Updated on 2026-09-24 GMT+08:00

App Users

This feature is designed to enable granular management of user data access permissions within business systems (systems that have the encryption plugin deployed). It determines which users are permitted to view plaintext data and which users are allowed to access desensitized data.

This feature enables you to safeguard sensitive data, implement business-driven minimal authorization, and customize appropriate data access permissions for users with different roles.

To manage user data access permissions within the Fine-Grained Management Business System (systems deployed with the encryption plugin), after creating application users as required in this chapter, additional configuration steps are necessary; for detailed instructions, please refer to the "User-Level Data Anonymization" section.

Adding an App User

To create a new application user, you need to provide a unique identifier, a user name, and other required information.

  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account.
  2. In the left navigation tree, select User Management > Application User.
  3. In the right-hand section, click Add User, as shown in Figure 1.

    Figure 1 App user

  4. In the Add User dialog box, configure application user-related information as shown in Figure 2; the descriptions for new user parameters are provided in Table 1.

    Figure 2 Creating an app user
    Table 1 New user parameter documentation

    Parameter

    Description

    Username

    The username for the business system corresponding to the integrated plugin.

    For example: If the business system is CRM, the user name should match the user name used in CRM.

    Unique identifier

    The encryption platform is used to distinguish users across different customer business systems, ensuring that each user is uniquely identified within the platform; for example, both a CRM business system and an ERP business system may contain a user named Zhang San, but their permissions differ between these two systems – in such cases, a unique identifier is required to differentiate between these two users. This unique identifier can be constructed using the employee's employee ID/account number combined with the name of the business system, e.g., zhangshan_crm.

    Remark

    Provide additional information such as the user's position, department, or intended use to facilitate subsequent management and maintenance. Example: Big Data Platform Operations and Maintenance Lead.

    Is plaintext enabled

    Indicates whether the data browsed by the user within the business system is in plaintext.

    Is desensitization enabled

    Indicate whether the data browsed by the user within the business system has been desensitized.

  5. After completing the configuration, click Confirm to create the application user.

Viewing App Users

View detailed information for all app users, including username and notes, as shown in Figure 3.

Figure 3 Viewing app users

Editing or Deleting an App User

Adjust the information of existing application users to accommodate changing business requirements.

  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account.
  2. In the left navigation tree, select User Management > Application User.
  3. When the mouse pointer hovers over the character that needs to be manipulated, the Edit and Delete buttons will appear, as shown in Figure 4.

    Figure 4 Editing or deleting an app user

  4. As needed, you can edit or delete application users, as shown in Figure 5.

    Figure 5 Editing a user

  5. Click Confirm to execute the operation.