コンテンツにスキップ

ロールデータアクセス制限(Role Data Access)|iDempiere 13 画面リファレンス

ロールデータアクセス制限(Role Data Access)

Section titled “ロールデータアクセス制限(Role Data Access)”

iDempiere 13 標準ウィンドウ(AD_Window_ID: 268)

メニュー: システム管理 ▸ 全般設定 ▸ セキュリティ管理 ▸ ロールデータアクセス制限

Maintain Data Access Rules

Maintain Data Access Roles of Roles/Responsibilties. Note that access information is cached and requires re-login or reset of cache.

#タブテーブル階層説明
10ロールデータアクセスAD_Role0Role with Data Access Restriction
20テーブルアクセスAD_Table_Access1Maintain Table Access
30カラムアクセスAD_Column_Access1Maintain Column Access
40レコードアクセスAD_Record_Access1Maintain Record Access

ロールデータアクセス タブのフィールド

Section titled “ロールデータアクセス タブのフィールド”

Select Role for with Data Access Restrictions. Note that access information is cached and requires re-login or reset of cache.

フィールドカラム型必須説明
クライアントAD_Client_IDTable Direct✔Tenant for this installation.
組織AD_Org_IDTable Direct✔Organizational entity within tenant
名称NameString✔Alphanumeric identifier of the entity
説明DescriptionStringOptional short description of the record
初期値設定レベルPreferenceTypeList✔Determines what preferences the user can set
変更ログIsChangeLogYes-No✔Maintain a log of changes
会計情報表示許可IsShowAcctYes-No✔Users with this role can see accounting information
全組織アクセス許可IsAccessAllOrgsYes-No✔Access all Organizations (no org access control) of the tenant
レポート閲覧許可IsCanReportYes-No✔Users with this role can create reports
エクスポート許可IsCanExportYes-No✔Users with this role can export data
レコードアクセス権限設定許可IsPersonalLockYes-No✔Allow users with role to lock access to personal records
制限されているレコードへのアクセス許可IsPersonalAccessYes-No✔Allow access to all personal records
Role TemplateIsMasterRoleYes-No✔A role template cannot be assigned to users, it is intended to define access to menu option and documents and inherit to other roles

テーブルアクセス タブのフィールド

Section titled “テーブルアクセス タブのフィールド”

If listed here, the Role can(not) access all data of this table, even if the role has access to the functionality.
If you Include Access to a table and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a table and select Read Only, you can only read data (otherwise no access).
Please note that table access rules here are in addition to the Data Access Levels defined for a Table and the User Level defined for a Role. These rules are evaluated first and you only need to define the exceptions to these rules here.

Note that access information is cached and requires re-login or reset of cache. Be aware that if you use Include rules, then you need to include also several supporting entities. As an alternative, grant access only to functionality required.

フィールドカラム型必須説明
クライアントAD_Client_IDTable Direct✔Tenant for this installation.
組織AD_Org_IDTable Direct✔Organizational entity within tenant
ロールAD_Role_IDTable Direct✔Responsibility Role
テーブルAD_Table_IDTable Direct✔Database Table information
有効IsActiveYes-No✔The record is active in the system
アクセス不可IsExcludeYes-No✔除外する
アクセスタイプAccessTypeRuleList✔The type of access for this rule
読取専用IsReadOnlyYes-No✔Field is read only

カラムアクセス タブのフィールド

Section titled “カラムアクセス タブのフィールド”

If listed here, the Role can(not) access the column of this table, even if the role has access to the functionality.
If you Include Access to a column and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a column and select Read Only, you can only read data (otherwise no access). Note that access information is cached and requires re-login or reset of cache.

フィールドカラム型必須説明
クライアントAD_Client_IDTable Direct✔Tenant for this installation.
組織AD_Org_IDTable Direct✔Organizational entity within tenant
ロールAD_Role_IDTable Direct✔Responsibility Role
テーブルAD_Table_IDTable DirectDatabase Table information
カラムAD_Column_IDTable Direct✔Column in the table
有効IsActiveYes-No✔The record is active in the system
アクセス不可IsExcludeYes-No✔除外する
読取専用IsReadOnlyYes-No✔Field is read only

レコードアクセス タブのフィールド

Section titled “レコードアクセス タブのフィールド”

You create Record Access records by enabling “Personal Lock” for the administrative role and Ctl-Lock (holding the Ctrl key while clicking on the Lock button).

If listed here, the Role can(not) access the data records of this table, even if the role has access to the functionality.
If you Include Access to a record and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a recorf and select Read Only, you can only read data (otherwise no access). Note that access information is cached and requires re-login or reset of cache.

フィールドカラム型必須説明
クライアントAD_Client_IDTable Direct✔Tenant for this installation.
組織AD_Org_IDTable Direct✔Organizational entity within tenant
ロールAD_Role_IDTable Direct✔Responsibility Role
テーブルAD_Table_IDTable Direct✔Database Table information
レコードIDRecord_IDRecord ID✔Direct internal record ID
有効IsActiveYes-No✔The record is active in the system
アクセス不可IsExcludeYes-No✔除外する
読取専用IsReadOnlyYes-No✔Field is read only
依存エンティティIsDependentEntitiesYes-No✔依存エンティティを確認する