Introduction
Derived Access Control
Derived Access Control (DAC) is a mode that you can set for a user account whereby the user groups (and their assigned roles) to which the account belongs enforce the user’s permissions, read/write access to domains, and change policies. This mode means an administrator does not have to edit individual user accounts separately.
For a user account in DAC mode, the system automatically propagates any changes to a group and its roles to that account.
Figure 2: Hierarchical Definition of Groups and Roles
If a user account is not in DAC mode, the account inherits a group’s permissions, and so on, when you first assign it to the group. Though the system does propagate subsequent additions to the group’s permissions and domains to the user account, it does not propagate the removal of any permissions or domains from the group.
For examples of DAC behavior when creating a user account or editing a user group, see the below video.
Setting Derived Access Control Mode for a User Account
Migrating User Accounts to Derived Access Control
Parent Topic:
Introduction
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/ida918ceae-eb67-45e8-a448-e88ea7a145b9 · retrieved 2026-07-18