Clarification on service security policies


taken from this page:

Could someone please clarify, I presume that the note means the tag access section of the policy is meaningless if running on a single gateway (edge in this instance).

  1. Does this mean if there is a remote gateway on the network that access to tags can be controlled through the policy when connected to the local gateway?
  2. Is there any way to control access to prevent a certain zone from being able to edit tags if using only a single gateway?

If you have an ignition gateway connecting to your devices, and a second using that gateways tags you can limit access in the security policies.

If you want to read/write to tags on the same gateway this policy won't affect it, you need to configure the security on the tags themselves in the designer. See here: Tag Security Properties | Ignition User Manual

It's not a massive problem for me but I would be curious to know if it is possible to allow a user to read/write but not edit tags on the gateway.

If you want to limit editing the tags, you want to edit the settings in the Tag Provider.

See here:Tag Provider Security | Ignition User Manual