Privilege definition reference

Draft comment:
This topic only applies to BAW, and is located in the BAW repository. Last updated on 2025-03-13 12:15
The security configuration wizard in the Case administration client sets permissions on workflow and content objects. A set of predefined privileges are available in the security configuration wizard by default. You can customize the default settings by editing the privilege definition file.
Table 1. Default privileges in the security configuration wizard
Privilege Allows Sets Applies to What is updated?
create createCase "view all properties"

"create instance"

"read permissions"

"this object only" Case Type Subclass: TOS > Other Classes > Folder > Base Case > Case Folder > CaseType
"modify all properties" "this object only" Deployed Case Type Folder
"view all properties"

"create subfolder"

"file in folder/annotate"

"read permissions"

"this object and all children" Deployed Case Type Folder
"view all properties" "this object only" Deployed Case Type Folder
  startTask "change state" "this object and all children" Deployed Case Type Folder
    "create"   Process region roster
view viewCase "view all properties" "this object only" Deployed Case Type Folder
"view all properties"

"read permissions"

"this object and all children" Deployed Case Type Folder
update viewcase "view all properties" "this object only" Deployed Case Type Folder
viewcase "view all properties"

"read permissions"

"this object and all children" Deployed Case Type Folder
updatecase

"modify all properties"

"this object and all children" Deployed Case Type Folder
addDocument

"file in folder/annotate"

"unfile from folder"

"this object and all children" Deployed Case Type Folder
createSubfolder "create subfolder" "this object and all children" Deployed Case Type Folder
addComment

"file in folder/annotate"

"this object and all children" Deployed Case Type Folder
createDiscretionaryTask "view all properties"

"create instance"

"read permissions"

"this object only" Discretionary task type subclass: TOS > OtherClasses > Task > CaseTask > MyDiscretionaryTask
createDynamicTask "view all properties"

"create instance"

"read permissions"

"this object only" Discretionary task type subclass: TOS > OtherClasses > Task > CaseTask > MyDynamicTask
startTask

"change state"

"this object and all children" Deployed Case Type Folder
  "create"   Process region roster
viewWork "query"   Process region role: Process Configuration Console > Work Queues > SolPrefix_Role > Security Tab
processWork "process"   Process region role: Process Configuration Console > Work Queues > SolPrefix_Role > Security Tab
manage manageCase "view all properties" "this object only" Deployed Case Type Folder
"view all properties"

"modify all properties"

"file in folder/annotate"

"unfile from folder"

"create subfolder"

"delete"

"read permissions"

"modify permissions"

"modify owner"

"change state"

"this object and all children" Deployed Case Type Folder
  startTask "change state" "this object and all children" Deployed Case Type Folder
    "create"   Process region roster
    "write"   Process Configuration Console > Application Space > Solution > Security
full control FullControl   "this object and all children" Deployed Case Type Folder
      this object only TOS/OtherClasses/Task/CaseTask/MyDiscretionaryTask

TOS > Other Classes > Folder > Base Case > Case Folder > CaseType