Security Settings
Base Security
By default, each user will have a certain level of access to the system before they are given specific security rights. You can change their default level of access by changing this setting to Read/Write, Read Only or No Access.
Read/Write will give them the ability to read (view) and write (change) information in the system unless another security setting prevents them from doing so. This setting is very useful if most the users in the system will be reading and writing most of the data.
Read Only will give them the ability to read (view) all the information in the system unless another security setting prevents them from doing so. You can add more security settings later to give them the ability to write (change) certain information but for most information they will only be allowed to read. This is useful if the system is such where most of the information is OK for most users to view but you only want a smaller portion of users to change the information.
No Access will hide all information from them unless you specifically give them rights to certain types of information later. This is useful if most of the information is sensitive or if there are many groups of users and many types of information in the system.
Inactivity Logout
If you wish to have the users automatically logged out after a set number of minutes they are inactive, set the number of minutes in this field. Set to 0 to use the built-in 24-hour session expiration. Once the user has been inactive for the specified number of minutes they will be logged out.
Password Change
This is used to specify wow often (in days) to force users to change their passwords. Leave it blank or set to 0 to not force password changes. Otherwise when a user logs in after their password expiration they will be prompted to change their password.
Password Complexity
You can set this option to the level of password protection you need. The options are Low, Medium and High.
Low - No specific password requirements
Medium - Minimum password length of 6 characters
High - Minimum of 6 characters, one or more must be upper case, one or more must be lower case, and one or more must be non-alphanumeric
Custom - You can specify a custom REGEX expression that dictates the complexity required
Password Security REGEX
Set your custom REGEX expression here for password complexity
Change Password
Turning this option ON allows users to change their own password. If this is OFF then admins must manage the passwords.
Password Reset
Turning this option ON allows users to click a Forgot Password link on the login page to start the password recovery process. Turn it OFF if you do not wish to use that feature.
Remember Me
Turning this option ON allows users to check the 'Remember Me' box in the login page. By checking that box during login, the user will be automatically logged in when visiting the site again. This is done with persistent cookies so please review all security concerns around using encrypted cookies with SSL communications before using this.
Failed Logins
Whether or not to send emails to admins when a user login fails. This is useful for identifying improper access attempts.
Standard Logins
Whether or not to allow standard logins when using SSO for the normal logins. If you use SSO but still have some support logins or other non-SSO logins that need access then you can turn this on. If you want to be sure that only SSO users are allowed access, turn this off.
Auto SSO Login
Whether or not to automatically direct users to the SSO login cycle when coming to the login screen. If you turn this OFF then users will be directed to login using your SSO provider instead of having to click the Auto Login button.
SSO Login User Property
If you are using Single Sign On, this allows you to select which user property matches your SSO login main property. The default is Email which works most of the time.
Non-Admin Restore
Allows users without Admin rights to view and restore deleted Documents. Normally this is an Admin-Only feature.
Secure Individual Records
Allows for records to be secured using the @SECURE data field. This adds extra security but there is a trade off for speed. Keep this off unless you need it.
Personal Signatures
Allow users to set their personal signatures. These will be available via the annotation stamps and the signature pads from workflow, add-in or e-form signature prompts.
Public PDF Forms
DocMgt has the capability to accept external PDF forms as posts into the system. For security this is not enabled by default. If you wish to use PDF forms to post data and documents into the system turn this on.
SFTP Access (Cloud only)
IF you wish to allow users to upload documents via SFTP you will want to turn on this setting.
Add-In Downloads
Turn this on to allow Add-Ins to download files to local computers and run applications
Secure API Mode
Public E-forms and other anonymous entry points run on the server under a service account so they can read the records they need to build and process the form. That means a data-pulling variable placed on a public form runs with that account's access, and a form could pull data from Record Types the public was never meant to see. Secure API Mode is the switch that closes that gap.
Turn this ON to restrict what public (not logged in) requests may do on the server. Today it governs the record-reading variables - DMGET, DMGET2, DMGETIN, DMGETLI, DMGETCOUNT, DMGETOPTIONS, DMGETCHARTDATA, DMGETEVENTS, DMGETMAPLOCS, DMGETPROP and GETRECORDID. When one of those is resolved by a public request, it only returns data if the Record Type it reads from allows it. A Record Type allows it when any one of Public Search Access, Collaboration Portals or Public Data Pulls is turned on for that Record Type.
Blocked pulls return no data rather than an error - an empty list, a count of zero, or a blank value - so the form still renders with that piece of data missing. Logged in users are never affected and continue to be governed by their normal Record Type rights. Workflow, Add-Ins and background processing are never anonymous, so they are unaffected as well.
Before turning this on, review the public forms you have in production and note which Record Types they pull data from, then enable the appropriate access toggle on each of those Record Types. Turning Secure API Mode back off makes the whole feature dormant immediately, so it is safe to switch off if a public form stops showing data unexpectedly.
While Secure API Mode is off, the Public Data Pulls toggle is hidden on the Record Type screen, since it has no effect until this option is on.
Legacy No Access Searching
This switch only appears while Base Security is set to No Access. It keeps things working the way they did before DocMgt's security update, while you give people access to the Record Types they need. A DocMgt update may have turned it on for you. While it is on, the System Advisor shows a Warning.
While it is on, No Access security is not fully enforced for forms and workflow. Form dropdowns, lists, charts, calendars, and maps, workflow and Add-In searches, and public forms can read records from Record Types the people using them have not been given access to. Turn it off once the access is in place.
Searching is never affected by this switch. The search screen, saved searches, the Home screen's search and chart panels, search exports, REST API and MCP searches, and the Importer's matching of existing records only ever return records the person or integration account has access to, whether the switch is on or off. If an integration account needs to find records, give it access to those Record Types.
What changes when you turn it off
Once the switch is off, anyone who has not been given access to a Record Type stops getting that Record Type's records in the places below. That includes the docMgt_Agent user, which runs public forms and background work such as retention, Record Type automation, OCR completion, and AI jobs. Records shared one at a time with @SECURE or @ALLOWUSER still come through.
- Forms: dropdowns, lists, charts, calendars, and maps filled by DMGET variables come up empty, and GETRECORDID values come up blank.
- Linked fields: type-ahead lookups, and option lists filled from a linked field, come up empty. This only applies to linked fields whose Skip Security setting is turned off; it is on by default.
- Workflow and Add-In actions that search for records, such as Search and Update, Search and Create, and Search and Run Actions, find nothing unless the action's Security setting is set to skip security. Search and Create then creates a new record instead of updating the one it would have found. The Lookup Table Validator action has no such setting and is always affected. QuickBooks Online sync actions are affected the same way: they no longer find the records they synced before and create duplicates.
- Accounts with no access to any Record Type at all also lose: Save Into Other Record on E-forms (a new record is created instead of the matching one being updated) and E-form repeating sections.
These keep working either way: opening a record, favorites, saving records, the values shown in linked fields, public search pages, and collaboration portal logins.
Before you turn it off, click Check DMGET Access to see which forms depend on it, and give the people who use them access. For public forms and background work, give the docMgt_Agent user access.
DMGET Access Check
This button only appears while Base Security is set to No Access. Under No Access, the DMGET variables that fill E-form dropdowns, lists, charts, calendars, and maps (and the GETRECORDID variable, which looks up a record's ID) return records only from Record Types the person running them has been given access to. When nobody using a form has access to the Record Type it reads from, the form comes up empty without any error. DMGET Access Check finds those variables for you.
Click Check DMGET Access to scan your E-forms, Record Types, Custom Variables, Workflows, Action Sets, and Add-Ins. The results open in a window with two lists.
Record Types read by DMGET variables lists each Record Type the variables read from, how many variables use it, who has access to it, and whether the docMgt_Agent account has access. Click a row to open that Record Type.
Where they are used lists each variable, the item it sits in, where in that item it was found, and the variable itself. Click a row to open that item. The list starts on Problems; click All to include the variables that are fine.
Each variable is marked with one of these statuses:
- Returns nothing – nobody who runs it gets any data. The Record Type grants no user or Team access, has no filter values set (No Access security can only grant a Record Type that has them), sets All Users to No Access, or no longer exists. On a public form it also means the docMgt_Agent user has no access, or that Secure API Mode is on and none of the Record Type's Public Search Access, Collaboration Portals, or Public Data Pulls switches is turned on.
- Some users only – some of the people who run it get data and the rest get nothing. The message says how many active users have access.
- Check by hand – the Record Type is chosen while the variable runs, or no Record Type is given at all, so access cannot be worked out ahead of time. Use the Variable Tester to see what a particular user gets.
- OK – everyone who runs it has access.
Who needs access depends on where the variable is used:
- E-forms, Record Types, and Custom Variables run as the person viewing the form or record.
- Workflows, Action Sets, and Add-Ins run as the person who started them. When they run in the background (OCR, retention, scheduled automation), they run as the docMgt_Agent account, so that account needs access too.
- Public E-forms run as the docMgt_Agent user for anyone who is not logged in, both while the form loads and in its buttons and field actions. All Users covers internal users only and never grants anything to visitors who are not logged in, so a public form needs the docMgt_Agent user to have access, granted to that user directly or through one of its Teams. An All Users grant does not count here, even though docMgt_Agent is a user. When Secure API Mode is on, the Record Type must also have at least one of its Public Search Access, Collaboration Portals, or Public Data Pulls switches turned on.
To fix a problem, open the Record Type's Security settings and grant access to the users or Teams who use the forms (All Users if every internal user needs it), and to the docMgt_Agent user for public forms and background workflow. Make sure the Record Type has at least one filter value. Then click Check Again.
If Legacy No Access Searching is on, these variables still return data today, and the window says so at the top. The results show what will happen once you turn it off, so clear the problems before switching it off.
The check works from Record Type security only. Records granted one at a time with @SECURE or @ALLOWUSER are not counted, so a variable marked Returns nothing can still return those records to the people they are granted to.