This article provides an overview of the RecordPoint permissions model and covers:

This guide is relevant for both RecordPoint on premises software and the Records365 service.

Roles and Groups

Standard RecordPoint Groups

For the RecordPoint site, four user groups are created as part of deployment. These groups are ranked in order, the lowest level access is granted to Record Visitor. A full description and default permissions for each group can be viewed through the UI under each user group. 

A custom SharePoint group created in RecordPoint can have security permissions granted. By default only the Record Administrator group has full access to stored records, this needs to be enabled for other user groups if required.

Custom Groups

RecordPoint also supports the use of custom groups to meet particular needs such as to define access to physical content types to manage security around physical records.

Limitations of Custom Groups

Please be aware of the following limitations when using Custom Groups.

  1. Custom Groups cannot be used to provide access to electronic records. Standard Groups should be used for this purpose.
  2. A SharePoint limitation means that custom groups cannot be added to other SharePoint groups.

Use of Active Directory Groups rather than individual users

In all cases we recommend the use of Active Directory Groups rather than placing individual users in either the standard or custom groups within RecordPoint.

Use of AD Groups minimizes the need to Update Permissions as new permissions do not need to the synchronized with the storage layer permissions within the RecordPoint.

Adding Users and Groups to Standard RecordPoint Groups

The use of Update Permissions can be an intensive task and should be scheduled out of hours.

In most cases using the Standard RecordPoint Security Group will be sufficient where:

RecordPoint supports the adding of users and groups to the above RecordPoint user groups. This includes the following types of users and groups:

Security is enabled by default in the RecordPoint Site.

  1. Navigate to Management and select Settings
  2. Under Users and Permissions, click Security Settings
  3. Select the records role to configure security settings for
    By default, the Records Administrator groups has access to all settings and full control of stored record data
  4. Update the required settings for this user group, then select the check box under description 'To allow the group access to all records in RecordPoint'. This provides access to the records store so the user can perform actions as per allocated permissions
  5. Click Submit to save
  6. On the Security configuration page
  7. Click Update Permissions to synchronise RecordPoint Users to all content sites

Providing access to electronic records

To provide access to electronic records:

  1. Add the relevant users or AD Group(s) to the RecordPoint Standard Group.
  2. Ensure that Record Access is ticked as this will push down permissions to view records onto the records held in the storage layer.
  3. Click Update Permissions which is at the bottom of the Security settings page.

Setting up a custom group

Custom groups are used where there is a requirement to manage physical records and to apply selective access to these records. They can also be used to provide, for example, IT Sysadmin staff with access to RecordPoint functions without any access to the records themselves.

To set up a Custom Group:

  1. Create a SharePoint group in the RecordPoint site collection using Site Settings→ People and Groups
  2. Add relevant users or, preferably, Active Directory Groups
  3. Go to ‘Security Settings’ and click on the newly created Custom Group
  4. Select the relevant permissions from the list e.g.
  5. The above configuration would give access to common IT related system admin tasks with no access to records tasks nor to view records in the system.
  6. To grant access to physical content types associate the group with the relevant content type(s)
Selecting Full Records Access for a Custom Groups will not provide access to electronic records. This can only be achieved by adding the relevant user/AD Group to a Standard Group.