Users overview and access model

IBM Controller Disclosure Management uses a role and permission-based access model to control user access to projects and style sheets.

User access control is implemented at the project and style sheet levels. Folder structures are used for content organization only and do not enforce access restrictions.

Access model

Key characteristics of the access model:

  • Access is defined at the project and style sheet levels.
  • Folder structures do not define or restrict access.
  • Permissions can be assigned directly to individual users or inherited through group assignments.
  • Group permissions take precedence over individually assigned permissions.

User group

Table 1. IBM DM Security Model: Groups and Key Permissions
Group Name Key Permissions
System_Administrators Admin Role: View access to Project, Stylesheet, User, Group, Roles pages. Super User Role: Full access (read, write, lock, unlock, delete, copy) to all projects and style sheets.
Account_Contributors Read and write access to all projects and features; View Project & Stylesheet pages.
Account_Viewers Read-only access to all projects and features; View Project & Stylesheet pages.
Restricted_Users No permissions - restricted access.

User visibility

Table 2. User visibility by role
Role Visible users
Administrator Can view and manage all user accounts in the system.
Standard user Can view only their own user profile.