What three components make up every permission, and how does a permission matrix capture them?
Every permission joins an identity (who), an operation (what they may do: read, write, execute, …) and a resource (on what). A permission matrix lists roles as rows, resources as columns and the allowed operations in the cells.
The permission itself says nothing about who has it; that only follows once identities are assigned to it. So a permission concept starts by collecting the resources (for example the shares Management, Allgemeine Dokumente = general documents, IT), then the roles, and then fills in the matrix. One sensible version:
| Role | General documents | Management | IT |
|---|---|---|---|
| Management | r w x | r w x | r |
| Staff | r w x | – | – |
| IT staff | r w x | – | r w x |
(r = read, w = write, x = execute.) The matrix is the design document; the groups and folder permissions are its implementation. With IGDLA, each role row becomes a global group and each column plus access level becomes a domain local group.
Go deeper:
Wikipedia: Access-control list — how identity, operation and resource are stored as ACL entries.