Safeguard Administrator's Manual (G06.29+, H06.08+, J06.03+)

Controlling User Access
Safeguard Administrator’s Manual523317-029
2-38
Establishing Guardian Defaults
Then she issues the INFO USER command with the CI option to check the results:
INFO USER admin.jeff, CI
The display shows:
Now SAFECOM is started automatically whenever ADMIN.JEFF logs on at a
Safeguard terminal. For more information, see Section 7, Securing Terminals.
The INFO USER display shows that you can specify other optional attributes relating to
the default command interpreter. For more information about these attributes, see the
Safeguard Reference Manual.
Establishing Guardian Defaults
When you add a user authentication record to the Safeguard database, you can
specify the Guardian default file-security string and the saved default volume and
subvolume for that user. The Guardian default file-security string is given to any of the
user disk files that are not under Safeguard protection. The user Guardian-saved
default volume and subvolume are established each time the user logs on to the
system or enters a VOLUME command without any parameters.
The GUARDIAN DEFAULT SECURITY attribute controls the Guardian default
file-security string. When you set this attribute in the Safeguard user authentication
record, it accomplishes the same function as using the DEFAULT program to set the
security string. For more information about the security string and the DEFAULT
program, see the Safeguard User’s Guide.
The GUARDIAN DEFAULT VOLUME attribute controls the Guardian-saved default
volume and subvolume. When you set this attribute in the Safeguard user
authentication record, it accomplishes the same function as using the DEFAULT
program to set the user saved default volume and subvolume.
Setting the File-Security String
If you do not specify a value for the GUARDIAN DEFAULT SECURITY attribute when
you add a Safeguard user authentication record, that user is given a Guardian default
security string of OOOO. This string indicates that when Guardian default protection is
applied, only the local file owner, the owners group manager, and the super ID have
READ, WRITE, EXECUTE, and PURGE authority.
GROUP.USER USER-ID OWNER LAST-MODIFIED LAST-LOGON STATUS WARNING-MODE
ADMIN.JEFF 1,12 200,1 15AUG05, 11:54 12AUG05, 16:02 THAWED OFF
CI-PROG = $SYSTEM.SYSTEM.SAFECOM
CI-LIB = * NONE *
CI-NAME = * NONE *
CI-SWAP = * NONE *
CI-CPU = * NONE *
CI-PRI = * NONE *
CI-PARAM-TEXT =