Do I have to give external users "get" permission for an ItemType when using a MAC policy to restrict access?
Hi community,
let´s assume we have a lot of regular Parts in Innovator. An external user now shall have access to a limited amount of these Parts. An additional property specifies which parts he is allowed to see.
This scenario is a perfect job for a MAC policy. MAC policies allow to restrict the user access based on the property.
But I noticed that the external user still needs to be added to the regular permission that is used for Parts (e.g. Permission "Released Part"). Is this really necessary?
The MAC rule it self works fine. But only if the external user is part of the "Released Part" permission. Otherwise he will see nothing.
But I would prefer to avoid adding the user to this general permission.
Reason: When the external user is part of the regular permission, he could see all items by default. Only after the MAC rule is activated, the item access is restricted. But what if we upgrade and forget to reactive the MAC rule? Will the external user see everything until we notice our mistake?
I would prefer things the other way round. The external user must not see any Part UNTIL the MAC policy activated.
Is this behavior possible?
Thanks in advance!
Angela