|
"Who
can do What to Whom, Where and When" is
the essence of Quadra's W5™
Security Access Management System.
W5™ offers a
comprehensive yet very versatile customization to any system
built using Expresso™, DataByLocation™ and W5™. Our enterprise
Single Sign-On (SSO) system, gives complete control to
operations (not programmers), allowing users with different
roles, one point of logging into the system via
username/password defining accessibility restrictions. The user
role dictates who has permissions to access what functions,
controlling which data sets belonging to which users in what
locations.
Access types are
defined as Create, Read, Update and Delete (CRUD)
permissions. W5™ security covers five core
Access Control (AC) areas as follows:
-
Who
The 1st W in W5™
is the Who needs access. The Who is
defined as the typical user of a system. System user
access is defined using either Groups or Roles or
both.
- a
Group
is made up of one or more system users.
- a
Role
consists of a list of access control definitions.
The combined list defines the functional role.
-
What
The 2nd W
in W5™
is the What is being accessed. The What
is divided into data and actions.
-
Data is the essence
of every system. W5™
data access control is made possible due
to the Expresso™
development technology and its abstract data types.
- Actions are developed complex
functions that manipulate data. Data manipulation
requires one or more of the CRUD permissions.
-
Whom
The 3rd W is the Whom. The Whom is
defined as the direct owner of the data being
accessed. As in Who, the Whom is also
classified by one individual or Groups,
Roles or both.
-
Where
The 4th W defines the Geographical Where. This is made only available
in conjunction with the use of
DataByLocation™
subsystem. Which gives developers access control by
location levels, an exact location or both.
-
When
The final W in W5™
is the When. The When permissions controls the date,
time and/or duration for which other permissions are
given.
W5™
offers a generic yet so versatile framework for
controlling all aspects of Security Access Control
and Management.
Please contact us for more details |