Access tags carry eight named rights, settable separately for models and for instances. Every action a person, a connector or an AI agent takes is recorded against the item it touched. External auditors and suppliers get exactly the slice you granted, and nothing else.
A role tells you what someone is called. A resolution rule tells you exactly which right is checked, on which object, before an action goes through. That difference is the whole security review: one is a promise, the other is something you can audit line by line.
An access tag is a label on an item or a model, and it carries the rights a group or a user holds over whatever wears it. The pairing that matters in practice: a team can be allowed to edit a model without being allowed to edit the items built from it, or the reverse.
That is the question an EN 9100 surveillance auditor asks, and the reason the activity log exists. Every modification to an unlocked item is recorded chronologically with the user, the timestamp and the old and new values. No email archaeology, no spreadsheet reconstruction.
Add an external user to an access tag and it becomes a shared tag: they see exactly what wears it. Koddex confirms before adding anyone outside your organisation, and confirms again before granting them write access. Shared tags and external members are visibly marked with their organisation.
For every action, the documentation spells out exactly which rights are checked and against what. You do not infer what a role allows; you read it.
These are the numbers that come up when an IT security reviewer sits down with the model, rather than the ones that look good on a slide.
view, edit, use model, view history, manage revisions, set access tag, share and lock. Nothing implicit, nothing bundled.
One documented rule per action, stating which right is checked and whether it applies to the model or the instance.
Every right but view and use model splits in two, so editing a template and editing its items are different decisions.