Administering Domains, Roles and Users > External User Management Systems
Dynamic User Access Control
If you want to apply an additional layer of authorization for access to designs and projects, you can do so by using dynamic domain assignment via a plugin.
With domains, project or design user access is first checked via the internal static method for validating access, see Domain Access for more details. Through use of a secure plugin, it can then be dynamically checked against an external data source to determine whether access should still be granted.
Figure 29: Static and Dynamic Domain Access Checks
Use cases where dynamic user access control might be employed include:
Final access definitions being outsourced to an external system.
User access varying based on current location.
Write access for some users being dependent on life-cycle state (release level).
For further information on creating and using dynamic user access control, see the CustomSecurityPluginDevelopment.pdf document in the doc/plugin folder of your Capital installation for information on creating and deploying a plugin to allow communication with an external authorization service.
A sample dynamic user access control plugin is provided in the following location:
%Capital_Home%\doc\plugin\examples\Java\src\com\example\plugin\useraccess
Parent Topic:
External User Management Systems
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/idb3ac4d14-4676-4189-8b92-409c7874b36a · retrieved 2026-07-18