I always thought that "Deny Access" was the be-all, end-all. But apparently not. If someone is listed in both the "Full Access Administrators" list and the "Deny Access" list for the server, they will still be able to access the server. The "Full Access Administrators" trumps the "Deny Access" setting.

From the Administrator Help file, here's information on the Full Access Administrators field:

Full access administrators

Full access administrator is the highest level of administrative access to the server. The full access administrator feature replaces the need to run a Notes client locally on a server. It resolves access control problems -- for example, such as those caused when the only managers of a database ACL have left an organization.

Full access administrators have the following rights:

* All the rights as listed for all administrator access levels (see above).
* Manager access, with all access privileges enabled, to all databases on the server, regardless of the database ACL settings.
Note ACL roles must still be enabled manually for full access administrators. Manager access, with all roles and access privileges enabled, to the Web Administrator database (WEBADMIN.NSF).
* * Access to all documents in all databases, regardless of Reader names fields.
* The ability to create agents that run in unrestricted mode with full administration rights.
* Access to any unencrypted data on the server.

Note Full access administrator does not allow access to encrypted data. The use of the specified user's private key is required to decrypt documents that are encrypted with public keys. Similarly, a secret key is required to decrypt documents encrypted with secret keys.


Obviously, you want to be careful with who is placed in that field. But when someone leaves the company, just putting them into Deny Access won't be sufficient. You have to pull them out of the Full Access Administrators field in addition to putting them in Deny Access.

I always get the complaints from the user saying being a manager I can't edit the document(s) which are created by other members.I always explain them , This is how Quickplace works.Quickplace shows "Edit" button to Author of the document or for those who are listed as "Additional Editors" section in the document.Yesterday, One of my user asked me to allow all AUTHORS and MANAGERS of the Quickplace to edit all the documents in the Quickplace.It could be only possible if you are writing your own LS code which executes manually or on schedule basis.Here was my solution , which worked fine and user got smile too :)

1- Open the Quickplace in Lotus client (It will depend on your requirement which room
you are going to implement this solution, I assume its main.nsf)

2- Write a LS agent which will take all documents handle from "h_Index" view (h_Index
only shows user documents)

Set view = db.GetView("h_Index")
Set entryColl=view.AllEntries

(I prefer entryCollection Class , Because it gives you better performance)

3- Checking whether document is "Published" or not. We need this checking because we
can't run the code which modify the personal draft documents.
You can use "h_PageCmd" field to check whether document is in draft mode or not.It
may contains three possible values , "h_MakeDraft" , "h_Publish" and
"h_MakeDraftFromPublishedVersion".

If doc.HasItem("h_PageCmd") And (doc.GetItemValue("h_PageCmd")(0)="h_Publish" Or doc.GetItemValue("h_PageCmd")(0)="h_MakeDraftFromPublishedVersion" ) then

4- Next, We have to get document's Author field handle.In my situation, I had
requirement to stamp all authors and managers of the main.nsf ACL.

5- Use NotesACL and NotesACLentry class to make list of desire authors and managers.

6- Update those Authors/Managers list to "h_Authors" fields of the document.

7- Save and close the document , go to the next document handle.

preload preload preload