<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://wiki.czechidm.com/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://wiki.czechidm.com/feed.php">
        <title>IdStory Identity Manager - devel:documentation:security:dev:authorization</title>
        <description></description>
        <link>https://wiki.czechidm.com/</link>
        <image rdf:resource="https://wiki.czechidm.com/_media/wiki/logo.png" />
       <dc:date>2026-05-02T13:41:14+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/evaluators?rev=1756824451&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/identity_evaluator_by_work_position?rev=1588871369&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/idmidentity?rev=1756981083&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/role_evaluator_by_role_catalogue?rev=1588832295&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://wiki.czechidm.com/_media/wiki/logo.png">
        <title>IdStory Identity Manager</title>
        <link>https://wiki.czechidm.com/</link>
        <url>https://wiki.czechidm.com/_media/wiki/logo.png</url>
    </image>
    <item rdf:about="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/evaluators?rev=1756824451&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-09-02T14:47:31+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Introduction</title>
        <link>https://wiki.czechidm.com/devel/documentation/security/dev/authorization/evaluators?rev=1756824451&amp;do=diff</link>
        <description>Introduction

Evaluators are used to provide permissions for database entities to users, they determine what any user can see and do in IdM. An user is assigned one or multiple roles and each role is assigned one or multiple authorization policies. Each authorization policy says &quot;for X kind of entity, give the user permissions A, B and C according to evaluator C&quot;. When resolving permissions, the user gets a given permission for a given entity if at least one authorization policy with that permis…</description>
    </item>
    <item rdf:about="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/identity_evaluator_by_work_position?rev=1588871369&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-05-07T17:09:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Identity by tree node evaluator</title>
        <link>https://wiki.czechidm.com/devel/documentation/security/dev/authorization/identity_evaluator_by_work_position?rev=1588871369&amp;do=diff</link>
        <description>Identity by tree node evaluator

The evaluator gives permissions for all identities that has contract position on selected tree node by evaluator configuration or positions that exists recursively under the given tree node.

Permissions and work position can be defined by frontend agenda.</description>
    </item>
    <item rdf:about="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/idmidentity?rev=1756981083&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-09-04T10:18:03+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Evaluators for IdMIdentity</title>
        <link>https://wiki.czechidm.com/devel/documentation/security/dev/authorization/idmidentity?rev=1756981083&amp;do=diff</link>
        <description>Evaluators for IdMIdentity

IdentityByTreeNodeEvaluator

@since 2.1.0

Evaluator that is given a tree node and provides permissions towards identities with contracts on this tree node or nodes below it.



If given the id of the tree node marked with the arrow as its parameter, this evaluator will give the user permissions to all the identities marked green.</description>
    </item>
    <item rdf:about="https://wiki.czechidm.com/devel/documentation/security/dev/authorization/role_evaluator_by_role_catalogue?rev=1588832295&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-05-07T06:18:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Role by role catalogue evaluator</title>
        <link>https://wiki.czechidm.com/devel/documentation/security/dev/authorization/role_evaluator_by_role_catalogue?rev=1588832295&amp;do=diff</link>
        <description>Role by role catalogue evaluator

The evaluator gives permissions for all roles that is inside defined catalogue or below.


at least in one role catalogue that is accessible
There is example of role catalogue and child's of the catalogue:</description>
    </item>
</rdf:RDF>
