Allow policies not to automatically grant owner right to document creators
While document creators have by definition unrestricted access to the data they add to the document, having owner rights would allow them to later extract data others have added to the documents they created. Owner rights also allow creators to downgrade classification on documents that have already been classified.
The suggestion is to have a setting on each policy that when enabled does not automatically grant the creator of a document full control rights or the ability to reclassify once the document is closed. This should enable revocation of access for content creators and would also prevent such users from removing protection.

7 comments
-
kojima kazunori commented
Enable revoking the issuer privilege of protected contents by AIP administrator.
-
Anonymous commented
This same feature is available in AD RMS as mentioned in the above Enrique Saggese's comment. i too agree that.
But, i have a question here.
1. Who is owner of the Document, if we have this feature?
I think owner means in real world, they have full accessible for their own things right. If, we didn't give the full rights for owner, then the "owner" name is not meaningfull.
one who is protecting the document, is one who is creating the document. So, he can have a full rights. Because, he is the creator, he can able to change the document in future even he can change the permission to another user too. This all happens only when he has the full rights. -
tamilmani.s commented
It would be nice, If we restrict the owner permission to the person who is applying protection to the document. Expecting this useful feature for AIP in future.
-
Kathirvel Nagaraj commented
While document creators have by definition unrestricted access to the data they add to the document, having owner rights would allow them to later extract data others have added to the documents they created. Owner rights also allow creators to downgrade classification on documents that have already been classified.
The suggestion is for AIP to have a setting on each policy that when enabled does not automatically grant the creator of a document full control rights or the ability to reclassify once the document is closed -
karthik r commented
It would be good to have this valid feature in AIP as well.
-
Kathirvel Nagaraj commented
Yes, we want the same feature "Allow policies not to automatically grant full control to document creators" in AIP/MIP.
-
Please note that this feature is available in AD RMS.