<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security rule to manage stream access rule in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/138982#M2201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a new customised content admin role to segregate content admin users to manage their own resources. I need the custom content admin to be able to create new stream and manage the security access rule for the stream he/she created/owned. However the custom content admin is still able to edit the security rule for read-only streams although other sections within the stream remained as read-only. Has anyone done this before? Appreciate advise from the experts out there. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the security rules i have created:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdmin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter -&lt;/STRONG&gt; Stream_*,App*,ReloadTask_*,UserSyncTask_*,SchemaEvent_*,User*,CustomProperty*,Tag_*,DataConnection_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions -&lt;/STRONG&gt; Create, Read, Update, Delete, Export, Publish, Duplicate, Approve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;((user.roles="CustomContentAdmin" and resource.app.@UserGroup=user.@UserGroup or resource.@UserGroup=user.@UserGroup))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdminStream&amp;nbsp; &lt;/STRONG&gt;(Note: If I dont add this rule the custom admin will not be able to create new stream and only able to see and manage the stream he/she owned)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt; - Stream*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt; - Create, Read, Publish, Change owner&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;((user.roles="CustomContentAdmin"))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdminRuleAccess&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt; - SystemRule_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt; - Create, Read, Update&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;user.roles = "CustomContentAdmin"&lt;/P&gt;&lt;P&gt;and resource.category = "Security" and (resource.resourcefilter matches "Stream_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Oct 2018 06:54:36 GMT</pubDate>
    <dc:creator>wailengwoo</dc:creator>
    <dc:date>2018-10-26T06:54:36Z</dc:date>
    <item>
      <title>Security rule to manage stream access rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/138982#M2201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a new customised content admin role to segregate content admin users to manage their own resources. I need the custom content admin to be able to create new stream and manage the security access rule for the stream he/she created/owned. However the custom content admin is still able to edit the security rule for read-only streams although other sections within the stream remained as read-only. Has anyone done this before? Appreciate advise from the experts out there. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the security rules i have created:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdmin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter -&lt;/STRONG&gt; Stream_*,App*,ReloadTask_*,UserSyncTask_*,SchemaEvent_*,User*,CustomProperty*,Tag_*,DataConnection_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions -&lt;/STRONG&gt; Create, Read, Update, Delete, Export, Publish, Duplicate, Approve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;((user.roles="CustomContentAdmin" and resource.app.@UserGroup=user.@UserGroup or resource.@UserGroup=user.@UserGroup))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdminStream&amp;nbsp; &lt;/STRONG&gt;(Note: If I dont add this rule the custom admin will not be able to create new stream and only able to see and manage the stream he/she owned)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt; - Stream*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt; - Create, Read, Publish, Change owner&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;((user.roles="CustomContentAdmin"))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CustomContentAdminRuleAccess&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt; - SystemRule_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt; - Create, Read, Update&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;user.roles = "CustomContentAdmin"&lt;/P&gt;&lt;P&gt;and resource.category = "Security" and (resource.resourcefilter matches "Stream_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 06:54:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/138982#M2201</guid>
      <dc:creator>wailengwoo</dc:creator>
      <dc:date>2018-10-26T06:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule to manage stream access rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/138983#M2202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Resolved the issue by adding the following condition in bold in the rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: 'Helvetica Neue',Helvetica,Arial,'Lucida Grande',sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: bold; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;Rule name: CustomContentAdminStream&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #3d3d3d; font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px; border-color: #3d3d3d; border-style: none;"&gt;&lt;STRONG style="font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: bold; border-color: #3d3d3d; border-style: none;"&gt;Resource filter&lt;/STRONG&gt; - Stream*&lt;/P&gt;&lt;P style="color: #3d3d3d; font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px; border-color: #3d3d3d; border-style: none;"&gt;&lt;STRONG style="font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: bold; border-color: #3d3d3d; border-style: none;"&gt;Actions&lt;/STRONG&gt; - Create, Read, Publish, Change owner&lt;/P&gt;&lt;P style="color: #3d3d3d; font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px; border-color: #3d3d3d; border-style: none;"&gt;&lt;STRONG style="font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: bold; border-color: #3d3d3d; border-style: none;"&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #3d3d3d; font-family: &amp;amp;font-size:13px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px; border-color: #3d3d3d; border-style: none;"&gt;((user.roles="CustomContentAdmin" &lt;STRONG&gt;and resource.owner.name=user.name))&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2018 04:05:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/138983#M2202</guid>
      <dc:creator>wailengwoo</dc:creator>
      <dc:date>2018-10-30T04:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule to manage stream access rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/1807621#M19432</link>
      <description>&lt;P&gt;I have the same issue.&lt;/P&gt;&lt;P&gt;But i can't restrict access Custom user role to&amp;nbsp;&lt;SPAN&gt;manage the security access rule for the stream he/she created/owned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Rule allow access to&amp;nbsp; all Streams security rules or no one.&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Stream_TORulesAccess&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- SystemRule_*, Stream_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Create, Read, Update,Delete&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;(user.roles = "Stream_TO"&amp;nbsp;&lt;BR /&gt;and (resource.category = "Security" and resource.resourcefilter matches "Stream_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}"))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its allow to create and edit secity rules for all streams&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Stream_TORulesAccess&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resource filter&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- SystemRule_*, Stream_*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Actions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Create, Read, Update,Delete&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;(user.roles = "Stream_TO"&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;and resource.owner.userId=user.userId&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;and (resource.category = "Security" and resource.resourcefilter matches "Stream_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}"))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's rule not works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Early thanks for any advice&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 10:33:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-rule-to-manage-stream-access-rule/m-p/1807621#M19432</guid>
      <dc:creator>korsikov</dc:creator>
      <dc:date>2021-05-13T10:33:53Z</dc:date>
    </item>
  </channel>
</rss>

