I wanted to explain this dialog - taken from the Manage & Settings-->Permissions and Administrators-->Permission Profiles:
![](/legacyfs/online/checkpoint/64460_1 confusing.png)
One of the benefits for using layers with R80.10 is that you can segregate them for different administrator roles. You do that by 2 steps:
1. Define a permission profile with reference to Access Control Layers
2. Set the Permission settings at the Layer Editor.
The by-profile approach:
With every layer, you should pick the specific permission profiles that can edit it.
Make sure that this option is checked at the permission profile editor:
![](/legacyfs/online/checkpoint/64461_3 per profile.png)
Only permission profiles with the above option checked, are eligible for selection in this portion of the layer editor:
![](/legacyfs/online/checkpoint/64462_4 select it in this one.png)
The by-blades approach:
The enabled blades on a layer will automatically determine which permission profiles can edit it.
All layers which match the this blade selection are available for editing for this permission profile:
![](/legacyfs/online/checkpoint/64463_5 by blade.png)
A layer with this blade selection will show the above permission profile as eligible for editing. At the layer editor, you can't select permission profiles which had the "automatically by blades" checked.
![](/legacyfs/online/checkpoint/64464_6 blades.png)
![](/legacyfs/online/checkpoint/64465_7 auto by blade.png)
Which one is the better approach? It depends. If you are about to create a bunch of inline layers with a set of blades enabled on them, will you remember to assign the correct specific permission profiles? And what happens when you enable another blade on a layer - do you want some permission profiles to be automatically removed from editing it? This is up to each customer to decide.
Let us know your comments on this.