Users are authenticated using a username and password, or through integration with an LDAP-compliant service. Once authenticated, users carry status information with them. This includes:

Almost all objects within the Claromentis Framework – such as documents within the Claromentis Document Manager application and published pages within the Claromentis Enterprise Content Manager application – can have their access rights configured according to user status. The following access rights can be granted according to a user’s role, group, extranet area or owner status:
Certain applications – such as Claromentis Sales Manager – have additional user status categories and access rights, helping to control specific accessibility and functionality.
Folder inheritance plays a key role in document security. If a parent folder does not allow access to a certain status of user, these users will also be denied access to its subfolders. When documents are created, the originator can either opt for the new document to ‘inherit’ the permission status and access rights information from the folder it has been created in, or define new status and rights information.
You may want your clients to be able to access certain content within your Claromentis solution – without seeing references to, or content about, other clients. Extranet areas are used to create virtual walls between content areas so users only have access to the content that you want them to see.
If extranet users create new documents or folders, they can only grant access rights to users that have access to the same extranet area. They will not be able to see the names of users that have access to other extranet areas.
When creating a new Extranet area it is possible to mark the area as 'read only', further restricting access to functions and modules within the Claromentis Framework.
Administration of permission levels is handled using a central administration screen. This has sub-panels for each of the modules and applications within the Claromentis Framework. The system administrator can grant access to these sub-panels to key users, distributing administration of the solution across multiple people.