Constellio

You write the rule.Everyone sees their own version.

Rights are defined once, by role, and apply everywhere: the same search, the same folder, the same tree do not produce the same screen depending on who is looking. With no separate copy and no “confidential” folder off to one side.

  • Control by role, not by person
  • Rights inherited from the classification plan
  • Multi-factor authentication
  • Rio Tinto
  • Ville de Montréal
  • Université Laval
  • Bibliothèque et Archives nationales du Québec
  • Hydro-Québec
  • CDPQ
  • Barreau du Québec
  • Ville de Longueuil

HOW IT WORKS

One rule. One screen per person.
There is nothing in between.

Access management comes down to two moves: writing what a role is allowed to do, and seeing what that produces. Everything else (inheritance, exceptions, multi-factor, the log) exists so those two moves stay true over time.

  1. 01 The role

    You set one role, not two hundred accounts.

    Each role gets what it can do: read, upload, edit, share, delete. People join a role, and a departure or a transfer doesn’t mean going back over every record.

    • Centralized rights management
    • Role-based access control
    • Inheritance from the classification plan
  2. 02 The view

    And here is what that produces on screen.

    The same folder does not present itself the same way to every role: what isn’t permitted doesn’t appear, sensitive fields are masked, and buttons that don’t apply simply aren’t there.

    • What isn’t allowed doesn’t appear
    • Sensitive fields masked rather than offered
    • Search results filtered at the source

A document invisible to a role is invisible in search, in lists and in reports too: it doesn’t appear only to vanish afterwards.

ONE RULE, SEEN FROM FOUR SIDES

The same folder,
four different screens.

Follow a rule from the moment it is written to what it produces. At the third step the console changes eyes: you are no longer the administrator but a records clerk, and the folder is not the same one.

  1. 01The role

    What the role is allowed to do.

    The rights editor puts roles against actions. A ticked box holds for everybody in that role, today and on every arrival. Management happens at the role, never account by account.

    • Roles set against permitted actions
    • One rule for everybody in the role
    • Arrivals and departures without touching records
  2. 02Inheritance

    The rule runs down the tree.

    A right is set on a heading of the classification plan and holds for everything below it. An exception is set in the same place, on one branch only, and stays visible as an exception.

    • Rights set on a heading of the plan
    • Inherited by everything filed under it
    • One-off exceptions, visible as such
  3. 03The view

    The console changes eyes.

    We move from the administrator to a records clerk. The folder loses eight items, two fields mask themselves, and the external share button disappears. Nothing was moved: it is the same repository, seen from elsewhere.

    • Items not permitted absent from the list
    • Sensitive fields masked
    • Forbidden actions removed from the interface
  4. 04The trace

    Who opened what, and who was refused.

    Signing in goes through a second factor, and every view and every refusal leaves a dated line. This log is what answers when an auditor asks who had access to what.

    • Multi-factor authentication at sign-in
    • Views and refusals both recorded
    • A log an auditor can actually work from

REAL-WORLD USE CASES

The file three people
are allowed to open.

Two organizations with the same problem for opposite reasons: one has to restrict very finely, the other has to prove who looked at what. The same rule serves both.

Colleagues meeting in the offices of a financial institution

For the financial sector

Restrict without building a separate system.

Sensitive documents stay in the same repository as everything else: only authorized employees can view and edit them. For everyone else they do not exist, not in the folders and not in the search results.

See data security
A municipal building photographed from outside

For public organizations

Centralize rights, and be able to show it.

By bringing rights management into one place, an organization stops depending on settings scattered across several systems. And because every view and every refusal is recorded, traceability isn’t reconstructed after the fact.

See compliance management

What access management covers

  • Centralized rights management
  • Role-based access control
  • Multi-factor authentication
  • Audit and tracking logs
  • Integration with third-party solutions
  • Customizable interface

Set at the role, applied everywhere

WHO CAN SEE WHAT

The whole access policy
fits in one table.

The other diagrams on this site tell a journey. This one tells none: it is a lookup table. A role, a heading, and the answer is at the intersection, which is exactly what the system does on every screen it draws.

ROLESHEADINGSQuotes312Contracts340HR files510Complaints318Records clerk24 peopleManager9 peopleManagement4 peopleExternal partner12 peopleWHAT APPLIES OVER THE TOPInheritancefrom the classification planExceptionon one branch onlyMulti-factorat sign-in
Legend Read and write Read only No access

Centralized management

Rights are set in one place for the whole platform, instead of being spread across as many consoles as there are systems.

Multi-factor authentication

A second factor at sign-in, so that losing a password isn’t losing an access.

Third-party integration

Roles can come from your existing directory: Constellio’s rights line up with the organization instead of duplicating it.

See data security

OUR KEY FIGURES

Fewer open doors.
Fewer files kept off to one side.

When rights are hard to set, people work around them: a folder reserved here, a copy emailed there. Every one of those workarounds is an access nobody is watching any more.

Figures published by Constellio
01

0

Reduction in search time

02

0

Reduction in search costs

03

0

Reduction in security incidents

Why choose Constellio

Security

Protection of your data is strengthened by controlling precisely who reaches what in your information system.

Flexibility

Rights adapt to the needs and the role of each person, without reorganizing the repository on every change.

Compliance

Audit logs demonstrate that data protection regulations are being met rather than asserting it.

Efficiency

One centralized console replaces scattered settings, and an arrival is handled by adding a person to a role.

Organizations running on Constellio

  • Rio Tinto
  • Ville de Montréal
  • Université Laval
  • Bibliothèque et Archives nationales du Québec
  • Hydro-Québec
  • CDPQ
  • Barreau du Québec
  • Ville de Longueuil

YOUR ACCESS POLICY

Unlock the potential
of your content.

Book a demo and bring your org chart. We turn it into roles, set them on your classification plan, and you look at the same folder from three different desks.

Or write to contact@constellio.com. Open source at its core, hosted the way you want it.