SAS Viya: General Authorization Window
- Introduction
- Navigation
- Examine Access
- Provide Access
- Limit Access
- Add a Condition
- Edit a Condition
- Delete a Condition
- Remove a Direct Setting
- Identify the Source of Effective Access
- Details for Share-Based Authorization Rules
- Shortcuts for Adding and Removing Settings
Introduction
Use this window to set permissions on folders, reports, and other content objects.
For concepts and background information, see General Authorization: Overview in SAS Viya Platform: General Authorization.
Navigation
Here is one way to access the Authorization window for content objects:
- In the applications
menu (
), under ADMINISTRATION, select Manage Environment.
- In the vertical
navigation bar in SAS
Environment Manager, click
.
- On the Content page, locate and select the object.
- In the toolbar
at the top of the navigation pane, click
, and select View Authorization or Edit Authorization.
Note: Some items on the Content page do not participate in general authorization. For example, you cannot set permissions on a virtual folder.Note: If Edit Authorization is not available, you are not authorized to modify access to the selected object.
Examine Access
For each principal and permission, the following icons describe effective (net) access to the current object:
|
Icon |
Meaning |
|---|---|
|
|
Authorized |
|
|
Conditional |
|
|
Not Authorized3 |
|
|
Unknown |
|
|
Direct (indicates that effective access comes from a direct setting)1 |
|
| |
| 1 This icon indicates that effective access comes from a permission that is directly assigned to the specified principal on the current object. If a direct setting exists but does not win (does not determine effective access), a diamond is not displayed. | |
| 2 This icon is applicable to only the Secure and Secure (convey) columns. This icon is displayed only if Secure access is not granted and sharing is possible. If Secure access is authorized, only the Authorized icon is displayed, because the ability to share is inherent in Secure access. | |
| 3 This icon signifies that any access that is not granted explicitly, either on the target or in its folder hierarchy, is implicitly denied. Authorization uses a deny-by-default model. If there is no rule (explicit or through container inheritance) granting a principal a specific permission to an object, then the principal is implicitly denied. | |
The scope of the display is as follows:
- There is always a row for Authenticated Users.
- There is always a row for you, the currently connected user who is using the display.
- There is a row for each principal that is assigned to a rule that affects access to the current object. The exception is that internal service principals (for example, sasapp or sas.folders) are not displayed in the Authorization window.
- If you add an identity and do not give that identity at least one direct setting, that identity is automatically removed from the display.
- You cannot directly remove a row. If you remove all direct settings for an identity and there is no other reason for that identity to be displayed, that identity is automatically removed from the display.
- For a non-container object (such as a report), only the Read, Update, Delete, and Secure permissions are displayed. The Create permission is not applicable to an individual content object.
- For a container
(such as a folder), two sets of permissions are displayed:
- The first set of permissions affects access to the object, including the ability to add members to and remove members from the object. This set of permissions has no effect on the folder’s members.
- The second
set of permissions affects the access that this object conveys to
its child members. See Inheritance in SAS Viya Platform: General Authorization.
TipAn effective access value of Not Authorized on the conveyed side of a folder’s Authorization window does not guarantee that access to child members is not authorized. A direct setting on the child or another influencing rule might provide access to the child member. For example, when you create a top-level folder, the effective access values on the conveyed side for SAS Administrators are all Not Authorized. However, SAS Administrators does have effective access to a folder that you add below the top-level folder. That access comes from a predefined rule that gives SAS Administrators access to all folders.
Provide Access
- Open the Edit Authorization window for the target object.
- If the principal
that you want to work with is not already listed, click
.
Note: If guest access is enabled, you must select either Add Identities or Add Guest after you click.
- Click an
effective access icon (for example,
).
- In the pop-up
window, select Grant as the direct
setting.
Note: If you cannot change a direct setting, you do not have Secure permission for the current object.
- In the Edit
Authorization window, click Preview.
Examine the impact of your unsaved change.
Note: If there is a relevant prohibit setting anywhere in the system, that setting has precedence over the direct grant that you added. In that case, the effective (net) result is Not Authorized (
), and a diamond (
) is not displayed.
- Click Save.
You can also apply direct grants for all permissions for a principal. See Add Direct Grants of All Permissions for an Identity.
Limit Access
Any access that is not granted is implicitly denied. The preferred approach is to grant selectively and to avoid use of prohibit settings.
If you must add a prohibit setting, make sure that you do not inadvertently block your own access, particularly for the Read and Secure permissions. If you do block your own access, see General Authorization: Troubleshooting in SAS Viya Platform: General Authorization.
CAUTION
A prohibit setting has absolute precedence, even if a more specific grant setting exists.
Add a Condition
To provide access within a particular scope or set of circumstances, add a condition.
- Open the Edit Authorization window for the target object.
- If the principal
that you want to work with is not already listed, click
.
Note: If guest access is enabled, you must select either Add Identities or Add Guest after you click.
- Click an
effective access icon (for example,
).
- In the pop-up
window, select Conditional Grant.
Note: A conditional prohibit setting does not provide access. A conditional prohibit setting blocks all access within its scope, regardless of any more specific grant settings. A conditional prohibit setting can limit access that is provided by a grant or conditional grant setting.
- In the Condition window, create an expression that specifies the scope and circumstances in which access is granted. Your syntax is validated when you click OK. See Rule Conditions in SAS Viya Platform: General Authorization.
- In the Edit Authorization window, click Preview. Examine the impact of your unsaved change.
- Click Save.
Edit a Condition
- In the Edit Authorization window for an object, click the effective access icon for the direct conditional setting that you want to modify.
- In the pop-up
window, next to the Conditional Grant
or Conditional Prohibit direct
setting, click
.
- In the Condition window, edit the expression. Your syntax is validated when you click OK. See Rule Conditions in SAS Viya Platform: General Authorization.
- In the Edit Authorization window, click Preview. Examine the impact of your unsaved change.
- Click Save.
Delete a Condition
- In the Edit Authorization window for an object, click the effective access icon for the direct conditional setting that you want to delete.
- In the pop-up
window, next to the Conditional Grant
or Conditional Prohibit direct
setting, click
.
- In the Condition window, delete the expression. Click OK.
- In the Edit Authorization window, click Preview. Examine the impact of your unsaved change.
- Click Save.
Remove a Direct Setting
- Open the Edit Authorization window for an object.
- In the cell
that has the direct setting that you want to remove, click the effective
access icon. In the pop-up window, select (none) as
the direct setting.
Note: If you cannot change the direct setting, you do not have Secure permission for the current object.
- In the Edit
Authorization window, click Preview.
Examine the impact of your unsaved change.
Note: Any identities that are no longer principals are automatically removed.
- Click Save.
You can also delete all direct settings for a principal. See Remove All Direct Settings for an Identity.
Identify the Source of Effective Access
To determine which rules and shares contribute to a particular effective access result, examine the origins information for that result.
- Open the View Authorization window for the target content object.
- Click the effective access icon for which you want origins information.
- In the pop-up
window, the Contributing Rules tab
provides a read-only display of all applicable rules, except share-based
rules. Here are tips:
- If the Edit Authorization window contains pending changes, the Contributing Rules tab is disabled.
- To view additional
details, add columns to the table. Click
and select Manage columns.
- In the pop-up
window, the Contributing Shares tab
provides a read-only display of all relevant shares. Here are tips:
- If sharing is disabled, the Contributing Shares tab is not displayed.
- To view additional details, add columns to the table.
Details for Share-Based Authorization Rules
Direct Settings
In the Authorization window, a share is not considered a direct setting.
A share does not cause a diamond () to be displayed.
You cannot modify shares in the Authorization window.
Effective Access
In the Authorization window, effective access information reflects shares as follows:
- Effective access information reflects any access that is provided by shares.
- In the Secure and Secure
(convey) columns, the Share icon
indicates that sharing is possible even though Secure access is not granted.
Note: If Secure access is granted, the Share icon is not displayed. The ability to share is inherent in Secure access.
Contributing Shares
After you click an effective access icon in the Authorization window, a pop-up window that includes a Contributing Shares tab is displayed. The tab provides a read-only list of the shares that are relevant to the selected effective access result.
A share is relevant if it meets all of the following criteria:
- The share specifies the current object (or a parent of that object) as the target.
- The share specifies the current principal (or a group to which that principal belongs) as the recipient.
- The share
type is relevant for the selected permission. For example, for the
Update and Delete permissions, the
readEditShareandreadEdittypes are relevant, but thereadandreadSharetypes are not relevant.Note: For the Secure permission, thereadShareandreadEditSharetypes are treated as relevant only because those types provide the ability to reshare. Sharing never creates a grant of the Secure permission.Note: To add the Share Type column to the display, clickand select Manage columns.
If Re-sharing Is Disabled
- In the Authorization window, no sharing-related information is displayed for the Secure permission.
- There is no Contributing Shares tab for the Secure permission.
If Sharing Is Disabled
- In the Authorization window, no sharing-related information is displayed.
- SAS Drive hides all actions and information that are related to sharing.
- SAS Drive provides direct access to the Authorization window for authorized users.
Shortcuts for Adding and Removing Settings
Remove All Direct Settings for an Identity
- Open the Edit Authorization window.
- Select the identity’s row.
- In the toolbar above the table, click
to remove all direct settings for the selected identity.
Note: This feature is new in 2024.12. - Notice that effective access
for any affected cells is unknown (
). Click Preview.
- Notice that all effective access values are known. If the associated user or group is no longer a relevant principal for the current object, the user or group is removed from the display.
- If you removed settings for a group, examine the impact on other principals.
- Click Save.
Add Direct Grants of All Permissions for an Identity
- Open the Edit Authorization window.
- Select the identity’s row.
- In the toolbar above the table,
click
to add direct grants of all permissions for the selected identity.
Note: This feature is new in 2024.12 - Notice that effective access
for any affected cells is unknown (
). Click Preview.
- Notice that all effective access values are known.
- If you added grants for a group, examine the impact on other principals.
TipIn general authorization, a direct grant does not have precedence over a prohibit setting, so adding direct grants does not guarantee full access. If there is an applicable (indirect) prohibit setting, no diamond icon () is displayed. After you save your changes, you can confirm the presence of the direct grants in the Origins window. See Identify the Source of Effective Access.
- Click Save.