Introduction > Derived Access Control
Setting
Derived Access Control Mode for a User Account
You specify whether you manage a user account in Derived Access Control (DAC) mode on the Login tab of the Edit User Account dialog box.
Procedure
Create or open the user account from the User Accounts folder in the browser tree.
Click the Login tab.
Select Derived Access Control (the default).Note If you do not want to manage the user account in DAC mode, unselect the option.
Click the OK button to save the user account in DAC mode and leave the Edit User Account dialog box, or click the Apply button to save the user account in DAC mode and keep the dialog box open
Results
The user groups (and their assigned roles) to which the account now belongs enforce the account’s permissions, read/write access to domains, license policy and change policies.
The Roles, Read-Only Domains, Read-Write Domains, License Policy and Permissions tabs for the user account become read-only.
The system automatically propagates any changes to the groups and their roles to the user account.
If a user account inherits settings from multiple groups: The settings for permissions, license policy and domains are merged for the user account.
In the case of domains, if a domain is read-only in one group but read-write in another group, the user account has the domain as read-write.
A superuser account will have all defined domains as read-write by default.
A user in DAC mode has a modified icon in the Capital Access Manager browser tree (). A user not in DAC mode has the standard icon ().
Parent Topic:
Derived Access Control
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/id6d6d0481-14e6-40e4-bc92-2b299e3ef78c · retrieved 2026-07-18