You are here: Reference > Rule types > Access of Role to Object > Specifying privileges for an Access of Role to Object rule

Specifying privileges for an Access of Role to Object rule

To more precisely define access to instances of a class, you update the Access of Role to Object rule to grant or revoke privileges for a role and access class.

You can make these updates by using Access Manager or the Access of Role to Object rule form. The production level values that you can specify are different on these two forms. For more information on Access Manager, see Access Manager landing page.

A privilege associated with an Access of Role to Object rule is granted to users who have the access role, when they work with instances of the rule's access class (or child class), on a system that has a specific production level (or lower).

To update a rule:

  1. In the Explorer panel, click Records > Security > Access of Role to Object, open the rule you want to change, and click the Privileges tab.
  2. In the Privilege field, enter the name of the privilege to grant to this role. The privilege must already be defined for this access class.
  3. In the Level field, enter a When rule name or a production level. At run time, the system evaluates this value in the following ways:

After you save the Access of Role to Object rule form, active requestor sessions on the current node are immediately updated. Requestors on other nodes in a cluster are updated when the next system pulse occurs on their nodes.