<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Difference in process model security and user security smart service.</title><link>https://community.appian.com/discussions/f/process/19212/difference-in-process-model-security-and-user-security-smart-service</link><description>Hi All, 
 
 We have different methods to set security for a particular process model. From designer we can set the security while creation of any process model. We also have a smart service , Modify process security &amp;#39; for that . 
 I wish to know the difference</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Difference in process model security and user security smart service.</title><link>https://community.appian.com/thread/75240?ContentTypeID=1</link><pubDate>Tue, 07 Jul 2020 12:51:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:dc6da17a-bd90-4b88-a417-041c33a33c9c</guid><dc:creator>Peter Lewis</dc:creator><description>&lt;p&gt;These two methods provide security in different ways. It&amp;#39;s&amp;nbsp;&lt;em&gt;always&lt;/em&gt; necessary to provide security on the process model object because this determines which users are able to start the process. Then, once a process instance is started, the instance will inherit all of the security roles provided on the process model. The Modify Process Security is used to change only a certain instance of a process, and it can be used to allow different access for different process instances.&lt;/p&gt;
&lt;p&gt;It usually helps the most by providing an example. Suppose you have a process where any user can open a support case. Since all users should have access, you should make sure that All Users have at least initiator access on the process model to be able to start it. However, suppose that you created a process-backed record that displays data about the case. For some cases, you&amp;#39;d like to limit access so that only certain users can view this record. If you only use the default security provided at the process model level, all users would be able to view all cases. The Modify Process Security allows you to change an active instance of a process to change what security applies to that instance.&lt;/p&gt;
&lt;p&gt;The Modify User Security smart service is unrelated to process security - it only updates the user rolemap and likely does not apply to this discussion.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>