在此頁面上:使用物件層級存取控制來限制個別物件(例如歷程、行銷活動和優惠方案)的存取標籤,因此您可以將敏感內容和個人資料限制在授權的使用者之內。
您可以根據存取權標籤限制對物件的存取。 這個方法能保護敏感的數位資產,避免未經授權的使用者存取,並確保進一步保護個人資料。
物件層級存取控制(OLAC)功能可讓您定義授權,以管理所選物件的資料存取:
- 歷程
- 促銷活動
- 範本
- 片段
- 登陸頁面
- 產品建議
- 靜態優惠收藏
- 優惠決定
- 管道設定
- IP熱身計畫
先決條件 prereq-labels
若要能夠建立標籤,您必須屬於具有 管理使用標籤 許可權的角色。
若要能夠指派標籤,您必須屬於具有 管理 許可權的角色,即Manage journeys、Manage Campaigns或Manage decisions。 若沒有此許可權,管理存取權按鈕會變成灰色。
若要了解權限的詳細資訊,請參閱本章節。
建立標籤 create-labels
標籤可讓您根據套用至該資料的使用原則來分類資料集和欄位。 標籤可隨時套用,讓您在控管資料的方式上有彈性。
使用標籤為使用者提供存取權,並強制執行資料治理和同意原則。 這些治理標籤可能會影響下游消耗。
您可以在Permissions產品中建立標籤。 如需詳細資訊,請參閱Adobe Experience Platform檔案。
您也可以直接在Journey Optimizer中建立標籤。 若要建立標籤,請遵循下列步驟:
-
從Adobe Journey Optimizer物件(例如新建立的促銷活動),按一下 管理存取權 按鈕。
在Adobe Journey Optimizer中
-
從 管理存取權 視窗,按一下建立標籤。
-
設定您的標籤。 您必須指定:
- 名稱
- 易記名稱
- 說明
-
按一下[建立] 以儲存您的 標籤。
您新建立的 標籤 現在可在清單中使用。 如有需要,您可以在Permissions產品中修改它。
指派標籤 assign-labels
若要將自訂或核心資料使用標籤指派給您的Journey Optimizer物件:
-
從Adobe Journey Optimizer物件(例如新建立的促銷活動),按一下 管理存取權 按鈕。
在Adobe Journey Optimizer中
-
從 管理存取權 視窗,選取您的自訂或核心資料使用標籤,以管理此物件的存取權。
如需核心資料使用標籤的詳細資訊,請參閱此頁面。
-
按一下 儲存 以套用此標籤限制。
若要存取此物件,使用者的 角色 中必須包含特定的標籤。 例如,具有C1標籤的使用者將只能存取C1標籤或未標籤的物件。
如需如何將 標籤 指派給 角色 的詳細資訊,請參閱此頁面。
This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.
For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.
- TL;DR: Object level access control (OLAC) lets you apply access labels to specific Journey Optimizer objects — such as journeys, campaigns, and offers — so only users whose role includes the matching label can view or interact with those objects.
Intents:
- Create a custom access label directly in Journey Optimizer or via the Permissions product
- Assign access labels to Journey Optimizer objects (journeys, campaigns, offers, etc.)
- Restrict sensitive content to authorized users only
- Understand which permissions are required to create and assign labels
Glossary:
- OLAC (Object level access control): A capability to define authorizations to manage data access for a selection of specific Journey Optimizer objects (product-specific)
- Label: A tag applied to an object to categorize it by usage policy and restrict access based on role membership (product-specific)
- Manage access: The button or interface available on supported Journey Optimizer objects for creating and assigning access labels (product-specific)
- Core data usage labels: Pre-defined labels provided by Adobe Experience Platform, as opposed to custom labels created by the organization (product-specific)
Guardrails:
- Creating labels requires the Manage usage labels permission (prerequisite)
- Assigning labels requires a Manage permission for the object type (e.g., Manage journeys, Manage Campaigns, or Manage decisions); without it, the Manage access button is greyed out (prerequisite)
- Supported objects for OLAC labels: Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, IP warmup plan
Terminology:
- Canonical name: Object level access control — Acronym: OLAC — variants: object-based access control, object-based access management
- Do not confuse: OLAC (restricts access to specific AJO objects like journeys and campaigns using labels) ≠ ABAC (attribute-based, applies label policies to schema fields, datasets, and audiences at the platform level)
- Do not confuse: “core data usage labels” (pre-built labels from Adobe Experience Platform) ≠ “custom labels” (labels created by the organization)
FAQ:
- Q: Can I create a label directly in Journey Optimizer without going to the Permissions product? — Yes; use the Manage access window on any supported object and click Create label.
- Q: Which object types support OLAC labels? — Journey, Campaign, Template, Fragment, Landing page, Offer, Static offer collection, Offer decision, Channel configuration, and IP warmup plan.
- Q: What permission is needed to assign a label to a journey? — The Manage journeys permission; without a Manage permission, the Manage access button is greyed out.
- Q: If a user has only the C1 label in their role, which objects can they access? — Only C1-labeled or unlabeled objects.