Understanding Custodian Change Policies
About Custodian Change Policies
About Custodians
In collaborative environments such as Max Platform, multiple custodians manage shared data. This means it is essential to provide clear rules to determine which users can modify, delete, link, or unlink records. Otherwise, there is a risk that data can be unintentionally altered or removed by custodians who are not responsible for the related records, leading to the following issues:
• Unusable features or functionality.
• Inconsistent or unauthorized changes.
• Conflicts between teams or departments.
• Nonfunctional relationships between records.
Custodian Change Policies ensure that operations on records respect the ownership established by their custodians. These policies enforce consistent and predictable rules that are based on custodian matching, so that data integrity is protected and updates, deletions, and modifications to relationships can be executed only by authorized custodians.
Max Platform provides a set of custodian-based access policies that determine user rights to update, delete, or deactivate records, and also to modify relationships between records. In all User Preferences records, the configured Default Custodian field value is used to evaluate permissions to make changes to records. If no Default Custodian value is configured, the value defined in the active System Setting record is used. Permission checks compare the configured Default Custodian value for each user to the Custodian value configured in records, and rules are enforced based on the configured Custodian Change Policy field value. These policies apply to records and to Multiple Relationships.
Custodian Change Policies for Records
All records have configured Custodian Change Policies that determine what users whose Default Custodian field values do not match the Custodian values in those records, as follows:
• No Restriction: All users can update, delete, or deactivate records.
• Cannot Delete: Only users with matching Default Custodian values can delete, and all other users can update and deactivate but not delete records.
• Cannot Delete or Deactivate: Only users with matching Default Custodian values can delete or deactivate, and all other users can update but not delete or deactivate records.
• Cannot Delete or Update: Only users with matching Default Custodian values can delete, deactivate, or update, and all other users cannot make delete, deactivate, or update records.
Custodian Change Policy for Relationships
All Multiple Relationship records have configured Custodian Change Policies for Relations that determine what users whose Default Custodian field values do not match the Custodian values in those records, as follows:
• No Restriction: Any users can link or unlink records in the Relationship.
• Cannot Link: Only users with matching Default Custodian values can link source records to target records, and all users can unlink existing Relationships.
• Cannot Unlink: Only users with Default Custodian values that match that of the user who originally linked two related records can unlink them, and all users can link records.
|
|
• The user who originally linked two related records is not visible in the record view, which means that when users with non-matching Default Custodian values try to unlink records, an error message appears and informs them that they cannot unlink the current relation.
• If the source record is deleted in the same transaction, any user can unlink records regardless of their Default Custodian value.
|
• Cannot Link or Unlink: Custodian validation is applied for both linking and unlinking in the same manner as for the Cannot Link and Cannot Unlink policies.
|
|
• In individual records, you can check the Custodian and Custodian Change Policy fields on the System Info tab. In Relationship records, the Custodian Change Policy for Relations field is also on the System Info tab.
• When the Custodian Change Policy or Custodian Change Policy for Relations field values are unspecified, the default policy is No Restriction.
• You cannot create new Custodian records, which means that the Custodian record named Default Custodian is always what is used for the Custodian field value in records.
|