<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Simplify AGE security model in terms of data governance in ArcGIS Enterprise Ideas</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idi-p/1700544</link>
    <description>&lt;P&gt;&lt;U&gt;Current state:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our company (Prague Airport)&amp;nbsp;has&amp;nbsp;a complex&amp;nbsp;AGE deployment. We are&amp;nbsp;maintaining&amp;nbsp;multiple&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;web apps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;containing&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;web maps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;map services.&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;In each of the&amp;nbsp;apps&amp;nbsp;a&amp;nbsp;different agenda&amp;nbsp;is being&amp;nbsp;managed,&amp;nbsp;and&amp;nbsp;the data is accessed/viewed/edited by&amp;nbsp;users in user&amp;nbsp;groups with specific privileges.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is&amp;nbsp;very difficult&amp;nbsp;and&amp;nbsp;time consuming&amp;nbsp;to&amp;nbsp;maintain&amp;nbsp;these apps&amp;nbsp;and keep&amp;nbsp;them&amp;nbsp;up-to-date.&amp;nbsp;If we need to make a&amp;nbsp;simple change, we need&amp;nbsp;to update each of the apps&amp;nbsp;one by one.&amp;nbsp;Imagine the amount of work when we currently&amp;nbsp;manage&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;12+&amp;nbsp;applications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Idea:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We&amp;nbsp;would appreciate&amp;nbsp;having an environment where&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;data&amp;nbsp;governance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;was&amp;nbsp;simplified.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We suggest a&amp;nbsp;solution&amp;nbsp;to use&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;a single service,&amp;nbsp;a&amp;nbsp;single&amp;nbsp;map&amp;nbsp;and&amp;nbsp;a&amp;nbsp;single&amp;nbsp;app&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;– with&amp;nbsp;settings&amp;nbsp;similar to&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;security proxy&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;, that&amp;nbsp;ensure the users see only&amp;nbsp;items&amp;nbsp;specific&amp;nbsp;to their user&amp;nbsp;group.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This&amp;nbsp;solution could be applied&amp;nbsp;on:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Layers:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;A map&amp;nbsp;with multiple layers&amp;nbsp;where&amp;nbsp;each user&amp;nbsp;could&amp;nbsp;only&amp;nbsp;see a subset of them.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Fields and domains&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; within a service:&amp;nbsp;A particular user (or the public) could only&amp;nbsp;see&amp;nbsp;a subset of fields.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Applications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;A&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;security proxy&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;could&amp;nbsp;control capabilities based on user groups.&amp;nbsp;For example, to prevent users who manage power line data from seeing and editing waterpipes.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Widgets in apps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;It would be great if the&amp;nbsp;security configuration could allow the app to enable/disable widgets dynamically on load.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;This approach would make item and data management more flexible,&amp;nbsp;efficient&amp;nbsp;and easier to&amp;nbsp;maintain.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you&amp;nbsp;please consider&amp;nbsp;changing the security model as described?&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/78925"&gt;@VHolubec&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/661303"&gt;@RomanJanecek&lt;/a&gt; &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/486001"&gt;@JanDlouhy&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2026 12:34:21 GMT</pubDate>
    <dc:creator>PancovaMarketa</dc:creator>
    <dc:date>2026-06-04T12:34:21Z</dc:date>
    <item>
      <title>Simplify AGE security model in terms of data governance</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idi-p/1700544</link>
      <description>&lt;P&gt;&lt;U&gt;Current state:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our company (Prague Airport)&amp;nbsp;has&amp;nbsp;a complex&amp;nbsp;AGE deployment. We are&amp;nbsp;maintaining&amp;nbsp;multiple&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;web apps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;containing&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;web maps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;map services.&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;In each of the&amp;nbsp;apps&amp;nbsp;a&amp;nbsp;different agenda&amp;nbsp;is being&amp;nbsp;managed,&amp;nbsp;and&amp;nbsp;the data is accessed/viewed/edited by&amp;nbsp;users in user&amp;nbsp;groups with specific privileges.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is&amp;nbsp;very difficult&amp;nbsp;and&amp;nbsp;time consuming&amp;nbsp;to&amp;nbsp;maintain&amp;nbsp;these apps&amp;nbsp;and keep&amp;nbsp;them&amp;nbsp;up-to-date.&amp;nbsp;If we need to make a&amp;nbsp;simple change, we need&amp;nbsp;to update each of the apps&amp;nbsp;one by one.&amp;nbsp;Imagine the amount of work when we currently&amp;nbsp;manage&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;12+&amp;nbsp;applications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Idea:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We&amp;nbsp;would appreciate&amp;nbsp;having an environment where&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;data&amp;nbsp;governance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;was&amp;nbsp;simplified.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We suggest a&amp;nbsp;solution&amp;nbsp;to use&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;a single service,&amp;nbsp;a&amp;nbsp;single&amp;nbsp;map&amp;nbsp;and&amp;nbsp;a&amp;nbsp;single&amp;nbsp;app&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;– with&amp;nbsp;settings&amp;nbsp;similar to&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;security proxy&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;, that&amp;nbsp;ensure the users see only&amp;nbsp;items&amp;nbsp;specific&amp;nbsp;to their user&amp;nbsp;group.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This&amp;nbsp;solution could be applied&amp;nbsp;on:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Layers:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;A map&amp;nbsp;with multiple layers&amp;nbsp;where&amp;nbsp;each user&amp;nbsp;could&amp;nbsp;only&amp;nbsp;see a subset of them.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Fields and domains&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; within a service:&amp;nbsp;A particular user (or the public) could only&amp;nbsp;see&amp;nbsp;a subset of fields.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Applications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;A&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;security proxy&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;could&amp;nbsp;control capabilities based on user groups.&amp;nbsp;For example, to prevent users who manage power line data from seeing and editing waterpipes.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Widgets in apps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;It would be great if the&amp;nbsp;security configuration could allow the app to enable/disable widgets dynamically on load.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;This approach would make item and data management more flexible,&amp;nbsp;efficient&amp;nbsp;and easier to&amp;nbsp;maintain.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you&amp;nbsp;please consider&amp;nbsp;changing the security model as described?&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/78925"&gt;@VHolubec&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/661303"&gt;@RomanJanecek&lt;/a&gt; &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/486001"&gt;@JanDlouhy&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 12:34:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idi-p/1700544</guid>
      <dc:creator>PancovaMarketa</dc:creator>
      <dc:date>2026-06-04T12:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Simplify AGE security model in terms of data governance</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idc-p/1710888#M4659</link>
      <description>&lt;P&gt;Another example that comes to mind is the Special Event Operations solution from ArcGIS Solutions. We recently deployed this solution and in the solution there is one service, one map, and one app for people to edit what is happening with an event. After showing the solution to Fire, Parks, Police, and Public Works they pointed out that are different aspects that each department is responsible for and they were concerned with accidentally modifying some other departments edits. Currently, I will have to recreate the solution by making copies of the service, map, and app for each department so that each department can edit what they need to but still see what the other departments are doing for overall operational context.&lt;/P&gt;&lt;P&gt;It would save so much time to be able to even at just the service level control edits and views for different groups and that propagates up through the map and app. Then I have just one service, map, and app to manage special event operations but different controls for the different groups accessing it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 21:10:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idc-p/1710888#M4659</guid>
      <dc:creator>Joshua-Young</dc:creator>
      <dc:date>2026-06-29T21:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Simplify AGE security model in terms of data governance</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idc-p/1710960#M4660</link>
      <description>&lt;P&gt;Valid idea and use cases. This is currently only supported via custom SOI&amp;nbsp;&lt;A href="https://architecture.arcgis.com/en/framework/architecture-pillars/integration/methods/server-object-interceptors-and-extensions.html" target="_blank" rel="noopener"&gt;Integration | SOEs and SOIs | ArcGIS Architecture Center.&lt;/A&gt;&lt;BR /&gt;If you need something right away, you can find a suitable Partner Solution here:&amp;nbsp;&lt;A href="https://www.esri.com/partners/con-terra-gmbh-a2T70000000TNNiEAO/security-manager-nex-a2d70000000UKkEAAW" target="_blank" rel="noopener"&gt;security.manager NEXT by con terra GmbH | Esri Partner Solution.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Similar idea:&amp;nbsp;&lt;A href="https://community.esri.com/t5/arcgis-pro-ideas/access-permissions-on-versioned-services-need-to/idi-p/1709842" target="_blank"&gt;https://community.esri.com/t5/arcgis-pro-ideas/access-permissions-on-versioned-services-need-to/idi-p/1709842&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 04:00:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/simplify-age-security-model-in-terms-of-data/idc-p/1710960#M4660</guid>
      <dc:creator>SimonSchütte_ct</dc:creator>
      <dc:date>2026-06-30T04:00:46Z</dc:date>
    </item>
  </channel>
</rss>

