A one-page card that names which Maximo security layer answers which question, so you stop solving record problems with security group count. Applies to MAS 8.x, 9.0, and 9.1.
Most Maximo security messes happen because someone solves a record problem with an application, site, or security-group-count fix. This card names the layer first. It lays out the three layers, application security, site and org authorization, and data level security, then maps the common problems to the layer that actually solves each one and the fix you should not reach for instead.
Access combines toward more, never less. A user gets the combined effect of every security group they are in. Application and site access take the most permissive group, and data restrictions OR together, so the broader condition wins. Any security group with no condition on the object grants full access, and one broad group defeats the careful restriction you built somewhere else. The card spells this out so you design for it from the start.
No email, no signup. Print it, pin it by the Security Groups application, and reach for it before you create another security group.
This card tells you which layer to build in. Building the conditions, restrictions, and group model for your environment end to end is the AppPoints and Security Groups Workshop and Playbook.