I help maintain an ArcGIS Enterprise environment for a large government organisation that works with sensitive and operationally critical information. We’ve recently been facing challenges on a project where several team members need the ability to edit data, but we cannot assign them full editing or Creator licences without risking the integrity of our environment. At the same time, we can’t make the layer public, as doing so could expose sensitive information contained in the dataset.
This creates an operational deadlock: users need to maintain content, but our governance model prevents us from giving them the permissions that would enable it.
In ArcGIS Enterprise, users currently require a Creator (or higher) user type to make even small adjustments to shared items, such as:
However, granting Creator licences also gives users capabilities they do not need, such as:
For environments handling sensitive data, this is a significant governance concern. As a result:
Introduce a new permission model that allows users to edit existing items and table records shared within their groups, without granting high‑risk publishing or creation rights.
This could be implemented in one of two ways:
A user type that includes:
but excludes:
For example:
“Edit items and table records shared within user’s groups (no ability to create or publish new content)”
This could be assigned to custom roles while retaining strict governance.
This change would support:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.