对象级访问控制 object-level-access

在此页面上:​使用对象级别的访问控制来限制具有访问标签的单个对象,例如历程、营销活动和优惠,以便您可以将敏感内容和个人数据限制为仅供授权用户使用。

您可以根据访问标签限制对对象的访问。 这种方法可以保护敏感数字资产免受未经授权用户的访问,确保进一步保护个人数据。

对象级访问控制(OLAC)功能允许您定义用于管理所选对象的数据访问的授权:

  • 历程
  • 促销活动
  • 模板
  • 片段
  • 登陆页面
  • 产品建议
  • 静态优惠收藏集
  • 优惠决策
  • 渠道配置
  • IP预热计划

先决条件 prereq-labels

创建标签,您必须属于具有​ 管理使用标签 ​权限的角色。

要能够分配标签,您必须属于具有​ 管理 ​权限的角色,即Manage journeys、Manage Campaigns或Manage decisions。 如果没有此权限,管理访问权限​按钮将灰显。

可在此部分中详细了解权限。

创建标签 create-labels

标签​允许您根据应用于该数据的使用策略对数据集和字段进行分类。 标签​可以随时应用,从而灵活地管理数据。

使用标签为用户提供访问权限,并强制实施数据治理和同意策略。 这些治理标签可能会影响下游消费。

您可以在Permissions产品中创建标签。 有关详细信息,请参阅Adobe Experience Platform文档

您也可以直接在Journey Optimizer中创建​标签。 要创建标签,请执行以下步骤:

  1. 从Adobe Journey Optimizer对象(例如新创建的​营销活动)中,单击​ 管理访问权限 ​按钮。

    Adobe Journey Optimizer中的 管理访问权限按钮

  2. 在​ 管理访问权限 ​窗口中,单击​创建标签

  3. 配置您的标签。 您必须指定:

    • 名称
    • 友好名称
    • 描述

    标签配置字段

  4. 单击​ 创建 ​以保存您的​标签

您新创建的​ 标签 ​现在在列表中可用。 如果需要,您可以在Permissions产品中修改它。

分配标签 assign-labels

要将自定义或核心数据使用标签分配给您的Journey Optimizer对象,请执行以下操作:

  1. 从Adobe Journey Optimizer对象(例如新创建的​营销活动)中,单击​ 管理访问权限 ​按钮。

    Adobe Journey Optimizer中的 管理访问权限按钮

  2. 从​ 管理访问权限 ​窗口中,选择自定义或核心数据使用标签以管理对此对象的访问权限。

    有关核心数据使用标签的详细信息,请参阅此页面

  3. 单击​ 保存 ​以应用此标签限制。

要访问此对象,用户必须在其​ 角色 ​中包含特定的​标签。 例如,具有C1标签的用户将只能访问带有C1标签或未标签的对象。

有关如何将​ 标签 ​分配给​ 角色 ​的详细信息,请参阅此页面

AI Knowledge Reference

This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.

For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.

  • TL;DR: Object level access control (OLAC) lets you apply access labels to specific Journey Optimizer objects — such as journeys, campaigns, and offers — so only users whose role includes the matching label can view or interact with those objects.

Intents:

  • Create a custom access label directly in Journey Optimizer or via the Permissions product
  • Assign access labels to Journey Optimizer objects (journeys, campaigns, offers, etc.)
  • Restrict sensitive content to authorized users only
  • Understand which permissions are required to create and assign labels

Glossary:

  • OLAC (Object level access control): A capability to define authorizations to manage data access for a selection of specific Journey Optimizer objects (product-specific)
  • Label: A tag applied to an object to categorize it by usage policy and restrict access based on role membership (product-specific)
  • Manage access: The button or interface available on supported Journey Optimizer objects for creating and assigning access labels (product-specific)
  • Core data usage labels: Pre-defined labels provided by Adobe Experience Platform, as opposed to custom labels created by the organization (product-specific)

Guardrails:

  • Creating labels requires the Manage usage labels permission (prerequisite)
  • Assigning labels requires a Manage permission for the object type (e.g., Manage journeys, Manage Campaigns, or Manage decisions); without it, the Manage access button is greyed out (prerequisite)
  • Supported objects for OLAC labels: Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, IP warmup plan

Terminology:

  • Canonical name: Object level access control — Acronym: OLAC — variants: object-based access control, object-based access management
  • Do not confuse: OLAC (restricts access to specific AJO objects like journeys and campaigns using labels) ≠ ABAC (attribute-based, applies label policies to schema fields, datasets, and audiences at the platform level)
  • Do not confuse: “core data usage labels” (pre-built labels from Adobe Experience Platform) ≠ “custom labels” (labels created by the organization)

FAQ:

  • Q: Can I create a label directly in Journey Optimizer without going to the Permissions product? — Yes; use the Manage access window on any supported object and click Create label.
  • Q: Which object types support OLAC labels? — Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, and IP warmup plan.
  • Q: What permission is needed to assign a label to a journey? — The Manage journeys permission; without a Manage permission, the Manage access button is greyed out.
  • Q: If a user has only the C1 label in their role, which objects can they access? — Only C1-labeled or unlabeled objects.
recommendation-more-help
journey-optimizer-help