Permission Settings
Similar to AI agents, users can also set granular user permissions for the library.
Object Type
Set the object type for permission control:
- User: Set permissions for an individual user.
- User Group: Set permissions for a user group.
Select Object
Set the specific object that needs to be authorized.
- When the object type is set to User, you must add the required user by entering their complete user ID, login ID, or unified identity authentication ID.
- When the object type is set to User Group, you can add the corresponding user group from the dropdown list (you can only see user groups you have created or publicly available user groups).
Permission Type
Set the specific type of authorization:
- Allow: Allow the selected user and permissions.
- Deny: Deny the selected user and permissions.
⚠️ Note: According to the principle of least privilege, the deny permission always takes precedence. This means that if a user is allowed a certain permission in one user group but denied the same permission in another user group, the user will ultimately not have that permission.
Permissions
Set the specific user permissions here:
- Read: The user can view the documents and settings of this library.
- Write: The user can view, modify the settings of this library, delete or add library files, or modify individual library file settings.
- Delete: The user can view, modify, and delete this library.
⚠️ Note: Deleting includes modify permissions, and modifying includes view permissions.