Skip to main content
Version: 4.1 (2026 H2)

Profile sharing policies

Profile sharing policies share profiles automatically, instead of every user sharing their profile manually: e.g. so that a secretariat automatically gets access to the profiles of all employees of a department.

The policies are managed in the DataSourceAdminApp (Dashboard) under Settings → Profile Sharing Policies, per datasource.

How it works​

Active policies are evaluated when a profile is created: during the onboarding of new users (default profile) and for every further newly created profile. If the profile owner meets the policy's condition, a share to the policy's target is created automatically on the new profile.

  • Existing profiles are not covered retroactively. A newly created or changed policy only affects profiles created from then on. Saving an existing profile again does not trigger an evaluation either: for existing data there is only Apply policies now.
  • Existing shares are never overwritten: if a share to the target account already exists, granted manually or from an earlier policy run, it stays unchanged and the policy's permission levels have no effect. Policies only add missing shares, they never correct an existing one.
  • A deactivated policy (Active off) is no longer applied; shares that were already created remain in place.
  • If several policies target the same account, only one of them takes effect: policies are processed alphabetically by Name, and at most one share is created per target account, namely that of the alphabetically first matching policy. Neither is the highest permission level chosen nor are levels merged.

Organisation unit with write access​

When editing another person's profile, the organisation unit selection follows the profile owner's permissions, not those of the editor. In primedocs Desktop, this assignment requires a connection to the primedocs server and is not available in offline mode. Write access does not extend the owner's permitted organisation units.

Properties of a policy​

PropertyDescription
Name (required)Name of the policy (max. 256 characters). With several policies targeting the same account, it decides which one takes effect.
Description (optional)Description.
ActiveOnly active policies are applied. Deleting is only possible while the policy is deactivated: the Delete button appears only then.
Sharing Target (SID) (required)Who the profile is shared with: a user or a group (by SID). The account must already be known to primedocs in this datasource.
Condition (SID) (optional)Condition on the profile owner: the share is only created if the owner is a member of the specified group. Without a condition, the policy applies to all users.
ProfilePermissionLevelHow the shared profile may be used: 0 = not usable as a regular profile, 1 = usable with an "on behalf" marker, 2 = fully assuming the identity.
SignatureProfilePermissionLevelUse as a second signature: 0 = not allowed, 1 = without the signature image, 2 = with the signature image.
AccessPermissionLevelRead-only (default) or Read & write: with write access, the authorised person may edit the profile (data fields, signatures, organizational unit). Write access only allows editing; whether the profile may also be used is determined by the other two levels.

At least one of the three permission levels must be set; if all three are 0, the policy cannot be saved.

note

The same permission levels can also be set per individual share via the Admin API (profilePermissionLevel, signaturePermissionLevel, accessPermissionLevel).

The condition​

A policy has exactly one condition: the profile owner's membership of a group. Conditions cannot be combined: there is no AND/OR, no second criterion and no condition editor. To cover several cases, create several policies.

When the condition is evaluated:

  • The profile owner's own SID and all of their group SIDs are checked. Memberships through nested groups therefore count as well.
  • SIDs are compared case-insensitively.
  • Without a condition, the policy applies to all users.

The condition always concerns the profile owner, never the person the profile is shared with.

What a condition actually looks like​

The condition is not an expression and not a formula. It is a single input field, Condition (SID), into which the SID of one group is entered. There is nothing more to enter.

Example: the legal department's secretariat should automatically get access to the profiles of everyone in that department.

Field in the editorValue
NameLegal secretariat
Sharing Target (SID)S-1-5-21-1234567890-987654321-1122334455-4001 — group «Legal secretariat»
Condition (SID)S-1-5-21-1234567890-987654321-1122334455-3007 — group «Legal department»
ProfilePermissionLevelShared with OnBehalf Note

Read out, this means: if the owner of a profile is a member of the «Legal department» group, that profile is automatically shared with the «Legal secretariat» group, usable with an "on behalf" marker.

If Condition (SID) is left empty, the check is skipped and the policy applies to all profiles in the datasource.

If the finance secretariat should additionally get access to the finance department's profiles, that becomes a second policy with a different condition, not an extended first one.

Finding the SID​

Enter the SID of the security principal from the directory service, in the usual Active Directory notation S-1-5-21-….

The SID must belong to an account that primedocs already knows in this datasource. Otherwise the policy cannot be saved and the editor reports The conditionIsMemberOfSecurityAccountAsSid field is invalid. A group that was never taken over through provisioning (e.g. SCIM) is therefore not available as a condition.

The SID is visible in two places in the dashboard:

  • Under SECURITY, open the account: the SID is shown next to the name.
  • In the list of policies: the ? badge next to the group name shows the SID as a tooltip, both in the Sharing Target and in the Condition Group (optional) column.

Applying and resetting policies​

On its own, a new or changed policy only affects profiles created from then on. For existing data, two actions are available under Settings → Profile Sharing Policies in the Policy actions section:

ActionEffect
Apply policies nowApplies all active policies once to all existing profiles. Missing shares are added, existing ones stay unchanged.
Remove profile shares based on policies (Reset)Removes all shares that were created by policies. Manually granted shares are kept.
caution

Reset works across the whole datasource and cannot be limited to individual policies: every share created by a policy is deleted. They can only be restored through Apply policies now, and only as far as the corresponding policies are still active and their conditions still apply.