Modifying Administrator Rights
When a new administrator is created in the database, he is automatically added to his own Security tab with the following access rights defined: Read Allow and Write Deny . Through this the newly created administrator is able to see himself in the console and to check his capabilities, for example, but he cannot make modifications to any of his settings.
When an administrator is to modify access rights to a specific object he must have the following capabilities and rights:
Capabilities
- View Administrators
- View Security
- Manage Security
- View Object Type
- Manage Object Type
Access Rights
- Read and write access on the object itself.
It is strongly recommended to not provide the general administrators with the possibility to modify their security settings, only the superadministrator should have this option. If administrators can modify their own settings they might gain access to objects, to which they should not.