Centralized management
Rights are set in one place for the whole platform, instead of being spread across as many consoles as there are systems.
Rights are defined once, by role, and apply everywhere: the same search, the same folder, the same tree do not produce the same screen depending on who is looking. With no separate copy and no “confidential” folder off to one side.
Inherited by 1,284 records
6 of 14 items visible
Hidden items don’t appear in search either
















HOW IT WORKS
Access management comes down to two moves: writing what a role is allowed to do, and seeing what that produces. Everything else (inheritance, exceptions, multi-factor, the log) exists so those two moves stay true over time.
Inherited by 1,284 records
Each role gets what it can do: read, upload, edit, share, delete. People join a role, and a departure or a transfer doesn’t mean going back over every record.
6 of 14 items visible
Hidden items don’t appear in search either
The same folder does not present itself the same way to every role: what isn’t permitted doesn’t appear, sensitive fields are masked, and buttons that don’t apply simply aren’t there.
A document invisible to a role is invisible in search, in lists and in reports too: it doesn’t appear only to vanish afterwards.
ONE RULE, SEEN FROM FOUR SIDES
Follow a rule from the moment it is written to what it produces. At the third step the console changes eyes: you are no longer the administrator but a records clerk, and the folder is not the same one.
The rights editor puts roles against actions. A ticked box holds for everybody in that role, today and on every arrival. Management happens at the role, never account by account.
A right is set on a heading of the classification plan and holds for everything below it. An exception is set in the same place, on one branch only, and stays visible as an exception.
We move from the administrator to a records clerk. The folder loses eight items, two fields mask themselves, and the external share button disappears. Nothing was moved: it is the same repository, seen from elsewhere.
Signing in goes through a second factor, and every view and every refusal leaves a dated line. This log is what answers when an auditor asks who had access to what.
Rights by role
Classification plan
External sharing · Removed: the role doesn’t allow it
REAL-WORLD USE CASES
Two organizations with the same problem for opposite reasons: one has to restrict very finely, the other has to prove who looked at what. The same rule serves both.

For the financial sector
Sensitive documents stay in the same repository as everything else: only authorized employees can view and edit them. For everyone else they do not exist, not in the folders and not in the search results.
See data security
For public organizations
By bringing rights management into one place, an organization stops depending on settings scattered across several systems. And because every view and every refusal is recorded, traceability isn’t reconstructed after the fact.
See compliance managementWhat access management covers
Set at the role, applied everywhere
WHO CAN SEE WHAT
The other diagrams on this site tell a journey. This one tells none: it is a lookup table. A role, a heading, and the answer is at the intersection, which is exactly what the system does on every screen it draws.
Rights are set in one place for the whole platform, instead of being spread across as many consoles as there are systems.
A second factor at sign-in, so that losing a password isn’t losing an access.
Roles can come from your existing directory: Constellio’s rights line up with the organization instead of duplicating it.
See data security ↗OUR KEY FIGURES
When rights are hard to set, people work around them: a folder reserved here, a copy emailed there. Every one of those workarounds is an access nobody is watching any more.
Figures published by Constellio ↗−0%
Reduction in search time
What gets through
−0%
Reduction in search costs
What gets through
−0%
Reduction in security incidents
What gets through
Why choose Constellio
Protection of your data is strengthened by controlling precisely who reaches what in your information system.
Rights adapt to the needs and the role of each person, without reorganizing the repository on every change.
Audit logs demonstrate that data protection regulations are being met rather than asserting it.
One centralized console replaces scattered settings, and an arrival is handled by adding a person to a role.
Organizations running on Constellio
















YOUR ACCESS POLICY
Book a demo and bring your org chart. We turn it into roles, set them on your classification plan, and you look at the same folder from three different desks.
Or write to contact@constellio.com. Open source at its core, hosted the way you want it.
