このページ: オブジェクト レベルのアクセス制御を使用して、アクセス ラベルを使用してジャーニー、キャンペーン、オファーなどの個々のオブジェクトを制限します。これにより、機密性の高いコンテンツと個人データを許可されたユーザーに制限することができます。
アクセスラベルに基づいて、オブジェクトへのアクセスを制限できます。 このアプローチでは、機密性の高いデジタルアセットを権限のないユーザーから保護し、個人データの保護を強化します。
オブジェクトレベルのアクセス制御(OLAC)機能を使用すると、次のように選択したオブジェクトへのデータアクセスを管理する権限を定義できます。
- ジャーニー
- Campaign
- テンプレート
- フラグメント
- ランディングページ
- オファー
- 静的なオファーコレクション
- オファーの決定
- チャネル設定
- IP ウォームアッププラン
前提条件 prereq-labels
ラベルを作成するには、使用状況ラベルの管理権限を持つ役割に属している必要があります。
ラベルを割り当てるには、Manage journeys、Manage Campaigns または Manage decisions などの 管理 権限を持つ役割に属している必要があります。 この権限がない場合は、「アクセスを管理」ボタンが灰色表示になります。
権限について詳しくは、この節を参照してください。
ラベルの作成 create-labels
ラベルを使用すると、データに適用される使用ポリシーに従ってデータセットとフィールドを分類できます。 ラベルはいつでも適用でき、データの管理方法に柔軟性を提供できます。
ラベルを使用してユーザーにアクセス権を付与し、データガバナンスと同意ポリシーを適用します。 これらのガバナンスラベルはダウンストリームの使用に影響を与える可能性があります。
Permissions 製品でラベルを作成できます。 詳しくは、Adobe Experience Platform ドキュメントを参照してください。
また、Journey Optimizer で ラベル を直接作成することもできます。 ラベルを作成するには、次の手順に従います。
-
新しく作成された Campaign などの Adobe Journey Optimizer オブジェクトから、「アクセスを管理」ボタンをクリックします。
-
アクセスを管理ウィンドウから、「ラベルを作成」をクリックします。
-
ラベルを設定します。 次を指定する必要があります。
- 名前
- わかりやすい名前
- 説明
-
「作成」をクリックして、ラベルを保存します。
新しく作成された ラベル がリストで利用できるようになりました。 必要に応じて、Permissions 製品で変更できます。
ラベルの割り当て assign-labels
カスタムラベルまたはコアデータ使用ラベルを Journey Optimizer オブジェクトに割り当てる方法は次の通りです。
-
新しく作成された Campaign などの Adobe Journey Optimizer オブジェクトから、「アクセスを管理」ボタンをクリックします。
-
アクセスを管理ウィンドウで、このオブジェクトへのアクセスを管理するカスタムラベルまたはコアデータ使用ラベルを選択します。
コアデータ使用ラベルについて詳しくは、このページを参照してください。
-
「保存」をクリックして、このラベルの制限を適用します。
このオブジェクトにアクセスするには、ユーザーは特定の ラベル を役割 に含める必要があります。 例えば、C1 ラベルを持つユーザーは、C1 ラベル付きオブジェクトまたはラベル付けされていないオブジェクトにのみアクセスできます。
ラベルを 役割 に割り当てる方法について詳しくは、このページを参照してください。
This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.
For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.
- TL;DR: Object level access control (OLAC) lets you apply access labels to specific Journey Optimizer objects — such as journeys, campaigns, and offers — so only users whose role includes the matching label can view or interact with those objects.
Intents:
- Create a custom access label directly in Journey Optimizer or via the Permissions product
- Assign access labels to Journey Optimizer objects (journeys, campaigns, offers, etc.)
- Restrict sensitive content to authorized users only
- Understand which permissions are required to create and assign labels
Glossary:
- OLAC (Object level access control): A capability to define authorizations to manage data access for a selection of specific Journey Optimizer objects (product-specific)
- Label: A tag applied to an object to categorize it by usage policy and restrict access based on role membership (product-specific)
- Manage access: The button or interface available on supported Journey Optimizer objects for creating and assigning access labels (product-specific)
- Core data usage labels: Pre-defined labels provided by Adobe Experience Platform, as opposed to custom labels created by the organization (product-specific)
Guardrails:
- Creating labels requires the Manage usage labels permission (prerequisite)
- Assigning labels requires a Manage permission for the object type (e.g., Manage journeys, Manage Campaigns, or Manage decisions); without it, the Manage access button is greyed out (prerequisite)
- Supported objects for OLAC labels: Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, IP warmup plan
Terminology:
- Canonical name: Object level access control — Acronym: OLAC — variants: object-based access control, object-based access management
- Do not confuse: OLAC (restricts access to specific AJO objects like journeys and campaigns using labels) ≠ ABAC (attribute-based, applies label policies to schema fields, datasets, and audiences at the platform level)
- Do not confuse: “core data usage labels” (pre-built labels from Adobe Experience Platform) ≠ “custom labels” (labels created by the organization)
FAQ:
- Q: Can I create a label directly in Journey Optimizer without going to the Permissions product? — Yes; use the Manage access window on any supported object and click Create label.
- Q: Which object types support OLAC labels? — Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, and IP warmup plan.
- Q: What permission is needed to assign a label to a journey? — The Manage journeys permission; without a Manage permission, the Manage access button is greyed out.
- Q: If a user has only the C1 label in their role, which objects can they access? — Only C1-labeled or unlabeled objects.