<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>I have an Appian Security Design question. I have designed a Contract Request Ap</title><link>https://community.appian.com/discussions/f/data/5276/i-have-an-appian-security-design-question-i-have-designed-a-contract-request-ap</link><description>I have an Appian Security Design question. I have designed a Contract Request App where security is paramount. The security requirements include 2 basic security roles: 1 - Observers allowed to view all contracts. (ex. CIO and members of contracting office</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: I have an Appian Security Design question. I have designed a Contract Request Ap</title><link>https://community.appian.com/thread/19708?ContentTypeID=1</link><pubDate>Fri, 03 Jul 2015 03:05:12 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:598bba80-5683-490c-9090-5f99e005aedd</guid><dc:creator>Andrew P Gramann</dc:creator><description>Perhaps should all app users be allowed to view the Record and then put security on each Process Instance resulting in them only being able to their Records their allowed?&lt;br /&gt;&lt;br /&gt;This is the way to do it for process backed records.  Additionally, a!queryRecord() takes security into account when it is executed, so your can develop reports against your records type that still respect record level security.&lt;br /&gt;&lt;br /&gt;Appian COE has written up the best practice for record level security on Data Entity backed records here &lt;a href="https://forum.appian.com/suite/help/7.9/Record_Level_Security_for_Entity_Backed_Records_Best_Practice.html"&gt;forum.appian.com/.../Record_Level_Security_for_Entity_Backed_Records_Best_Practice.html&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: I have an Appian Security Design question. I have designed a Contract Request Ap</title><link>https://community.appian.com/thread/19707?ContentTypeID=1</link><pubDate>Fri, 03 Jul 2015 03:01:13 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ed807b08-ac6b-414d-a0ee-1c51560aa57d</guid><dc:creator>nathan.schmitz</dc:creator><description>Having per instance process security using process backed records is probably the simplest approach.  However processes must be archived at some point (preferably soon) after completion at which point the process will no longer be visible.  If this is unacceptable, you should consider using entity backed records and implementing security as part of the default filter.  This will enables users to continue to see the record even after process instances are archived.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: I have an Appian Security Design question. I have designed a Contract Request Ap</title><link>https://community.appian.com/thread/19683?ContentTypeID=1</link><pubDate>Thu, 02 Jul 2015 21:29:50 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:01f6a4d1-a7d6-45e5-9b8e-ae7e36b2928b</guid><dc:creator>greggl</dc:creator><description>...process via the News but not all the other contract Records. &lt;br /&gt;&lt;br /&gt;However this is not a good user experience. The documents attached to the Record, and latest data, are only visible via the Record. I am wondering if there is a better way? Perhaps should all app users be allowed to view the Record and then put security on each Process Instance resulting in them only being able to their Records their allowed? &lt;br /&gt;&lt;br /&gt;In other words, what is the best security architecture to allow users identified at process run-time to see only the Records they are participating in the process and no other records for the same process model?&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;Gregg&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>