Standard Security Settings

This chapter describes the default security settings of the Kentico CMS (and Kentico CMS Desk). You can modify them according to your own security rules.

 

Default Resources and Related Permissions

 

Resource Names

Permission Names

CMS Administration

Create

Delete

Modify

Read

CMS Content

Check In any Document

Create

Delete

Destroy

Unfold Tree

Modify

Read

Manage Workflow

Modify Permissions

CMS Files

Create

Delete

Modify

Read

CMS Meta Designer

Create

Delete

Modify

Read

 

Default Document Templates and Related Permissions

 

All document templates recognize the following permission names:

 

 

Access Control of the Kentico CMS Desk

 

CMS Desk Section

Access Control

Content

The user needs the ExploreTree permission for access to this section.

 

ExploreTree permission is required for going through the tree hierarchy.

 

When creating, deleting, modifying or reading particular node, the user needs either Create, Delete, Modify or Read permission for the particular document template or Create, Delete, Modify or Read permission for the CMS Content module.

 

Check in any Document permission allows user to check in any document that has been checked out by any user. It's recommended that you grant administrators or content managers with this permission so that they can check in forgotten documents.

 

Destroy permission allows user to delete document including its history so that it cannot be restored. It's recommended that you grant only administrators or experienced users with this permission.

 

Manage Workflow permission allows you to approve or reject any document in any step. It's recommended that you grant administrators or content managers with this permission.

 

Modify Permissions permission allows you to modify the document-level permissions. It's recommended that you grant administrators and other power users with this permission.

 

Modify permission is also requested for adding or deleting relationships in the Content section.

Files

The user needs Create, Delete, Modify or Read permissions for the CMS Files module.

Administration

The user needs Create, Delete, Modify or Read permissions for the CMS Administration module.

Meta Designer

The user needs Create, Delete, Modify or Read permissions for the CMS Meta Designer module

 

 

Default Roles

 

Role

Description

CMS Administrators

Administrators are allowed to:

  • manage content

  • manage all files

  • manage roles, users and permission matrixes

  • read Meta Designer settings

CMS Developers

Developers are allowed to:

  • explore content

  • read administration settings

  • manage all Meta Designer settings

CMS Editors

Editors are allowed to:

  • manage all content

  • read files

CMS File Editors

File Editors are allowed to:

  • manage files

 

 

Default Permission Matrixes

 

CMS Administration

 

 

CMS Content

 

 

CMS Files

 

 

CMS Meta Designer