Statement properties reference
Overview
To create an access control statement, you define its precise scope using the following four properties:
- Effect
The effect the statement has when it applies to an access request, that is, whether the statement allows or denies access.
- Resource
The type of object that the user is requesting to perform the action on, such as an activity type.
- Action
The operation that the user is requesting to perform on the resource, for example view, create, etc.
- Conditions
Additional conditions to define the resource with greater granularity, based on activity attribute values (such as activities where a specified activity attribute has a particular value), or further specifying the resource type.
To put access control statements into effect, you use an additional property that is linked not to the individual statements, but the policy that contains them:
- Users
The Uptempo user accounts to which the statements in the policy apply. Can be specified either individually, or as part of a team.
Each of these five properties is further organized into types, or subcategories with a specific scope. For example, the Actions object contains types like View or Create.
In practice, you construct an access control statement by using the Statement Editor or the Raw JSON editor to select a type for each property: in combination, these types define a complete permissions scope.
This reference guide outlines all the available types for each property that you can use to create access control statements.
Effect
The Effect property defines the outcome that the access control system applies when a statement takes effect.
Supported types
- ALLOW
Specifies that the access control system permits access within the scope of the statement. This means the specified user is granted permission to perform the specified action on the specified resource, and if the specified conditions (if present) are met.
- DENY
Specifies that the access control system blocks access within the scope of the statement. This means the specified user is denied permission to perform the specified action on the specified resource, and if the specified conditions (if present) are met.
Resource
The Resource property defines the type of system asset that a User can perform an Action on.
Supported types
- Activity
Scopes the statement to all activities (of all types).
In combination with the Conditions property, can be specified as:
Activities of a specified activity type
Activities of a specified activity type group
Activities that have a specified value for a specified attribute
- Activity type
Scopes the statement to all activity types and activity type groups.
For each activity type, this scope includes:
The attributes that exist on activities of that type.
The actions that are possible for activities of that type.
The activity rules that govern where activities of that type can exist in the activity hierarchy.
The layout of the activity setup assistant and the details panel for activities of that type.
- Attribute
Scopes the statement to activity attributes and their values.
Action
The Action property defines the types of operation that a User can perform on a Resource.
Supported types
Actions are specific to resource types, so the supported actions are determined by the selected resource.
Resource Type: Activity
- All Actions
Scopes the statement to all possible actions on the specified resource, including view, create, modify, and delete.
- List
Scopes the statement to only the List action. When granted, the List action gives users only access to the name of the specified resource. This means the user can see an activity's full name in the Activity Hierarchy, but can't open the activity's details panel to view any other information about the activity.
- View
Scopes the statement to only the View action. When granted, the View action gives users read-only access to the specified resource. This means the user can see an activity's full name, attribute details, etc., but is not able to modify the activity in any way.
- Set Activity As Child Of
Scopes the statement to only the Set Activity As Child Of action. When granted, the Set Activity As Child Of action gives a user the ability to create child activities under the resource scoped in the statement.
Resource Type: Activity Type / Activity Type Group
- All Actions
Scopes the statement to all possible actions on the specified resource, including view, create, modify, and delete.
- View
Scopes the statement to only the View action. When granted, the View action gives users read-only access to the specified resource. This means the user can see activity types or type groups, but not create them.
- Create
Scopes the statement to only the Create action. When granted, the Create action gives users the ability to create new activities in an activity type.
Resource Type: Attribute
- Set Value
Scopes the statement to only the Set Value action. When granted, the Set Value action gives users the ability to input, modify, or clear the data within the specified attribute field(s) on an activity.
Conditions
The Conditions property defines more granular conditions for the Activity resource type, which must be met for the statement to take effect.
Supported types
- Attribute Values
Scopes the statement to only activities which have a specified value (or one of a set of specified values) for a specified attribute.
- Activity Type
Scopes the statement to only activities of a specified activity type.
- Activity Type Group
Scopes the statement to only activities from any activity type within a specified activity type group.
Users
The Users object defines the type of entity that can perform an Action on a Resource.
Supported types
- Users
Scopes all statements in the policy to specific individual Uptempo user accounts used by human users.
- Teams
Scopes all statements in the policy to specific predefined groups containing multiple Uptempo user accounts.