Hi, I am very interested in how to control access to restricted documents in IFS, particularly ITAR. We are on IFS Version 10, UPD7 and use Active Directory Federation Services to connect users to their Active Directory accounts for login. We have multiple companies and sites across a number of countries. I am quite familiar with Document Access and Document Class Management using assigned person groups. However, the loophole is that a Document Control rep at one of our sites with access to Document Basic Data can inadvertently add a unauthorized person to a person group that is assigned to a restricted Document Class. I am also interested in the best approach in terms of the Doc Vault. We presently use Shared Files. Storing document files in the database is not feasible given the impact to system performance with the volume of documents in use across all of our sites. We are at the point of removing the restricted documents completely, storing the files in site specific file servers with server access controlled at the site level and using hyperlinks from a dummy document object to retrieve the restricted document file outside of the IFS Document Management module for those you are granted access at the server level.
Also is there a standard for moving obsoleted documents into a separate vault/server or deleting them?
Thanks,
Steve O’Steen