πŸ“‹ Group Management: Configuring Permissions, Licenses, and Priority Rules

Administrators learn here how permissions and licenses are managed via groups, which logic applies to assignments (cumulative, priority, dominant), and which group settings are available.

Managing groups and permissions

In FTAPI, permissions and licenses are managed via groups. Every user must belong to at least one group.

Basics of group management

Under Administration > Groups, you can create an unlimited number of custom groups. For each group, specific rights and licenses for products such as SecuMails or SecuRooms can be enabled. Assigning a user to one or more groups can be done either directly when creating the user or at any time later via their user profile.

Handling multiple groups per user

A user can be a member of several groups simultaneously. The resulting permissions are combined according to fixed rules:

  • Cumulative: The permissions are added together.   
    Example: If the file extension *.zip is blocked in Group A and the extension *.exe is blocked in Group B, a member of both groups is not allowed to send either of these file types.
  • Priority: The setting of the group with the highest rank (for 1 and 2, this is 1) applies. The rank is a number that determines the precedence of a group in case of conflicting settings. (see screenshot, to the right of the group)  
    Example: Group A has rank 2 and user account cleanup is deactivated. Group B has rank 4 and cleanup is activated. For a member of both groups, cleanup is deactivated, as Group B has the higher rank and its setting therefore takes precedence.
  • Dominant: Here, the higher value is always chosen, which provides the user with more resources, regardless of the group's rank.   
    Example: If Group A grants 200 MB of storage and Group B grants 500 MB, a member of both groups will have 500 MB available.

Important group-specific settings

Within each group, you can make detailed settings to precisely control the use of FTAPI:

  • Features: Determine which FTAPI products (e.g., SubmitBox, SecuRooms) and functions are available to group members.
  • Restrictions: Define technical limits, such as the maximum size for file attachments or the total available storage per user.
  • Cleanup: Set up automatic routines for deactivating or deleting inactive user accounts or expired deliveries.
  • Security levels: Restrict which security levels are available for sending deliveries or for SubmitBox submissions.
  • Two-factor authentication (2FA): Enforce the use of 2FA (via app or SMS) for all members of a specific group to increase login security.

Related articles

πŸ“‹ User management: Creating user accounts manually, automatically, or via AD