Product · Governance

    Permissions engineers actually trust.

    Access tags carry eight named rights, settable separately for models and for instances. Every action a person, a connector or an AI agent takes is recorded against the item it touched. External auditors and suppliers get exactly the slice you granted, and nothing else.

    koddex · Access tag · QA-Regulatory
    RightModelInstance
    viewImplicit with any access tag
    editValues and metadata
    use modelCreate items from this model
    view historyRead the activity log
    manage revisionsView and create revisions
    set access tagApply this tag at creation
    shareAdd another access tag
    lockMake the item immutable
    Every right except view and use model is set independently for models and for instances.

    Most PLMs have roles. Koddex has resolution rules.

    A role tells you what someone is called. A resolution rule tells you exactly which right is checked, on which object, before an action goes through. That difference is the whole security review: one is a promise, the other is something you can audit line by line.

    Access tags

    Eight rights, and a separate answer for models and instances.

    An access tag is a label on an item or a model, and it carries the rights a group or a user holds over whatever wears it. The pairing that matters in practice: a team can be allowed to edit a model without being allowed to edit the items built from it, or the reverse.

    • Identities are members or service accounts; groups organise them; tags say what they can do
    • Roles govern who administers users, groups and tags, not what happens to the data
    • Bulk application checks the rule on every affected item and skips the ones you lack rights on
    koddex · Identities and tags
    Members
    Service accounts
    Groups
    Access tags
    Activity history

    Who changed the acceptance criteria, and when.

    That is the question an EN 9100 surveillance auditor asks, and the reason the activity log exists. Every modification to an unlocked item is recorded chronologically with the user, the timestamp and the old and new values. No email archaeology, no spreadsheet reconstruction.

    • Reading the log is itself a right, so history is not visible to everyone by default
    • Removed items live on in the activity history of what they were removed from, and can be restored
    • Connector and agent actions land in the same log as human edits, with the permissions they ran under
    Lock and revise
    koddex · Activity · TR-4421
    a.chen@editedAcceptance criteria · 4.2 → 4.5 bar14:32
    m.laurent@approvedTest Report TR-442114:28
    ci-bot@linkedTR-4421 → REQ-11814:15
    s.okafor@lockedBaseline B-1411:26
    External sharing

    Give an auditor the slice, not the file.

    Add an external user to an access tag and it becomes a shared tag: they see exactly what wears it. Koddex confirms before adding anyone outside your organisation, and confirms again before granting them write access. Shared tags and external members are visibly marked with their organisation.

    • Only access-tag or group administrators can bring an external user in
    • Add them one by one, or in bulk from a CSV of email addresses
    • External users are visible to you only on items you can already see yourself
    Audit-ready traceability
    koddex · Shared access tag
    MLM. LaurentQuality Managerinternal
    ACA. ChenSystems Engineerinternal
    PNP. NadeauExternal auditorBureauCert
    SOS. OkaforSupplierPolyMed SA
    Koddex asks for confirmation on every external addition, and again before granting write access.

    Twelve resolution rules, written down.

    For every action, the documentation spells out exactly which rights are checked and against what. You do not infer what a role allows; you read it.

    1Viewing an item
    2Editing an item
    3Creating a new item
    4Changing access tags on an item
    5Viewing revision history
    6Creating a revision
    7Viewing activity history
    8Viewing and assigning users
    9Extending a model
    10Editing a model used by other models
    11Locking an item
    12Commenting on an item

    What a security review actually asks for.

    These are the numbers that come up when an IT security reviewer sits down with the model, rather than the ones that look good on a slide.

    Named rights per access tag

    view, edit, use model, view history, manage revisions, set access tag, share and lock. Nothing implicit, nothing bundled.

    8
    Rights, individually granted

    Resolution rules you can read

    One documented rule per action, stating which right is checked and whether it applies to the model or the instance.

    12
    Documented resolution rules

    Separate answers for model and instance

    Every right but view and use model splits in two, so editing a template and editing its items are different decisions.

    2
    Permission planes per right

    Frequently asked questions

    Bring your security reviewer to the call.

    We go through the access tags, the twelve resolution rules and the activity log on a live workspace. It is the fastest way to find out whether the model fits your policy.