I am new to using OLS and now have to implement security within a package application that uses OLS. User screens have been provided with which to setup the label policy components and data labels. Screens are also provided with which to assign the data labels to the securable objects within the application.
The user maintenance screen provides a means to mark the users access to each of the components within the policy.
The application allows me to give the user access to combinations of components that do not exist as a valid data label combination.
Can anyone tell me if this is correct or should all combinations exist as a label?
My instinct says no they do not have to exist as a label, only the object accesses must exist as a valid label.
I would investigate further by checking the data in the appropriate LBAC Sys tables but this is not possible at the moment nor are the applications developers available to assist. Thanks.