How ION decides access
During sign-in, ION reads the group memberships your identity provider sends through its standard group data. For each request, ION checks that membership for an exact match with either of these group names:Employee Export UnRestrictedExport UnRestricted
The export-control decision reads your identity provider’s group membership, not an arbitrary SSO attribute. If your identity provider stores the entitlement in another attribute, map that value into the group data your SSO connection sends before ION can act on it.
What export control protects
Export control applies to three record types: parts, procedures, and runs. For an export-restricted person, a flagged record is omitted from query results, and a direct link returns not found. A run is treated as export-controlled when its own flag, its associated part, or its source procedure is export-controlled. ION doesn’t manage export-control group membership. You manage it in your identity provider. Because ION filters these records before an update can load them, an export-restricted person can’t edit an existing export-controlled part, procedure, or run. They also can’t mark a part, procedure, or run as export-controlled.Configure export-control access
- Contact First Resonance Support to enable export control and confirm that your SSO connection sends identity-provider group membership to ION.
- In your identity provider, create or identify a group named exactly
Employee Export UnRestrictedorExport UnRestricted. - Add each person who can access export-controlled records to one of the allowed groups. Keep everyone else out of both groups.
- After you change group membership, have the affected person start a new sign-in session so ION receives their current groups.
Mark a record as export-controlled
An export-unrestricted person sets the flag on the record itself:- On a procedure, turn on the Export control toggle.
- While creating a run, turn on Export controlled.
- On a part, set the
export_controlledcolumn totruewhen you import parts.
Verify the restriction
- Prepare a controlled test record:
- On a test procedure, turn on Export control, then create a run from that procedure.
- To test a part, import a test part with
export_controlledset totrue, then associate it with a run. - To test a run on its own, turn on Export controlled while creating the run.
- Sign in with an account in one of the allowed groups that also has the ION permissions the records need. Confirm that the part or procedure and its associated run are available.
- Sign in with an account outside both allowed groups. Confirm that list results omit the controlled records and that a direct link returns not found.
- If the part has inventory, confirm that the inventory record stays visible but an update to it is blocked.