Advanced Customization > Business Logic Customization > Customizing Security Labels > Customizing Security Labels > Specifying Authorized Participants for Custom Security Labels > Using a UFID to Specify the Authorized Participants
  
Using a UFID to Specify the Authorized Participants
When using only a UFID for the authorized participant, specifying a user-defined group to identify the authorized participants provides the most flexibility, as membership in the group can be modified as needed using the Participant Administration utility, the Organizations > Groups page, or a third party LDAP tool to manage groups within an LDAP directory service. If a group is used as the authorized participant for a custom security label, the membership of the group can include other groups. Users who are not authorized participants for any value of the custom security label are denied access to objects with that label value applied, unless they are specifically granted temporary clearance to the value by being in the authorized participants set for an agreement. Being authorized for one security label does not automatically authorize a user for any other security label. Users must be cleared for all security labels that are set on an object to be able to access the object.
For example, a site might have a system outside of Windchill that tracks whether a user has completed ITAR training. The ITAR Clearance security label value on the Export Control standard security label value is configured with a custom evaluator. The custom evaluator queries the external system to determine if the user has completed the training. The evaluator method returns false for a user who has completed the training (when Yes is returned by the external system) and the user is cleared for the security label value.