Understanding Granted and Effective Permissions

You can grant an access permission to a group or to a user. When you grant permissions to a group, the users belonging to this group inherit the group permissions.

In a property sheet, the list of permissions displays two columns:

By default, group members do not appear in the list of permissions, this is called the non-inherited display mode. However, you can display these users by clicking the Show All Authorized Users tool, this is called the inherited mode.

The behavior of the Permissions lists changes according to the display mode.

Non-inherited Mode

This is the default display mode, it displays the permissions actually granted to users or groups.

  • Members groups are not displayed

  • The permission <none> is not used

  • The granted permission of a user or a group is always equal to the effective permission

  • Deleting a group or a user is immediately applied

Inherited Mode

  • Members of selected groups are displayed

  • The Granted Permission column displays <none> for these users until you define a permission using the list

  • The Effective Permission column displays the actual permission of the groups and users; in this column the most extensive permission selected among the group or the user granted permissions appear, as shown in the following example:

    Group permission

    User (from group) permission

    Effective permission of user

    List

    Write

    Write

    Full

    Read

    Full

  • When you delete a group and before you select the Apply button, the group remains visible in the list together with its users, the Granted Permission column displays <none>. When you apply the changes, the group and its members disappear from the list of permissions.