Careful consideration must be given when granting privileges to users.
For a client, the access level defined in the membership policy applies only to the client and the matters created within it.
To get full control over every single item in the file plan, including all client, matters, and file parts, a user must have the File Plan Admin privilege. When a user is granted this privilege, they can create, modify, or delete any client, matter, or file part in the system. (Among other things) They can also action approvals in IRM Web Client. Very few users should have this privilege.
NOTE: Even if you have the File Plan Admin privilege set as Granted, you can create a matter only if you are a member of the Facility’s WorkSpace Creators group.For matters, the access level defined in the parent membership policy is examined when the user tries to browse to or search for the item. The membership policy is examined for matters, and the security policy is examined for file parts. If these policies prevent the action, the user is blocked from performing the action. If the user isn't granted the appropriate privilege, the action is also prevented.
When a user is granted the File Plan Admin privilege, the access level is ignored and the user can create, modify, or delete any matter in the system. For integrity purposes, this privilege should typically not be granted to any user.
The File Part Manager privilege is intended for limited super-users with domain-specific privileges. Most users with disposition processing capabilities should have this privilege (File Clerks), though it isn't strictly required. The File Part Manager privilege grants delete-level permissions for file parts that exist within a matter where the user has at least view-level permissions. The File Part Manager privilege extends to clearing the failed disposition job Processing Errors. For example:
If a user is granted view permissions for a matter, and no access to any file part, but has the File Part Manager privilege, they effectively have view permissions for those file parts.
If a user is granted view permissions to a matter, and view access to any file part, but has the File Part Manager privilege, they effectively have delete permissions for those file parts.
If they have no access to the parent matter, then they have no access to any of the file parts within.
No privilege exists to create a file part from a template. Assuming the parent membership policy or security doesn't prevent it, any user can create a file part from a template.