Barcode permission structure
The rules determining which people, devices, and services may create identifiers, change labels, capture transactions, override validation, administer equipment, or export data.
- Here, barcode permission structure aligns authority with operational consequences.
- Its limit is that it must cover nonhuman identities.
- Verify quantity override before the access administrator relies on it in the effective-access record.
Label design right
Permission to change payload fields, symbology, size, text, graphics, or application commands in a template.
- Here, label design right can alter readability and meaning.
- Its limit is that it should be separated from routine printing.
- Verify device enrollment before the access administrator relies on it in the effective-access record.
Reprint authority
Permission to reproduce a previously issued identifier or serialized label.
- Here, reprint authority supports legitimate replacement.
- Its limit is that it can create duplicate physical identities if uncontrolled.
- Verify configuration profile before the access administrator relies on it in the effective-access record.
Transaction action
The allowed receive, move, pick, count, adjust, ship, issue, return, or custody event initiated through a scan.
- Here, transaction action changes operational state.
- Its limit is that it must be constrained by role and context.
- Verify bulk export before the access administrator relies on it in the effective-access record.
Device enrollment
The authority to register a scanner, printer, or mobile computer and assign its configuration, certificates, application, and site.
- Here, device enrollment admits equipment to the environment.
- Its limit is that it requires asset identity and ownership.
- Verify service credential before the access administrator relies on it in the effective-access record.
Service credential
A nonhuman identity used by a device, print service, mobile application, integration, or management platform.
- Here, service credential enables automated access.
- Its limit is that it needs narrow scope, rotation, and revocation.
- Verify remote support before the access administrator relies on it in the effective-access record.