Skip to content

ロールデータアクセス制限(Role Data Access)|iDempiere 13 画面リファレンス

This content is not available in your language yet.

ロールデータアクセス制限(Role Data Access)

Section titled “ロールデータアクセス制限(Role Data Access)”

iDempiere 13 標準ウィンドウ(AD_Window_ID: 268)

メニュー: システム管理 ▸ 全般設定 ▸ セキュリティ管理 ▸ ロールデータアクセス制限

Maintain Data Access Rules

Maintain Data Access Roles of Roles/Responsibilties. Note that access information is cached and requires re-login or reset of cache.

#タブテーブル階層説明
10ロールデータアクセスAD_Role0Role with Data Access Restriction
20テーブルアクセスAD_Table_Access1Maintain Table Access
30カラムアクセスAD_Column_Access1Maintain Column Access
40レコードアクセスAD_Record_Access1Maintain Record Access

ロールデータアクセス タブのフィールド

Section titled “ロールデータアクセス タブのフィールド”

Select Role for with Data Access Restrictions. Note that access information is cached and requires re-login or reset of cache.

フィールドカラム必須説明
クライアントAD_Client_IDTable DirectTenant for this installation.
組織AD_Org_IDTable DirectOrganizational entity within tenant
名称NameStringAlphanumeric identifier of the entity
説明DescriptionStringOptional short description of the record
初期値設定レベルPreferenceTypeListDetermines what preferences the user can set
変更ログIsChangeLogYes-NoMaintain a log of changes
会計情報表示許可IsShowAcctYes-NoUsers with this role can see accounting information
全組織アクセス許可IsAccessAllOrgsYes-NoAccess all Organizations (no org access control) of the tenant
レポート閲覧許可IsCanReportYes-NoUsers with this role can create reports
エクスポート許可IsCanExportYes-NoUsers with this role can export data
レコードアクセス権限設定許可IsPersonalLockYes-NoAllow users with role to lock access to personal records
制限されているレコードへのアクセス許可IsPersonalAccessYes-NoAllow access to all personal records
Role TemplateIsMasterRoleYes-NoA role template cannot be assigned to users, it is intended to define access to menu option and documents and inherit to other roles

テーブルアクセス タブのフィールド

Section titled “テーブルアクセス タブのフィールド”

If listed here, the Role can(not) access all data of this table, even if the role has access to the functionality.
If you Include Access to a table and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a table and select Read Only, you can only read data (otherwise no access).
Please note that table access rules here are in addition to the Data Access Levels defined for a Table and the User Level defined for a Role. These rules are evaluated first and you only need to define the exceptions to these rules here.

Note that access information is cached and requires re-login or reset of cache. Be aware that if you use Include rules, then you need to include also several supporting entities. As an alternative, grant access only to functionality required.

フィールドカラム必須説明
クライアントAD_Client_IDTable DirectTenant for this installation.
組織AD_Org_IDTable DirectOrganizational entity within tenant
ロールAD_Role_IDTable DirectResponsibility Role
テーブルAD_Table_IDTable DirectDatabase Table information
有効IsActiveYes-NoThe record is active in the system
アクセス不可IsExcludeYes-No除外する
アクセスタイプAccessTypeRuleListThe type of access for this rule
読取専用IsReadOnlyYes-NoField is read only

カラムアクセス タブのフィールド

Section titled “カラムアクセス タブのフィールド”

If listed here, the Role can(not) access the column of this table, even if the role has access to the functionality.
If you Include Access to a column and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a column and select Read Only, you can only read data (otherwise no access). Note that access information is cached and requires re-login or reset of cache.

フィールドカラム必須説明
クライアントAD_Client_IDTable DirectTenant for this installation.
組織AD_Org_IDTable DirectOrganizational entity within tenant
ロールAD_Role_IDTable DirectResponsibility Role
テーブルAD_Table_IDTable DirectDatabase Table information
カラムAD_Column_IDTable DirectColumn in the table
有効IsActiveYes-NoThe record is active in the system
アクセス不可IsExcludeYes-No除外する
読取専用IsReadOnlyYes-NoField is read only

レコードアクセス タブのフィールド

Section titled “レコードアクセス タブのフィールド”

You create Record Access records by enabling “Personal Lock” for the administrative role and Ctl-Lock (holding the Ctrl key while clicking on the Lock button).

If listed here, the Role can(not) access the data records of this table, even if the role has access to the functionality.
If you Include Access to a record and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a recorf and select Read Only, you can only read data (otherwise no access). Note that access information is cached and requires re-login or reset of cache.

フィールドカラム必須説明
クライアントAD_Client_IDTable DirectTenant for this installation.
組織AD_Org_IDTable DirectOrganizational entity within tenant
ロールAD_Role_IDTable DirectResponsibility Role
テーブルAD_Table_IDTable DirectDatabase Table information
レコードIDRecord_IDRecord IDDirect internal record ID
有効IsActiveYes-NoThe record is active in the system
アクセス不可IsExcludeYes-No除外する
読取専用IsReadOnlyYes-NoField is read only
依存エンティティIsDependentEntitiesYes-No依存エンティティを確認する