ao link
Affino

System Security Rights

security centre
security centre

Overview

This guide lists in alphabetical order all of the System Security Rights. You can refer to this guide for a comprehensive list.

 

System Securities differ from Content Security Rights (Viewing Access) as the former exist permanently in the system, and are simply assigned on the basis of who can do what on an Affino Site. A Content Security Right may prevent you accessing content or structure, but say you wanted to actually interact or participate in some way - you would need some System Security Rights to enable that.

 

System Security Rights are split by 6 different User Types - from top to bottom:

  • Site Controller - We used to call this Webmaster or Web Manager, but ’Site Controller’ seems more suitable now, this Very Senior Admin who is responsible for the day-to-day running of the site, and has in effect the keys to the vault - ’Security’ as well as the ability to effect complete system updates via ’Affino Updater’, other sensitive Securities we advise be solely within the Site Controller domain, are ’Site Editor’ and ’Zone Moderator’. (4 Sensitive Rights)
  • Authorized Developer - Someone specially trained and Authorized by Affino to access System Management Functions - ’Developer’ and ’Web API’ Security Rights (2 Rights)
  • Senior Admin - Sensitive or Complex tasks which require delicacy and experience - Business Management, Campaign Management, Channel, Classic Design, Commerce, Community Manager, Contract, Design, Sales, Social Marketplace (12 Rights)
  • Admin - Various activities suitable for most personnel - typically control-side and display-side content and media upload and editing (53 Rights)
  • Advanced User -  Special Status End User - who gets access to more advanced forms of content, functions or analysis - Action Client, Action User, Campaign Statistics, Dashboard User (4 Rights)
  • User -  General End User - who is granted participation rights for key interaction, transaction and communication functions (17 Rights)

 

Securities : A - C : #1 to 23

Name

AreaFunctionUser Type
    
Action UserSocial > ForumsForum Task Manager Agent and Manager StatusAdvanced User
    
Affino UpdaterSettings > System UpdateAbility to Use Affino UpdaterSite Controller
    
Application Bar UserDisplay-side ControlEdit | Manage - Content, Media, Commerce and Design from the display-sideAdmin
    
ArchivePublishManage - Article ArchivingAdmin
    
BlogSocial > BlogsAbility to Post | Edit - Blog PostsUser
    
Business ManagementSocial > CRMAbility to Manage - Product Categories, Product Lines, Sales Teams, Business UnitsSenior Admin
    
Campaign ManagementPromote > Campaign ManagementManage - Advertising Campaigns and BannersSenior Admin
    
Campaign StatisticsPromote > Campaign ManagementView - Campaign StatisticsAdvanced User
    
ChannelStructure > ChannelAdd | Edit | Manage - ChannelsSenior Admin
    
CommentSocial > Comments ApprovalAdd | Edit | Manage - CommentsAdmin
    
Comment UserSocial > Comments & RatingsAbility to Post CommentsUser
    
CommerceCommerceAbility to Add | Edit | Manage All Ecommerce Elements, inc. Store Profile, Discounts, etc.Senior Admin
    
Commerce UserCommerceAbility to View Prices and Add to BasketUser
    
Community ManagerSocialAbility to Manage Community Elements - Accounts, Assign Badges, Contacts, CRM, External User Info, Group Profile, Live Users, Lookups, Most Recent Users, Personnel, Personnel Type, Related ContactSenior Admin
    
Community ModeratorSocialManage Community | Moderate User Activities - All Moderator Rights (Comments, Media Library Moderator)Admin
    
Contact ManagementSocial > CRMAdd, Change or Remove Contacts and Accounts and their AddressesAdmin
    
ContractSocial > CRMAbility to Manage - Bill Analysis, Bills, Contract Analysis, ContractsSenior Admin
    
ControlControlAccess to Core Control Functions, Control HomeALL Admin

Securities : D - L : #24 to 45

Name

AreaFunctionUser Type
    
DashboardAnalyse > DashboardAccess to View Control-Side DashboardAdmin
    
DesignResponsive Design CentreAdd | Manage - Design Objects, Skins, Templates, CSS etc.Senior Admin
    
DeveloperSystem | System ManagementDeveloper Access to Deep System Functions for Custom ApplicationsAuthorized Developer
    
Digital Asset ManagementMedia > Digital Asset ManagementMain Access to Media Centre, as well as access to Media Editor and advanced Media Library FunctionsAdmin
    
Document (deprecated)Publish > DocumentsAdd | Edit | Manage = DocumentsAdmin
    
Dynamic FormSocial > Dynamic FormsAdd | Edit | Manage - Dynamic FormsAdmin
    
Dynamic MessageSocial > Dynamic FormsAbility to access and receive form entries via notificationAdmin
    
EcardPromote > EcardAdd | Edit - EcardsAdmin
    
Edition DeletePublish > EditionDelete EditionsAdmin
    
Edition ManagementPublish > EditionAdd | Manage Editions and Edition Profiles. Run Edition ImportAdmin
    
EditorPublish + Social

Ability to view Control-side editorial screens, including: Analyse, Article Attribute, Article Export, Article Icon, Article Import, Article Profile, Article Type, Audit, Broken Links, Channel Analysis, Competitor Analysis, Content Analysis, Content Subscription Analysis, Content Subscriptions, Event Profile, Incoming Feeds, Media Subscription Analysis, My Messages Profile, Product Search Profile, Profanity Filter Settings, Regions, Region and City Export, Region and City Import, Related Profile, Related Profile, Restructure, Search Analysis, Search Profile, Search Settings, Search Update, Site Analysis, Site Tree, Spam Prevention Profile, Storage Analysis, To Do Lists, Un-used Content, Update, User Analysis, Webservice Profile

Admin
    
EventPublish > EventsAdd | Edit | Manage - Events and SeminarsAdmin
    
FinanceSocial > CRM / Commerce / AnalyseAccess Tax Period Summary Export, Tax Transactions Report, Sales Invoice Export, Deferred Income Report, Deferred Income Detail Report, Sage Audit Trail Export, Sage Customer List ExportSenior Admin
    
FlatplanPublish > FlatplansAbility to Create / Add FlatplansAdmin
    
Flatplan EditorPublish > FlatplansAbility to lay out and edit actual FlatplansAdmin
    
ForumSocial > ForumsAdd | Edit | Manage - ForumsAdmin
    
Forum UserSocial > ForumsAbility to Make Forum PostsUser
    
Full Text EditorPublishAccess to Full WYSIWYG Editing OptionsAdmin
    
ImageMedia > Design ImagesAbility to Upload | Edit - Design ImagesAdmin
    
InventoryCommerce > InventoryAbility to Manage | Update - InventoryAdmin
    
LegalSettings > Terms & Conditions Security > My Preferences Profiles & PermissionsAdd | Edit | Manage - Terms & Conditions, My Preferences Profile and Permissions. Run Preferences & Permissions Import and ExportAdmin

Securities : M - P : #46 to 69

Name

AreaFunctionUser Type
Media Library Bulk UploaderMedia > Media ItemsAbility to Use the Media UploaderAdmin
Media Library Moderator

Media

Abiity to Manipulate | Edit - Media Library Assets including Media Image Profiles, Media Library Profiles, Media Provider Profiles and Media Upload Profiles Admin
Media WorkflowMedia > Media Workflow ProfilesAbility to Manage Media WorkflowsAdmin
MessagingSocial > Message CampaignsAdd | Edit | Manage Message CampaignsAdmin
Meta DataPublish > MetaAdd | Edit | Manage | View - Meta DataAdmin
Multi-Zone UserSecurity > User (Multi-Site Licence)Enables Cross-domain Users - Means single User Account can straddle several ZoneUser
My Information UserSecurity > User (Publis Profile)Ability for Users to View and Access My Information Content and FunctionsUser
My MessagesSocial > My Messages Access to User Affino's On-site My Messages InboxUser
Non-securedDisplay-side AccessOpposite of what you might think - grants access to all unsecured display-side contentUser
Online DirectorySettings > Online DirectoryManage Directory Profiles and Directory Step ProfilesAdmin
Online FormSocial > Online FormAdd | Edit | Manage - Online FormsAdmin
Order ImportCommerce > Order ImportAbility to Import OrdersAdmin
Order ProcessingCommerce > Order ProcessingAbility to View | Manage from Order Processing Screen and receive Sales Notifications - Order Lists, Order Processing, Order Processing Line Item, Orders, Pro Forma OrdersAdmin
PaymentCommerce > Payment Gateways & MethodsAbility to Set Up | Manage Payment Gateways and view Payment DetailsAdmin
Personal DataSocial > CRMAccess to sensitive information such as passport informationAdmin
ProjectsSocial > CRMAbility to Add, Edit and Manage Projects and View Project AnalysisAdmin
PromotionPromoteAbility to Manage Promotion ElementsAdmin
PublishPublishAbility to Make Content 'Live'Admin
Publishing WorkflowPublish + SettingsAbility to Manage Publishing WorkflowsAdmin
Publishing Workflow UserPublish + SettingsAbility to Participate in Publishing WorkflowsUser

Securities : R - Z : #70 to 89

Name

AreaFunctionUser Type
    
Related Item Editor (deprecated)PublishAbility to Assign Any Related Content - Even Content which is beyond your Security ClearanceAdmin
    
SalesSocial > CRMAbility to Manage - Account Import, Account Merge, Accounts, Conversion Funnel Contacts, Conversion Funnels, CRM Analysis, Leads, Opportunities, Opportunity AnalysisSenior Admin
    
Sales AdministrationSocial > CRMAbility to View CRM Analysis, Order Line Item Report. and Sales Report screensAdmin
    
ScriptingPublish > ArticleAbility to use the Code field and add scriptsAdvanced User
    
SectionStructure > SectionsAdd | Edit | Manage - SectionsAdmin
    
SecuritySecurityVery High Level Access Management - System Security and User ProfilingSite Controller
    
SharePromoteManage | Add - Social Bookmarkers | Share to Social MediaAdmin
    
Site EditorSettings > Site SettingsAbility to Edit | Change Various High Level Site Settings; including: Email Profile, Email Settings, Google Analytics Profile, Redirect, Redirect Import, System Settings, ZoneSite Controller
    
Site ManagementSettings > Site SettingsAbility to Edit | Change Various High Level Site Settings; including: Google Maps Profile, Google Sitemap Profile, Google Tag Manager Profile, Recruitment Profile, SMS Provider, Data and Services Usage and Team Time Profile Site Controller
    
Standard ContentPublish > ArticlesAdd | Edit | Manage - ArticlesAdmin
    
Text ItemSettings > Text ItemsAbility to Edit Affino System Text Items / Text Screen PromptsAdmin
    
Topic ManagerPublish > Taxonomy and TopicsSet up and Manage Site Topics and Keywords and in a localized Taxonomy HierarchyAdmin
    
Web APISettings > SystemAbility to Manage APIs and API ProfilesAuthorized Developer
    
Zone ModeratorStructure > Zone (Multi-Site)Ability to Add and Delete Zone (Multi-Site Licence)Site Controller

Assigning System Security Rights

Several System Security Rights are grouped together with Several Content Security Rights - to grant Participation Rights, as well as Viewing Rights on Content and Functionality. These collected Rights are assigned to Security Groups, each one of which in turn manages access rights for a particular Site User Group or Audience Category.

 

Even though the User Types are split by 6 different 'User Types' you will find even more nuances in actual User / Security Groups.

 

As an example, you might split your staff by rank and ability - and both functional and area responsibilities for the Affino Site.

 

Larger Site can have all these different roles (Top - to - bottom)

  • Site Controller
  • Commercial Manager
  • Community Manager
  • Marketing / Promotional Manager
  • Editor in Chief
  • Art / Design Department
  • Editorial
  • Contributors

Affino has set up a number of Default Security Groups with approximate levels of Security Empowerment.

 

It is up to the Site Controller and or Community Manager to review and arrange all the different Access Rights for the different User Groups.

 

On smaller sites, much like with smaller businesses, there is a far higher degree of multi-tasking. And in some instance the whole site is managed by not even a handful of personnel.

 

 

Guidance & Troubleshooting

  • We recommend that for each and every level of Security Group - the Site Controller has a dummy account to access just those privileges. This is essential for ensuring the correct level of access
  • The Site Controller typically has all 78 System Security Rights, while those at the lowest rung would not be expected to have more than around a dozen
  • Backup accounts are also useful for Site Controller in case mistakes are made
  • As the Site Controller, make sure that new Security Rights are assigned across all necessary Security Groups - including the very top 'Site Controller' one, as it is quite common that Rights are assigned to lower down groups - Users etc. but overlooked for the admin staff
  • Be aware also that all Security in Affino is Session-based, which means that every time new Securities are Assigned - the Users of that group need to logout and log back in again to benefit from those new Securities!

Did you find this content useful?

Thank you for your input

Thank you for your feedback

Product Version

Version 9.0.7.4
VIEW

Driving business at some of the world's most forward thinking companies

Our Chosen Charity

Humanity Direct