators to modify all documents, assign administrators Author access along with one or more Modifier roles to control the types of documents they can edit. For example, assign the UserModifier role to administrators who are responsible for managing users. Unlike Creator roles, Modifier roles are a true security feature.

Table 2. Modifier roles
RoleAllows
GroupModifierAdministrators to edit Group documents
NetModifierAdministrators to edit all documents except Person, Group, Policy, and Server documents
PolicyModifierAdministrators to edit Policy documents
ServerModifierAdministrators to edit Server documents
UserModifierAdministrators to edit Person documents

When using Modifier roles, keep in mind the following points:


Related tasks
Controlling access to the Domino Directory
Roles in the ACL