<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Rule Addition #1 in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-Addition-1/m-p/1112036#M31158</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an addition/change to the security rules that you may (or may not) want, depending on your needs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario:&amp;nbsp; under the proposed custom rules in the GSS package, your RootAdmin roles will be able to see all streams and apps in the hub, which are published.&amp;nbsp;&amp;nbsp; In addition, they can see all unpublished apps in their own My Work stream.&amp;nbsp;&amp;nbsp; This can be overwhelming to see everybody's in-progress apps, but I find it useful for oversight and monitoring.&amp;nbsp;&amp;nbsp;&amp;nbsp; IF YOU DON'T WANT THIS capability, then consider the changes below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) in the custom security rule called "_abc - Root Admin Group Rule", uncheck the &lt;STRONG&gt;Export data&lt;/STRONG&gt; checkbox, and then change the &lt;STRONG&gt;Context&lt;/STRONG&gt; to &lt;STRONG&gt;Only in QMC.&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; This will remove all of the unpublished apps from being seen in the RootAdmin's My Work stream (they will still see their own unpublished apps, just not others').&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Since this will also remove their built in ability to see all streams, you will want to add a @QlikGroup custom property value of "Admin" or something similar to each stream in your QMC.&amp;nbsp;&amp;nbsp; Then add the group "Admin" to any RootAdmins in your security catalog.&amp;nbsp;&amp;nbsp; What this does is allow the group access rule (_abc - Group Access Rule) to give read access to all streams for the RootAdmins.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See screenshot below.&amp;nbsp;&amp;nbsp; I used the @QlikGroup value of "IT" on all of my streams and then added the security group "IT" to all of my Admins, so they could see all streams.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brad Peterman, QLIK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2025 17:06:43 GMT</pubDate>
    <dc:creator>Brad_Peterman</dc:creator>
    <dc:date>2025-01-29T17:06:43Z</dc:date>
    <item>
      <title>Security Rule Addition #1</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-Addition-1/m-p/1112036#M31158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an addition/change to the security rules that you may (or may not) want, depending on your needs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario:&amp;nbsp; under the proposed custom rules in the GSS package, your RootAdmin roles will be able to see all streams and apps in the hub, which are published.&amp;nbsp;&amp;nbsp; In addition, they can see all unpublished apps in their own My Work stream.&amp;nbsp;&amp;nbsp; This can be overwhelming to see everybody's in-progress apps, but I find it useful for oversight and monitoring.&amp;nbsp;&amp;nbsp;&amp;nbsp; IF YOU DON'T WANT THIS capability, then consider the changes below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) in the custom security rule called "_abc - Root Admin Group Rule", uncheck the &lt;STRONG&gt;Export data&lt;/STRONG&gt; checkbox, and then change the &lt;STRONG&gt;Context&lt;/STRONG&gt; to &lt;STRONG&gt;Only in QMC.&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; This will remove all of the unpublished apps from being seen in the RootAdmin's My Work stream (they will still see their own unpublished apps, just not others').&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Since this will also remove their built in ability to see all streams, you will want to add a @QlikGroup custom property value of "Admin" or something similar to each stream in your QMC.&amp;nbsp;&amp;nbsp; Then add the group "Admin" to any RootAdmins in your security catalog.&amp;nbsp;&amp;nbsp; What this does is allow the group access rule (_abc - Group Access Rule) to give read access to all streams for the RootAdmins.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See screenshot below.&amp;nbsp;&amp;nbsp; I used the @QlikGroup value of "IT" on all of my streams and then added the security group "IT" to all of my Admins, so they could see all streams.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brad Peterman, QLIK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2025 17:06:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-Addition-1/m-p/1112036#M31158</guid>
      <dc:creator>Brad_Peterman</dc:creator>
      <dc:date>2025-01-29T17:06:43Z</dc:date>
    </item>
  </channel>
</rss>

