Associating access roles, privileges, and classes
Access role obj rules (rules of type Rule-Access-Role-Obj) associate access roles with the classes to which they provide access and with any relevant privileges or access settings. When
you create a new access role, you must associate it with the appropriate classes using the procedure in this section or using the Role Editor.
When you associate an access role or privilege with a class, you not only associate the names of the rules but you also specify the level of access a role or privilege has to a class or the conditions under which the role or privilege can access the class. This process allows for an extremely flexible and powerful way of defining class-based security.
Previous topic Controlling access to individual rules using privileges Next topic Understanding access role obj rules