Skip to content

User rights on documents

Introduction

Intelligent Disclosure documents are stored in SharePoint and so the SharePoint user rights management system can be used to control who can access, edit or delete documents.

Note. This manual is not intended to be a complete guide for managing SharePoint user rights. For more information, see the official Microsoft documentation on Permission levels in SharePoint.

User rights in SharePoint

SharePoint user rights define the permissions assigned to users or groups of users to run actions on SharePoint Sites, Collections, Folders or Documents. User rights can be inherited from the higher level, or interrupted and customised at the lower level.

There are various types of user permissions in SharePoint: Total Control, Edit, Read, Contribution, Approval, etc. Every user right defines a set of actions that the user can run on the SharePoint element.

Example 1. If it is useful to assign rights to a site, all the collections, folders and documents within that site will inherit the same user rights, unless inheritance is interrupted and different user rights are assigned to a specific collection, folder or document.

Rights can be assigned to a user or a group of users. A group of users is a collection of users who share the same right. Using user groups can help to simplify and optimise the management of user rights: the same right can be assigned to several users simultaneously, and even easily update or remove the right for the whole group.

Example 2. A user with the Read right can only view and download the element; whereas a user with the Edit right can also add, edit or delete the element. You can also create customised user rights by selecting the specific actions that you want to permit or deny.

Intelligent Disclosure user roles

Intelligent Disclosure user roles identify the permissions that can be assigned to users to access and run actions using the additional Intelligent Disclosure component. The user rights defined in SharePoint also apply to Intelligent Disclosure documents.

The difference between SharePoint user rights and Intelligent Disclosure user roles

SharePoint user rights control access to and actions on SharePoint elements, while Intelligent Disclosure user roles control access to and actions on data within documents. For example, a user with the Read right in SharePoint can view and download an Intelligent Disclosure document, but may not be able to edit or update the data within the document, depending on their user roles in Tagetik. The management of User Rights in ID must consider both SharePoint user rights and Tagetik user roles. SharePoint user rights will determine who can access, edit or delete documents, while Tagetik user roles will determine who can add, edit or update the data within documents. For more information on Tagetik user roles, see User role application

Best Practices

  • Use user groups to assign SharePoint access rights to several users simultaneously and to simplify the management of access rights.
  • Use the concept of inheritance to apply the same SharePoint access rights to all elements within a site or a collection, unless the access rights are customised for a specific element.
  • Use reports on SharePoint access rights to monitor and check the assignment of or changes to access rights.