Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
OBJECTTYPE Security Commands
Safeguard Reference Manual 520618-030
12 - 2
OBJECTTYPE Access Authorities
OBJECTTYPE Access Authorities
The ACL defined for an OBJECTTYPE can grant any of these access authorities to
users and user groups:
Table 12-1. Defaults for Undefined OBJECTTYPE ACLs
Type of Object Who Can Place an Object Under Safeguard Control
ALIAS Group manager of underlying user ID. Also must be the owner of
underlyin
g user ID or owner’s group manager.
DEVICE Any local super group member
DISKFILE Local owner of the existing file
DISKFILE-PATTERN Any local user
GROUP Any local super group member
OBJECTTYPE Any local super group member
PROCESS Any local user
SUBDEVICE Any local super group member
SUBPROCESS Any local user
SUBVOLUME Any local user
USER Guardian rules apply:
The local super ID can create any local user ID.
The local group manager can create any local group member
user ID.
VOLUME Any local super-group member
Note. OBJECTTYPE USER controls who can add
users, aliases, and groups.
CREATE Add an authorization record for an object of this type
OWNER Manage the OBJECTTYPE authorization record