Friday, August 8, 2008

Sysadmin and Super User

Sysadmin

Create, alter, and drop users and groups
Create, modify, and delete system-level ACLs
Grant and revoke Create Type, Create Cabinet, and Create Group privileges
Create types, cabinets, and printers
Manipulate workflows or work items, regardless of ownership
Manage any object’s lifecycle
Set the a_full_text attribute

The Sysadmin privilege does not override object-level permissions

Super User

Perform all the functions of a user with Sysadmin privileges
Unlock objects in the repository
Modify or drop another user’s user-defined object type
Create subtypes that have no supertype
Register and unregister another user’s tables
Select from any underlying RDBMS table regardless of whether it is registered or not
Modify or remove another user’s groups or private ACLs
Create, modify, or remove system ACLs
Grant and revoke Superuser and Sysadmin privileges
Grant and revoke extended privileges
View audit trail entries

No comments: