Permissions Issues
Posted in 2005
We are on IDS 9.4FC5 on AIX5.3 and 7.31UC5 on SCO. We have been asked to find a way to ensure that our developers are not able to update, insert, or delete from our production databases. We have about 170 instances and about 1000 users. I have considered roles, but without a default role, it really does no good. The only options that I have come up with are: 1. revoke update,insert, and delete from public on every table and then grant update, insert, and delete to our individual end-users. This adds up to over 900,000 entries in systabauth on our main database alone, and would be very cumbersome and error-prone to maintain. 2. Upgrade to 10.0 FCx and enable a default role for developers that only has select permissions. The only bad news is that we have only been given 3 weeks to make this happen. Now I can certainly upgrade in less than three weeks, but I don't think our board would have the assurances they require that it won't ruin the business in that time frame. Does anyone have any other ideas that might help? I needed some input from people who were away from the situation and might come up with something else.