基于属性的访问控制 attribute-based-access

在此页面上:​在Adobe Journey Optimizer中使用基于属性的访问控制,将敏感架构字段、配置文件属性和受众限制为授权角色,以便您可以保护个人数据并防止未经授权的用户对其进行操作。

基于属性的访问控制功能允许您定义用于管理特定团队或用户组的数据访问的授权。 其目的是保护敏感的数字资产免受未经授权用户的侵害,进一步保护个人数据。

在Adobe Journey Optimizer中使用基于属性的访问控制来保护数据,并授予对特定字段元素(包括体验数据模型(XDM)架构、配置文件属性和受众)的特定访问权限。

有关用于基于属性的访问控制的术语的更详细列表,请参阅Adobe Experience Platform文档

在此示例中,向​ 国籍 ​架构字段添加标签以限制未经授权的用户使用它。 要使此功能正常工作,请执行以下步骤:

  1. 创建新的​角色,并为该角色分配相应的​标签,以便用户能够访问和使用架构字段。

  2. 将​ 标签 ​分配给Adobe Experience Platform中的​ 国籍 ​架构字段。

  3. 在Adobe Journey Optimizer中使用​架构字段

请注意,还可以使用基于属性的访问控制API访问​角色策略​和​产品。 有关详细信息,请参阅此文档

创建角色并分配标签 assign-role

IMPORTANT
​>在管理角色的权限之前,请先创建策略。 有关更多信息,请参阅 Adobe Experience Platform 文档

角色​是组织内共享相同权限、标签和沙盒的一组用户。 属于​ Role ​的每个用户都有资格使用产品中包含的Adobe应用程序和服务。 您还可以创建自己的​角色,以微调用户对界面中特定功能或对象的访问权限。

要授予所选用户访问标记为C2的​ 国籍 ​字段的权限,请创建一个包含一组特定用户的新​角色,并授予他们标签C2,以让他们在​ 历程 ​中使用​ 国籍 ​详细信息。

  1. 从Permissions产品中,从左窗格菜单中选择​角色,然后单击​创建角色。 请注意,您还可以将​ 标签 ​添加到内置角色。

    在权限产品中创建新角色

  2. 将​ Name ​和​ Description ​添加到您的新​角色,此处:受限角色人口统计。

  3. 从下拉列表中,选择您的​沙盒

  4. 从​ 资源 ​菜单中,单击​ Adobe Experience Platform ​以打开其他功能。 在此,我们选择​历程

  5. 从下拉列表中,选择链接到选定功能的​权限,例如​ 查看历程 ​或​发布历程

  6. 保存新创建的​ 角色 ​后,单击​ 属性 ​以进一步配置对角色的访问权限。

  7. 在​ 用户 ​选项卡中,单击​添加用户

  8. 从​ 标签 ​选项卡中,选择​添加标签

  9. 选择要添加到角色中的​标签,然后单击​保存。 在本例中,将标签C2授予用户,以访问以前受限的模式的字段。

    保存标签配置

受限角色人口统计​角色中的用户现在可以访问标记为C2的对象。

将标签分配给Adobe Experience Platform中的对象 assign-label

WARNING
不正确的标签使用可能会中断人员的访问并触发策略违规。

标签​可用于使用基于属性的访问控制来分配特定功能区域。 在此示例中,对​ 国籍 ​字段的访问受到限制。 此字段仅可供具有分配给其​ 角色 ​的相应​ 标签 ​的用户访问。

请注意,您还可以将​ 标签 ​添加到​架构数据集​和​受众

  1. 创建您的​架构。 有关详细信息,请参阅本文档

  2. 在新创建的​ 架构 ​中,我们首先添加包含​ 国籍 ​字段的​ 人口统计详细信息 ​字段组。

  3. 从​ 标签 ​选项卡,检查受限字段名称,此处​国籍。 然后从右窗格菜单中选择​编辑治理标签

    编辑字段的治理标签

  4. 选择相应的​标签,在这种情况下,C2 — 数据无法导出到第三方。 有关可用标签的详细列表,请参阅此页面

  5. 如果需要,可进一步个性化您的架构,然后启用它。 有关如何启用架构的详细步骤,请参阅此页面

现在,您架构的字段将仅对具有C2标签的角色集所包含的用户可见和使用。 通过将​ 标签 ​应用于您的​字段名称标签​将自动应用于每个创建的架构中的​ 国籍 ​字段。

访问Adobe Journey Optimizer中带有标签的对象 attribute-access-ajo

在新架构和角色中标记​ 国籍 ​字段名称后,可在Adobe Journey Optimizer中观察到此限制的影响。 对于此示例:

  • 用户X可以访问标记为C2的对象,并创建一个历程,该历程的条件以受限的​ 字段名称 ​为目标。
  • 用户Y如果无法访问标记为C2的对象,则会尝试发布历程。
  1. 在Adobe Journey Optimizer中,使用新架构配置​数据源

    配置数据源

  2. 将新创建的​ 架构 ​的新​ 字段组 ​添加到内置​数据源。 您还可以创建新的外部​ 数据源 ​和关联的​字段组

    向数据源添加字段组

  3. 选择之前创建的​ 架构 ​后,从​ 字段 ​类别中单击​编辑

  4. 选择要定位的​字段名称。 在此处,我们选择受限制的​ 国籍 ​字段。

  5. 创建向具有特定国籍的用户发送电子邮件的历程。 添加​ 事件 ​和​条件

  6. 选择受限制的​ 国籍 ​字段以开始构建表达式。

  7. 编辑您的​ 条件 ​以使用受限的​ 国籍 ​字段针对特定群体。

  8. 根据需要个性化您的历程,此处我们添加了一个​ 电子邮件 ​操作。

    向历程添加电子邮件操作

如果用户Y无权访问标签C2对象,则需要使用受限字段访问此历程:

  • 用户Y将无法使用受限字段名称,因为它将不可见。
  • 在高级模式下,用户Y将无法编辑具有受限字段名称的表达式。 将出现以下错误: The expression is invalid. Field is no longer available or you do not have enough permission to see it
  • 用户Y可以删除表达式。
  • 用户Y将无法测试历程。
  • 用户Y将无法发布历程。
AI Knowledge Reference

This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.

For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.

  • TL;DR: Protect sensitive data fields in Journey Optimizer by applying governance labels to schema fields and assigning matching labels to roles, so unauthorized users cannot view, edit, test, or publish journeys that use those restricted fields.

Intents:

  • Create a role and assign a governance label to restrict access to specific schema fields
  • Apply a label to a schema field in Adobe Experience Platform to enforce access restrictions
  • Use a labeled schema field in a Journey Optimizer journey
  • Understand how users without the required label experience access restrictions in journeys
  • Manage Roles, Policies, and Products via the attribute-based access control API

Glossary:

  • ABAC (Attribute-based access control): A capability to define authorizations to manage data access for specific teams or groups of users based on attributes such as labels (product-specific)
  • Role: A set of users sharing the same permissions, labels, and sandboxes within an organization (product-specific)
  • Label: A governance marker (e.g., C2) applied to schema fields, datasets, or audiences to control which roles can access them (product-specific)
  • Policy: A configuration that must be created before managing permissions for a role — prerequisite for ABAC (product-specific)
  • XDM schema: Experience Data Model schema used to define data structure in Adobe Experience Platform (product-specific)

Guardrails:

  • A policy must be created before managing permissions for a role (prerequisite, as stated in the Important note on the page)
  • Incorrect label usage can break access for people and trigger policy violations (as stated in the Warning on the page)
  • Users without a label matching a restricted field cannot: view the restricted field name, edit expressions referencing it in advanced mode, test the journey, or publish the journey

Terminology:

  • Canonical name: Attribute-based access control — Acronym: ABAC — variants: attribute-based access management
  • Canonical name: Experience Data Model — Acronym: XDM — variants: XDM schema, XDM schemas
  • Synonyms: “Label” = “governance label” = “data governance label”
  • Do not confuse: “Role” (a group of users with shared permissions and labels) ≠ “Policy” (rules governing enforcement of data access based on labels)
  • Do not confuse: ABAC (controls access to schema fields, datasets, and audiences via label policies at the platform level) ≠ OLAC (controls access to specific Journey Optimizer objects like journeys and campaigns)

FAQ:

  • Q: Can labels be added to built-in roles? — Yes, labels can be added to both custom and built-in roles.
  • Q: What happens to a user who lacks the label for a restricted field in a journey? — The field is not visible to them; they cannot edit expressions referencing it, test the journey, or publish the journey.
  • Q: Can labels be applied to objects other than schema fields? — Yes; labels can also be applied to schemas, datasets, and audiences.
  • Q: Is there an API for managing roles, policies, and products with ABAC? — Yes; Roles, Policies, and Products can be accessed via the attribute-based access control API.
recommendation-more-help
journey-optimizer-help