\label{Domain_Configuration_User_Privacy}
When a domain is part of the LON-CAPA network of collaborating institutions
it is possible for users in your domain to be assigned roles in courses,
communities, or authoring spaces in another domain. It is also possible for
a domain's users to be assigned domain-level roles outside their own domain.
Such types of role assignment can be subject to an approval process. In
addition, the types of ``directory'' and ``non-directory'' information
displayed in role contexts for a user's roles assigned in other domains
can be subject to restrictions. Both the types of approval, and possible
restriction of information are part of the domain configuration in the user's
own domain.
\begin{itemize}
\item \textbf{Approval options}
Approval options can be set for domains which belong to the same
institution, as determined by an identical ``internet domain'' entry for each
domain in the authoritative list of domains within a LON-CAPA cluster.
Approval options can also be set for domains which do not belong to the
same institution.
In each case, role authorization options will be set separately for roles of the
following type: Domain, Co-author, Course, and Community.
Authorization options are:
\begin{itemize}
\item \textit{Not allowed}
Roles of the particular type outside the domain may not be assigned to the domain's users.
\item \textit{User authorizes}
Assignment of roles of this type will be queued, pending the user's approval. On
the user's side a ``Show pending'' link in the Functions bar on the user's
Courses/Roles page provides access to a list of roles assigned to them, but queued
pending their approval.
\item \textit{Domain Coordinator authorizes}
Role assignments of this type will be queued, pending action by a Domain Coordinator
in the user's domain. The ``Create users or modify the roles and privileges of users''
link on a Domain Coordinator's Main Menu page provides access to a ``Queued Role
Assignments (this domain)'' link which can be used to approve or deny the assignment.
\item \textit{Unrestricted}
When a role is assigned in another domain, it is available without further
authorization, although a currently logged-in user would need to use the
"Check for changes" to display the new role and have it selectable, if the start
and end dates mean it is an active role. This is the default.
\end{itemize}
Active Domain Coordinators for whom checkboxes are checked in the ``Notify when role
needs authorization'' will receive a LON-CAPA message when a role in another domain
is assigned to a user in your domain and the approval is set to ``DC authorizes'' for
the corresponding role type.
\item \textbf{User information available}
The types of ``directory'' (i.e., last name, middle name, first name and generation) and
``non-directory'' information (i.e., email address and student/employee ID) which will
be viewable in another domain both before and after assigning a role in that domain to
a user from your domain can by configured for each institutional status type.
The default is for all user information to be viewable.
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>