Sharing and access control
On the Istari Digital Platform, sharing, roles, optional infosec levels, and control tags work together so teams can collaborate while limiting who can view or change Resources and Systems. Sharing and roles decide who is included and what they can do. Infosec levels add a classification clearance. Control tags add need-to-know between each user and each Resource, and a Secure Connection uses those same tags to decide which Resources may pass to a partner.
Why does it matter?
- Least privilege: You can grant only the access someone needs (view vs. edit vs. manage permissions) instead of sharing everything broadly.
- Need-to-know: A control tag on a Resource limits that Resource to users whose accounts hold the tag, including people already shared on the Resource or its System.
- Partner boundary: Secure Connection rules use control tags to allow or block each Resource, and to write local tags onto what a partner sends you. Those local tags then decide who on your side can see the received Resource.
- Auditability: Access is explicit—who has which role and which tags is reflected in the product and APIs, which supports reviews and compliance workflows.
Sharing and roles
You share files and systems with people in your organization by assigning a role per person. In the sharing dialogs, you choose among Viewer (read-only), Editor (can edit and share within limits), Administrator (can manage roles up to a point), and Owner (full control including archive). Who can assign which role depends on your own role; for example, editors cannot promote others to Administrator.
See Understanding roles in the user guide for the role matrix and assignment rules.
Infosec levels
When your organization enables information security (infosec) levels, Resources and Systems carry a classification that limits who can view or change them based on each user's clearance. Levels appear throughout the Istari Digital web app and work together with sharing, roles, and control tags.
See Infosec levels for schemas, enforcement, and what users see. Task-oriented steps are in Information Security (Infosec) Levels, Infosec Levels (admin), and Enabling experimental infosec levels.
System Permission Inheritance
What is it?
When a user is given a role on a system (Viewer, Editor, Administrator, or Owner), that role automatically cascades to all models and artifacts tracked by the system.
Why does it matter?
Instead of sharing dozens of files one-by-one, you can share the system and all tracked resources become accessible. When you remove a user from the system, their cascaded access is also removed.
Key details
- Viewer on a system grants view on all tracked models and artifacts.
- Editor on a system grants view and edit on all tracked models and artifacts.
- Archive does not cascade — only direct Owners or Administrators on a resource can archive it.
- If a resource is tracked by multiple systems, the user retains access via any system they have a role on.
- Subsystem contents are not included in the cascade.
Learn more
Control Tag
What is it?
A control tag is a need-to-know and transfer control. Your organization defines the tag once, then assigns it to users and to Resources together. The platform compares the two whenever it decides whether a user can open a Resource. A Secure Connection (the Secure Connection Service) compares the tags on a Resource whenever it decides whether that Resource may cross to a partner.
In the Istari Digital web app the tag appears as a colored chip on the Resource and on the user. The color identifies which control it is. The assignment is what the platform enforces.
The two assignments work as a pair:
- On a Resource (a model or an artifact), the tag is a requirement. Opening the Resource requires that tag.
- On a user, the tag is the authorization that meets the requirement. An organization administrator assigns it. See Assign Control Tags to a User.
A role from sharing still decides what the user may do (view, edit, manage, or own). The tag check decides whether they may do it at all. The user needs the role and every control tag on the Resource. Holding a tag is the need-to-know half of that check; the role is what includes the user.
Why does it matter?
- Inside your organization, tagging a Resource limits it to the people who hold that tag. Teammates who have a role through a direct share or through system permission inheritance still need the tag on their accounts.
- On a Secure Connection, the tags decide what may pass and what the received copy requires:
- A sending connection's tag rules read the tags on each Resource and return Allow or Block. An allowed Resource can transfer. A blocked Resource stays in your organization. An allow check can also add, remove, or map tags on the copy that is sent.
- A receiving connection's transformation rules add a local tag, remove an incoming tag, or map an incoming tag to a local one. The tags left on the received Resource are need-to-know requirements. Permitted recipients have a role on arriving Resources, and they see a tagged Resource when an administrator has assigned them every tag it carries.
Key details
- Pair the assignments. Put the tag on each Resource that should require it, and put the same tag on each user who should meet it. The check is the combination of the two.
- Every tag is required. A Resource with several control tags opens only for a user who holds all of them. See Terminology.
- Sending connection. Each check looks at the Resource's tags — no tags, any of a set, all of a set, or any tag outside a set — and allows or blocks that Resource. Every matching check applies. One matching Block blocks the Resource.
- Receiving connection. A rule that adds or maps a tag on a received Resource changes who can see it. Assign the resulting tags to the users who should see the Resource, including permitted recipients of the connection. An incoming tag that no remove or map rule covers is skipped, and that Resource stays out of sync until a rule covers the tag.
How it connects to other concepts
- Sharing and roles: Roles are set in the Resource or System sharing flows. See Share a system.
- System permission inheritance: A role on a System cascades to tracked Resources. Each Resource's control tags still apply to that cascaded role.
- Secure Connections: Tag rules decide what may leave. Transformation rules rewrite tags on the way in. The tags on the received Resource still have to be on each user's account.
- Infosec levels: Classification is a separate check. When infosec is enabled, a user needs the role, the control tags, and a sufficient clearance. See Infosec levels.
Example
Your organization defines an ITAR control tag. An administrator assigns ITAR to the engineers on that program.
A model tracked by a shared System is tagged ITAR. People with a role on the System keep that role. They can open the model when their accounts also hold ITAR. To include another teammate, an administrator assigns ITAR to that user.
The same tag is the transfer control on a Secure Connection. The sending connection's tag rules allow a Resource tagged ITAR and block a Resource whose tags fail the rules. On the partner's receiving connection, a Map Control Tag rule maps the incoming ITAR tag to the partner's local tag, so the received copy requires that local tag. Permitted recipients of the connection have a view role on the copy. They see it after an administrator assigns them the local tag.
Learn more
- Control tags — view and assign tags on a Resource.
- Control Tags (Administrator Guide) — create the tags, then assign them to users.
- Tag Rules — allow or block each Resource on a sending connection.
- Transformations — rewrite tags on a receiving connection, then assign the local tags to users.
How to manage access and tags
User guide (UI):
- Sharing and access control — hub for sharing Resources, control tags, and infosec levels.
- Share a file — step-by-step sharing and roles on files.
- Systems guide — systems and sharing (see also Share a system).
- Branches — Create, switch, and edit System branches; commits and change requests.
Administrator guide:
- Control Tags — create tags and assign them to users.
- Secure Connections — tag rules that allow or block a Resource, and receiving rules that write local tags onto what arrives.
Python client (SDK):
- SDK setup — install and configure the Istari Digital Python client.
- Client reference — sharing and permissions (
create_access,update_access,remove_access,list_access, and related methods on the Istari Digital Python client). - Control tag APIs — define tags and assign them to users, models, and artifacts.