Object permissions can be granted to users and roles to allow or deny execution of certain business operations and the specific instances of a given entity type. They are typically used for overriding operation permissions which describe a general security policy. You can manage object permissions for the entities of Content, Dynamic and Tagged Playlist, Live Text and Media Feed, Presentation, Group and Player types.
...
Permissions granted to users on the object level have the highest priority but the narrowest scope.
Permissions granted to roles on the object level have second priority and may be overridden by user permissions.
Permissions granted to roles on the operation level (visible in the Admin
...
> Roles page)
...
have the lowest priority but the widest scope.
Role and User Access States
Role and user access can be in one of the following states:
...
An editable permission for a specific principal, entity, or operation has an enabled/disabled active toggle switch and a "remove" buttondelete (trashcan) icon as shown in Image 1.
For example, a custom Content Managers role with permission to execute just the only Content - View Content operation permissions under the a selected Media File
An editable permission for a specific principal, entity, or parent operation has an enabled/disabled active toggle switch but without the "remove" buttonbut no delete icon.
For example, a custom Content Managers role with permission to execute the Content (Full Control) operation permissions under the a selected Media File. In this case, permission to execute Content - View Content is inherited fromĀ Content (Full Control).
An editable permission is defined for a specific principal, parent entity. These permissions are displayed withenabled/disabled active. The toggle switch is grey and does not have a "remove" buttondelete icon.
For example, a custom Content Managers role has permission to execute any operation under any new content folder. These permissions are inherited from the parent content folder.
An editable permission is defined for a parent principal. It is displayed with enabled/disabled active and the . The toggle switch is grey and does not have a "remove" buttondelete icon.
For example, a custom Content Managers role has permission to execute any operation under any new content folder or media file. If you assign a new user to this role, permissions to execute all operations under all content folders (except their personal folder) and media files are inherited from their role.
If permissions are defined for a parent principal, operation, or parent entity and are not editable, they will be displayed with enabled/disabled but inactive and a grey toggle switch without the "remove" buttondelete icon.
These are permissions defined for System Roles, Personal Folders, Special Groups, etc.
If permissions are not defined for a parent principal, operation, or parent entity, the toggle switch is disabled and grey. There is no "remove" buttondelete icon.
For example, a role with incompletely defined permissions and a user who doesn't extend and override them.
...
You can create and edit objectpermissionsin conjunction with CustomRoles to meet the organizational needs of a large digital signage network where pricing and offerings may vary by regions and/or stores. In this scenario, you may need to limit or allow access according to the objects (media Media files, dynamic playlistsDynamic Playlists, etc.) themselves.
...
Object permissions are accessed through the Security section of the Properties pane. This is on the right side of the screen in Network, Content, or Presentations tab (for player, content, or presentation properties).
...
Create a Custom Role based on Publishers.
Assign all of the store managers to this role.
Change the role so that the actions View Groups and Update Schedule in the Group category are denied.
Make sure that each group of players reflects a different store location ???
Change the object permissions of each group on the network so that each user assigned to the custom Publishers role can only view and modify the group corresponding to his or her store ???
You can also assign object permissions based on individual players. This is helpful if you already organize groups in some other way (by region, by store type, etc.).
...