You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过DQL查询Documentum对象的访问控制列表及ACL数量疑问

Hey there! Since you're new to Documentum, let's walk through your questions about Access Control Lists (ACLs) clearly and simply—no jargon overload, promise 😊

1. How to retrieve an object's ACL using DQL

There are two common ways to get ACL info for an object, depending on how much detail you need:

Basic ACL Identification

If you just need to know which ACL is assigned to the object (its name and domain), use this simple DQL query. Replace the r_object_id value with your target object's ID:

SELECT acl_name, acl_domain
FROM dm_document
WHERE r_object_id = '0900d28880001234'

Every Documentum object has acl_name and acl_domain properties that together uniquely identify its assigned ACL.

Detailed ACL Permissions

If you want to see the specific permissions (which users/groups have access, and what level of access), join the object table with dm_acl and dm_acl_permit (the table that stores individual permission entries):

SELECT 
  a.acl_name, 
  a.acl_domain, 
  p.permittee_name, 
  p.permittee_domain, 
  p.accessor_permit
FROM dm_document obj
JOIN dm_acl a ON obj.acl_name = a.object_name AND obj.acl_domain = a.owner_name
JOIN dm_acl_permit p ON a.r_object_id = p.acl_id
WHERE obj.r_object_id = '0900d28880001234'
  • accessor_permit uses numeric codes to represent permission levels (e.g., 7 = Full Control, 6 = Modify, 5 = Read, etc.)
  • This query will return every user/group and their corresponding access level for the object's ACL.
2. Can a Documentum object have multiple ACLs?

Short answer: No, each Documentum object can only have one primary ACL assigned to it at any time.

That said, there are a few related scenarios that might make it seem like multiple ACLs are in play:

  • You can easily replace an object's existing ACL with a different one (using API commands like set,c,acl_name or a DQL UPDATE statement)
  • Extended Permissions: These are additional, granular permission settings that supplement the primary ACL. They let you add or restrict access for specific users/groups without replacing the entire ACL, but they aren't separate ACLs—they're stored in the dm_acl_ext_permit table and work alongside the main ACL.
  • Folder Inheritance: Objects in a folder might inherit the folder's ACL by default, but once you assign a unique ACL to the object itself, it stops inheriting and uses its own single ACL.

内容的提问来源于stack exchange,提问作者Akhil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:53:13