What are Access Deny rules in Pega

An Access Deny rule is Pega's way of saying "no, whatever else you have been granted." It takes away a right on a class, and it always wins over an access grant. That single fact is the most common interview question about it.

How it fits with the other access rules

  • Access of Role to Object (ARO) grants rights such as Open, Update, Delete or Run report for a class.
  • Access Deny removes rights for a class from a role.
  • When both apply to the same operator, the deny wins, even if another role grants the right.

Why use a deny at all?

You could simply not grant a right, but a deny is useful when rights come from several places at once:

  • A broad role inherited from a framework grants too much, and you cannot change the framework.
  • An operator belongs to several roles, and one of them must never be able to do something, such as delete.
  • You want a hard, visible "never" that another developer will not accidentally undo by adding a grant.

A worked example

A bank has two roles:

  • Bank:Clerk: ARO on the Customer class with Open and Update.
  • Bank:Auditor: ARO on the Customer class with Open, plus an Access Deny that removes Update and Delete.

An employee who is both a clerk and an auditor might expect to keep the clerk's Update right. They do not: the deny from the Auditor role wins, and the employee can only view Customer records. This is deliberate. An auditor must not be able to change the records they audit.

Setting one up

  1. Create an Access Deny rule for the class you want to protect.
  2. Name the role it applies to, and choose the actions to deny.
  3. Save it in the security ruleset and add it to the application's rulesets.
  4. Test by signing in as an operator who has both the granting and the denying role.

Tips

  • Document every deny. They are easy to forget and hard to find when a user says "I cannot edit this".
  • Prefer plain ARO changes when you own the role. Use a deny when you need the rule to override grants that come from elsewhere.
  • Use the Pega "Access Manager" or the rule-by-rule check to see what an operator can really do.

Try it yourself

This exact scenario is one of the hard questions on our Weekly Challenge. Also read Access of Role to Object and What is Pega RBAC?

No comments:

Post a Comment