Adding and removing passwords from a role  Role heirarchies and mutual exclusivity

Chapter 14: Managing Adaptive Server Logins, Database Users, and Client Connections

Role hierarchies and mutual exclusivity

A System Security Officer can define role hierarchies such that if a user has one role, the user also has roles lower in the hierarchy. For example, the “chief_financial_officer” role might contain both the “financial_analyst” and the “salary_administrator” roles, as shown in Figure 14-2.

Figure 14-2: Role hierarchy

The Chief Financial Officer can perform all tasks and see all data that can be viewed by the Salary Administrators and Financial Analysts.

Roles can be defined to be mutually exclusive for:

System roles, as well as user-defined roles, can be defined to be in a role hierarchy or to be mutually exclusive. For example, you might want a “super_user” role to contain the System Administrator, Operator, and “tech_support” roles. You might also want to define the System Administrator and System Security Officer roles to be mutually exclusive for membership; that is, one user cannot be granted both roles.





Copyright © 2005. Sybase Inc. All rights reserved. Role heirarchies and mutual exclusivity

View this book as PDF