> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/administradores/windows_permisos.md).

# Permissions in Windows

## Editran services user security and permissions

The correct operation of Editran Connect on Windows environments depends not only on system configuration but also on the permissions granted to the **user that runs the services**. This section summarizes the security and access considerations required for that user.

***

### Execution context

Editran Connect services are developed in **Java** and use an **embedded JRE** deployed together with the application. Additionally, Editran includes:

* A **web server** (Editran Connect Server) for the user interface.
* A database service **PostgreSQL** for persistence of configuration and operations.

All these components require specific permissions to operate correctly and securely.

***

### Permission requirements for the user

The user that runs the services (either `LocalSystem` or a custom user) must have the following minimum permissions:

| Area / Resource                  | Required permission                            | Reason / Justification                                              |
| -------------------------------- | ---------------------------------------------- | ------------------------------------------------------------------- |
| Editran installation folder      | **Full control**                               | Read/write logs, run the JRE and JAR files                          |
| Network and local ports          | **Open and listen on ports (e.g. 8081, 8085)** | Access to web services, digital signing and external communications |
| Access to the PostgreSQL service | **Connection (localhost:5432)**                | Access the configuration database                                   |
| Access to keys and certificates  | **Read from local stores or files**            | Signature verification, secure connection to external services      |

***

### Security best practices

* 🔒 **Restrict access to sensitive folders.**\
  Only the services user should have write access to critical folders.
* 🧾 **Log relevant events.**\
  Enable the security log and monitor unauthorized access to ports or configuration files.
* 🌐 **Limit web access.**\
  Configure the firewall to restrict access to the web server only to necessary IPs.

***

### Special considerations if using a custom user

If services stop working when using a user other than `LocalSystem`, ensure that:

* The user has the "Log on as a service" right.
* They have access to all directories where executables, logs and configurations are located.
* The **environment variables** required are correctly defined in their context (see previous section).
* They can connect to the database port and the local web server.

> ✅ *Recommendation:* Create a specific user of the type `svc_editran` and add it to a limited group with defined permissions.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/administradores/windows_permisos.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
