<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on psLens</title><link>https://pslens.com/docs/security/</link><description>Recent content in Security on psLens</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://pslens.com/docs/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Permission Lists</title><link>https://pslens.com/docs/security/permission-lists/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pslens.com/docs/security/permission-lists/</guid><description>&lt;h2 id="permission-lists"&gt;Permission Lists&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;URL:&lt;/strong&gt; &lt;code&gt;/permissionlists&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Permission lists (PSCLASSDEFN, sometimes called classes) are the lowest-level grantable security object. Every menu, component, page, and function authorization attaches to one.&lt;/p&gt;
&lt;h3 id="what-you-can-do"&gt;What You Can Do&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;View Full Definitions:&lt;/strong&gt; See description, last modified information, and general settings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;View Authorizations:&lt;/strong&gt; See which menus and components the permission list authorizes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;View Assigned Roles:&lt;/strong&gt; See which roles include this permission list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sign-on Settings:&lt;/strong&gt; View allowed sign-on times and other access constraints.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="when-its-useful"&gt;When It&amp;rsquo;s Useful&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Auditing what access a particular permission list grants before assigning it.&lt;/li&gt;
&lt;li&gt;Incident response: what could a compromised permission list have touched.&lt;/li&gt;
&lt;li&gt;Finding permission lists that are overly broad (see also the &lt;a href="https://pslens.com/docs/reports/security/security-full-access/"&gt;Full Access Permission Lists report&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Roles</title><link>https://pslens.com/docs/security/roles/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pslens.com/docs/security/roles/</guid><description>&lt;h2 id="roles"&gt;Roles&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;URL:&lt;/strong&gt; &lt;code&gt;/roles&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Roles (PSROLEDEFN) are named bundles of permission lists. Users get roles, not permission lists directly.&lt;/p&gt;
&lt;h3 id="what-you-can-do"&gt;What You Can Do&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;View Included Permission Lists:&lt;/strong&gt; See the list of permission lists assigned to the role.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;View Assigned Users:&lt;/strong&gt; See which users are assigned this role.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Metadata Inspection:&lt;/strong&gt; See the role&amp;rsquo;s description and last modified information.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="when-its-useful"&gt;When It&amp;rsquo;s Useful&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Understanding what an unfamiliar role grants.&lt;/li&gt;
&lt;li&gt;Checking whether a role contains permission lists that are unexpectedly broad.&lt;/li&gt;
&lt;li&gt;Finding all users who have a particular role.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Users</title><link>https://pslens.com/docs/security/users/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pslens.com/docs/security/users/</guid><description>&lt;h2 id="users"&gt;Users&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;URL:&lt;/strong&gt; &lt;code&gt;/users&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Users (PSOPRDEFN, historically called operators) are login accounts. Each carries a set of roles, a primary permission list, a row-security permission list, and a process profile. Search supports both OPRID and name.&lt;/p&gt;
&lt;h3 id="what-you-can-do"&gt;What You Can Do&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;View Assigned Roles:&lt;/strong&gt; See the roles assigned to a user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Core Security Attributes:&lt;/strong&gt; See primary permission list, row security permission list, and process profile.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Account Metadata:&lt;/strong&gt; View account status (active/inactive), last login, and email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Password Settings:&lt;/strong&gt; See password-related settings (whether a password is set, when it expires).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="when-its-useful"&gt;When It&amp;rsquo;s Useful&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Checking what access a specific user has.&lt;/li&gt;
&lt;li&gt;Reviewing user accounts during security audits.&lt;/li&gt;
&lt;li&gt;Finding accounts that are inactive but still have broad role assignments.&lt;/li&gt;
&lt;li&gt;Investigating who has access to a sensitive area of the system.&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>