Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Role Model Rules

CTS
eCTS

Is It Possible to Grant Permissions to Users in the Role Model?

No. All role model rules are prohibitive only. The role model configures what is prohibited for a specific user or group of users (unlike the CDTN contour in the File Service section, where what is permitted is configured).

How Is the Attachment Type Determined?

Client Version Description
Before 3.71 When viewing/saving, all attachments in the app are identified by extension — they are downloaded as photo/video or as a document. Therefore, the restriction on downloading/saving documents applies only to document extensions.
3.71 and later

When the role model is enabled, the app determines the file type and extension by its content, not by the extension in its name. A renamed file is recognized correctly, and the restriction applies in the same way as for the original format — both when sending and when forwarding.


If the actual type cannot be determined, the app falls back to the previous method — by the extension in the file name. The check is performed on the user's device; file contents are not analyzed on the server.

The Document attachment type is not limited to office formats: in the list of restricted extensions, you can specify, for example, exe or zip.

Creating a Role Model Rule

To create a new rule, click Create new rule and configure it.

Rule Configuration Fields

Field Description
Rule name At the administrator’s discretion. It is recommended to use a unique name that reflects the essence of the prohibition.
Rule description Optional field, but recommended to fill out.
User groups Mandatory field. Select a pre-created group (in the “User Groups” section).
Scope Where the rule applies:
  • Messaging — in chats, channels, and discussions in the app
  • In Smartapp — in SmartApps in the app
Rule action Mandatory field. Select the action type:
  • Forwarding/sharing/saving attachments to device memory is not allowed
  • Recipients are not allowed to download attachments from cts users
  • Downloading/viewing attachments is not allowed
  • Sending/forwarding attachments is not allowed
  • Require pin
  • Forbid clibboard usage in application
  • Forbid screenshot creation
The list of rule types will be expanded.
Attachment Type Mandatory field for file-related rules. Select the attachment type:
  • Image
  • Video
  • Document
Multiple types cannot be selected. Create a separate rule for each type if necessary.

After creating the rule, don’t forget to activate it.

Restriction Target, Global and Local Rules for Chats

Global & Local Rules

Rule Type Global Local
Description Applies to all user chats. Applies to specific user chats based on specified attributes.
Attributes

When the fields chat participant type and chat type in the Restriction target group are empty — the rule applies globally.

A global rule can be created without attributes by filling only the fields Rule name, User groups, Rule action, and Attachment Type. This means that attachments from any users, of any size, and with any extension will be prohibited.

The rule becomes local when at least one field is filled in the Restriction target group:

  • chat participant type (Select users whose presense in the chat prohibits the action)
  • chat type (Select the chat type to be restricted)

In addition to chat attributes, local rules can include the fields size (Maximum file size (MB)), extension (Type of restricted extentions), or sender (Select users whose attachments are restricted).

Exception Chats Field Unavailable. Available when a field is filled in the Restriction target group.
When Applies The server sends the rule to the client when logging into the app and when reconnecting to the server. For the changes to take effect, the user needs to restart the app or reconnect to the network. The server sends the rule to the client when entering a specific chat, channel, or thread. For the changes to take effect, the user needs to navigate to the specific chat, channel, or thread.

Attributes Fields

The list of fields in the restriction target depends on the selected attachment type and the rule itself.


By default, if an attribute field is not filled, the attribute has the value “all”. For example:

  • If the extension and size of attachments are not specified, a prohibition is created for the selected attachment type with all its extensions and sizes (e.g., prohibiting sending any documents in a chat)
  • If chat type (Select the chat type to be restricted) or chat participant type (Select users whose presense in the chat prohibits the action) is not specified, the prohibition applies to all user chats and channels
  • If sender (Select users whose attachments are restricted) is not specified, the prohibition applies to attachments received from any user

Attribute Combinations

Attachment attributes: sender, size, extension. Chat attributes: chat participant type, chat type.


If chat attributes are not specified, rules for attachment attributes apply globally. If chat attributes are specified, rules apply only in the specified chats.


How multiple attributes are combined:

Server Version Combination
Pre 3.46 Attributes do not depend on each other; the logical “OR” rule applies between them.
3.46 and above Attributes are combined using “AND”, meaning the restriction will only trigger if all assigned conditions are met simultaneously.
⚠️ After updating to 3.46, migration will occur: old rules with multiple attributes will be split into smaller rules with a single attribute after migration.
  • Prior to version 3.46,
  • Starting from version 3.46,

Examples from an actual version (3.46 and above):

  • If for the attachment type Documents, you specified size = no more than 30 MB, and in the extension type field — pdf, pptx, a rule with two attributes is created, which are working together: prohibited action with all documents over 30 MB with pdf and pptx extentions.
  • When both Chat participant type and Chat type are filled, the rule applies to a chat that matches the value of both the Chat participant type field AND the Chat type field in the rule.
  • If for the attachment type Documents, you specified size = no more than 30 MB and selected a chat type, the action will be prohibited for all documents larger than 30 MB with any extension in chats of the selected type

What Happens If Multiple Restrictions Are Configured for a Single User Group?

Since role model rules operate only on a denial basis, when configuring multiple different prohibitions for a user group, they are cumulative and apply simultaneously.

Rules for SmartApps

Role model rules can be configured not only for messenger chats but also for SmartApps.

What Can Be Restricted in SmartApps?

Prohibitions for SmartApps apply only to actions with attachments in them. Actions with the content itself (e.g., forwarding an email in the Email SmartApp) cannot be controlled via the role model.


For example, when configuring the restriction for sending/forwarding attachments for SmartApps, the user is prohibited from uploading and sending attachments. However, if the user receives an email with an attachment and tries to forward it, this action will be allowed because the Email SmartApp uses existing attachments uploaded by another user when forwarding. With any prohibition in place, the user can forward an email with attachments or reply to it.


⚠️ If a SmartApp proxies another resource, role model rules won't work inside it. For example, such a SmartApp cannot have screenshots or the clipboard blocked.

Configuring Rules for Attachments in SmartApps

In a SmartApp rule, you can specify:

  • application to all SmartApps (with the option to specify exceptions)
  • application to specific SmartApps

Attachments in SmartApps can be restricted entirely or by file size/extension. SmartApps handle attachments differently on platforms:

Client platform Description
Web/Desktop In SmartApps in web/desktop apps, the attachment type cannot be selected when sending — photos and videos are sent only as photos or videos; they cannot be sent as documents.
Android, iOS In SmartApps in mobile apps, the attachment type can be specified when sending. Prohibitions trigger based on the attachment type in the rule and the selected type when sending. For example, if sending all documents is prohibited in the mobile app, photos or videos cannot be sent as documents.

Rules for SmartApps Chat Bots

Role model rules for SmartApps also apply in chats with their bots:

  • in a 1-on-1 chat with a SmartApp bot, only SmartApp rules apply
  • in a 1-on-1 chat with a regular bot (not a SmartApp), global or local rules for chats apply
  • in group chats and channels with any bot, global or local rules for chats apply

Searching and Checking Role Model Rules by User

To search and check rules, use the search field at the top of the page.


Searching for a rule by the user it applies to is performed only by the user HUID.


Search works by name (entered in the top search field), connection type, platform, and status.

“Sending/forwarding attachments in chats is not allowed” Rule

This rule can apply to both the messenger and Smart App. See below for descriptions of the rule fields and their actions.
Select users whose presence in the chat prohibits an action Not applicable to Smart Apps, only applies to the messenger.
Type Results
Images
Parameter Action
Everyone except users from trust servers If the chat includes users from untrusted corporate or public servers, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Everyone except users from their servers If the chat includes users from any server other than the current one, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Specific user If this specific user is present in the chat, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Public users and guests If the chat includes users from public servers or guests, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
The chat will display “This chat has restrictions on sending images” or “Forwarding images is restricted” when the prohibition is triggered for a user in the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except users from trust servers If the chat includes users from untrusted corporate or public servers, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Everyone except users from their servers If the chat includes users from any server other than the current one, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Specific user If this specific user is present in the chat, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Public users and guests If the chat includes users from public servers or guests, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
The chat will display “This chat has restrictions on sending videos” or “Forwarding videos is restricted” when the prohibition is triggered for a user in the group.
Documents
Parameter Action
Everyone except users from trust servers If the chat includes users from untrusted corporate or public servers, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Everyone except users from their servers If the chat includes users from any server other than the current one, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Specific user If this specific user is present in the chat, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Public users and guests If the chat includes users from public servers or guests, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
The chat will display “This chat has restrictions on sending documents” or “Forwarding documents is restricted” when the prohibition is triggered for a user in the group.
Select the chat type to be restricted Not applicable to Smart Apps, only applies to the messenger.
Type Results
Images
Parameter Action
Select chat Only in this chat, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Only group chats and channels without end-to-end encryption Only in group chats and channels without end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Only group chats and channels with end-to-end encryption Only in group chats and channels with end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
Only personal chats Only in 1-1 personal chats, clicking the paperclip button will not allow selecting the Image option, and the send button will be inactive after dragging an image into the chat.
The chat will display “This chat has restrictions on sending images” or “Forwarding images is restricted” when the prohibition is triggered for a user in the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Select chat Only in this chat, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Only group chats and channels without end-to-end encryption Only in group chats and channels without end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Only group chats and channels with end-to-end encryption Only in group chats and channels with end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
Only personal chats Only in 1-1 personal chats, clicking the paperclip button will not allow selecting the Video option, and the send button will be inactive after dragging a video into the chat.
The chat will display “This chat has restrictions on sending videos” or “Forwarding videos is restricted” when the prohibition is triggered for a user in the group.
Documents
Parameter Action
Select chat Only in this chat, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Only group chats and channels without end-to-end encryption Only in group chats and channels without end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Only group chats and channels with end-to-end encryption Only in group chats and channels with end-to-end encryption enabled, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
Only personal chats Only in 1-1 personal chats, clicking the paperclip button will not allow selecting the Document option, and the send button will be inactive after dragging a document into the chat.
The chat will display “This chat has restrictions on sending documents” or “Forwarding documents is restricted” when the prohibition is triggered for a user in the group.
Enter server IDs to which you want to prohibit sending attachments Sending attachments to the server IDs specified here will be prohibited. You can specify a CTS ID (regular corporate server), ECTS ID (corporate server under ETS), RTS ID (public server).
Apply in all SmartApps/Apply in specific SmartApps Not applicable to the messenger, only applies to Smart Apps and personal chats with their bots.
Type Results
Images In all or specific Smart Apps and in personal chats with their bots, a user in the group will not be able to attach and send an image.

When attempting to send or forward an image, the user in the group will see “This chat has restrictions on sending” in the bot chat or “Sending images is restricted” in the Smart App.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
In all or specific Smart Apps and in personal chats with their bots, a user in the group will not be able to attach and send a video.

When attempting to send or forward a video, the user in the group will see “This chat has restrictions on sending” in the bot chat or “Sending videos is restricted” in the Smart App.
Documents In all or specific Smart Apps and in personal chats with their bots, a user in the group will not be able to attach and send a document.

When attempting to send or forward a document, the user in the group will see “This chat has restrictions on sending” in the bot chat or “Sending documents is restricted” in the Smart App.
Enter the maximum file size Applies to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Results
Images When attempting to send an image larger than the specified size, the send button will be inactive for the user in the group, and “Sending images over N MB is restricted” will appear below the image.

When attempting to send or forward an image larger than the specified size, the user in the group will see “Forwarding images is restricted.”
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
When attempting to send a video larger than the specified size, the send button will be inactive for the user in the group, and “Sending videos over N MB is restricted” will appear below the video (up to 50 MB).

When attempting to send or forward a video larger than the specified size, the user in the group will see “Forwarding videos is restricted.”
Documents When attempting to send a document larger than the specified size, the send button will be inactive for the user in the group, and “Sending documents over N MB is restricted” will appear below the document.

When attempting to send or forward a document larger than the specified size, the user in the group will see “Forwarding documents is restricted.”
Enter the type of restricted extentions Applies to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Results
Images Not applicable to images.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Not applicable to videos.
Documents When attempting to send a document with a prohibited extension, the send button will be inactive for the user in the group, and “Sending N documents is restricted” will appear below the document.

When attempting to send or forward a document with a prohibited extension, the user in the group will see “Forwarding documents is restricted.”
Exception chats/Exception smartapps The rule will not apply to the selected chats or Smart Apps. Selecting excluded chats is only available when creating a local rule (when a field is filled in the Restriction target group). Selecting excluded Smart Apps is available when the rule applies to all Smart Apps, not specific ones.

“Downloading/viewing attachments is not allowed” Rule

This rule can apply to both the messenger and Smart Apps. See the descriptions of the rule fields and their actions below.


This rule already automatically includes the “Forwarding/sharing/saving attachments to device memory is not allowed” rule, as it prevents downloading a file from the server.

Select users whose presence in the chat prohibits the action Not applicable to Smart Apps, only applies to the messenger.
Type Results
Images
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to view the image.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to view the image.
Specific user If this specific user is present in the chat, the user from the group will not be able to view the image.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to view the image.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to view the video.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to view the video.
Specific user If this specific user is present in the chat, the user from the group will not be able to view the video.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to view the video.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to view the document.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to view the document.
Specific user If this specific user is present in the chat, the user from the group will not be able to view the document.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to view the document.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing documents is restricted” when the prohibition is triggered for the user from the group.
Select the chat type to be restricted Not applicable to Smart Apps, only applies to the messenger.
Type Results
Images
Parameter Action
Select chat Only in this chat, the user from the group will not be able to view the image.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption, the user from the group will not be able to view the image.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption, the user from the group will not be able to view the image.
Only personal chats Only in personal 1-1 chats, the user from the group will not be able to view the image.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Select chat Only in this chat, the user from the group will not be able to view the video.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption, the user from the group will not be able to view the video.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption, the user from the group will not be able to view the video.
Only personal chats Only in personal 1-1 chats, the user from the group will not be able to view the video.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Select chat Only in this chat, the user from the group will not be able to view the document.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption, the user from the group will not be able to view the document.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption, the user from the group will not be able to view the document.
Only personal chats Only in personal 1-1 chats, the user from the group will not be able to view the document.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing documents is restricted” when the prohibition is triggered for the user from the group.
Select users whose attachments are restricted This field works similarly to the Corporate users can read rule in the File Service > Contour section if the selected group is a group of users from the internal Corporate Data Transfer Network (CDTN) contour.

Not applicable to Smart Apps, only applies to the messenger.
Type Results
Images
Parameter Action
Everyone except internal users
This rule applies if the user from the group is inside CDTN.
A user in the CDTN contour will not be able to view the image from users outside the CDTN contour.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to view the image from users inside the CDTN contour.
Everyone except users from trust servers The user from the group will not be able to view the image from users on non-trusted or public servers.
Everyone except users from their servers The user from the group will not be able to view the image from users on any other server.
Specific user The user from the group will not be able to view the image from the specified user.
Public users and guests The user from the group will not be able to view the image from public users and guests.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except internal users
This rule applies if the user from the group is in CDTN.
A user in the CDTN contour will not be able to view the video from users outside the CDTN contour.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to view the video from users inside the CDTN contour.
Everyone except users from trust servers The user from the group will not be able to view the video from users on non-trusted or public servers.
Everyone except users from their servers The user from the group will not be able to view the video from users on any other server.
Specific user The user from the group will not be able to view the video from the specified user.
Public users and guests The user from the group will not be able to view the video from public users and guests.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Everyone except internal users
This rule applies if the user from the group is in CDTN.
A user in the CDTN contour will not be able to view the document from users outside the CDTN contour.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to view the document from users inside the CDTN contour.
Everyone except users from trust servers The user from the group will not be able to view the document from users on non-trusted or public servers.
Everyone except users from their servers The user from the group will not be able to view the document from users on any other server.
Specific user The user from the group will not be able to view the document from the specified user.
Public users and guests The user from the group will not be able to view the document from public users and guests.
The chat will display “This chat has restrictions on viewing attachments” or “Viewing documents is restricted” when the prohibition is triggered for the user from the group.
Apply in all SmartApps/Apply in specific SmartApps Not applicable to the messenger, only applies to Smart Apps and personal chats with their bots.
Type Results
Images In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to view or download the image.

When attempting to view or download the image, the user from the group will see “This chat has restrictions on viewing” in the chat with the bot or “Viewing images is restricted” in the Smart App.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to view or download the video.

When attempting to view or download the video, the user from the group will see “This chat has restrictions on viewing” in the chat with the bot or “Viewing videos is restricted” in the Smart App.
Documents In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to view or download the document.

When attempting to view or download the document, the user from the group will see “This chat has restrictions on viewing” in the chat with the bot or “Viewing documents is restricted” in the Smart App.
Enter the maximum file size Applies to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Results
Images Received (even from themselves) images larger than the specified size cannot be viewed or downloaded. The chat will display “This chat has restrictions on viewing attachments.”
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Received (even from themselves) videos larger than the specified size cannot be viewed or downloaded. The chat will display “This chat has restrictions on viewing attachments.”
Documents Received (even from themselves) documents larger than the specified size cannot be viewed or downloaded. The chat will display “This chat has restrictions on viewing attachments.”
Enter the type of restricted extentions Applies to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Results
Images Not applicable to images.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Not applicable to videos.
Documents Received (even from themselves) documents with prohibited extensions cannot be viewed. The chat will display “This chat has restrictions on viewing attachments” or “Viewing N documents is restricted.”
Exception chats/Exception smartapps The rule will not apply to the selected chats or Smart Apps. Selecting excluded chats is only available when creating a local rule (when a field is filled in the Restriction target group). Selecting excluded Smart Apps is available when the rule applies to all Smart Apps, not specific ones.

“Forwarding/sharing/saving attachments to device memory is not allowed” Rule

This rule can apply to both the messenger and Smart App. See below for descriptions of the rule fields and their actions.


Disable forwarding of messages with attachments in the app — this setting (since version 3.49) additionally prohibits forwarding attachments not only to other applications but also within the app itself.

Select users whose presence in the chat prohibits the action Not applicable to Smart Apps, only to the messenger.
Type Results
Images
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to forward, share, or save the image to device memory.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to forward, share, or save the image to device memory.
Specific user If this specific user is present in the chat, the user from the group will not be able to forward, share, or save the image to device memory.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to forward, share, or save the image to device memory.
The chat will display “Forwarding images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to forward, share, or save the video to device memory.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to forward, share, or save the video to device memory.
Specific user If this specific user is present in the chat, the user from the group will not be able to forward, share, or save the video to device memory.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to forward, share, or save the video to device memory.
The chat will display “Forwarding videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Everyone except users from trust servers If the chat includes users from non-trusted corporate or public servers, the user from the group will not be able to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Everyone except users from their servers If the chat includes users from any other server except the current one, the user from the group will not be able to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Specific user If this specific user is present in the chat, the user from the group will not be able to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Public users and guests If the chat includes users from public servers or guests, the user from the group will not be able to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
The chat will display “Forwarding documents is restricted” when the prohibition is triggered for the user from the group.
Select the chat type to be restricted Not applicable to Smart Apps, only to the messenger.
Type Results
Images
Parameter Action
Select chat Only in this chat will the user from the group be unable to forward, share, or save the image to device memory.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption will the user from the group be unable to forward, share, or save the image to device memory.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption will the user from the group be unable to forward, share, or save the image to device memory.
Only personal chats Only in 1-1 personal chats will the user from the group be unable to forward, share, or save the image to device memory.
The chat will display “Forwarding images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Select chat Only in this chat will the user from the group be unable to forward, share, or save the video to device memory.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption will the user from the group be unable to forward, share, or save the video to device memory.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption will the user from the group be unable to forward, share, or save the video to device memory.
Only personal chats Only in 1-1 personal chats will the user from the group be unable to forward, share, or save the video to device memory.
The chat will display “Forwarding videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Select chat Only in this chat will the user from the group be unable to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Only group chats and channels without end-to-end encryption Only in group chats and channels without enabled end-to-end encryption will the user from the group be unable to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Only group chats and channels with end-to-end encryption Only in group chats and channels with enabled end-to-end encryption will the user from the group be unable to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Only personal chats Only in 1-1 personal chats will the user from the group be unable to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
The chat will display “Forwarding documents is restricted” when the prohibition is triggered for the user from the group.
Select users whose attachments are restricted This field works similarly to the Corporate users can read rule in the File Service > Contour section.

Not applicable to Smart Apps, only to the messenger.
Type Results
Images
Parameter Action
Everyone except internal users
This rule applies if the user from the group is inside CDTN.
The user from the group, located in the CDTN contour, will not be able to forward, share, or save the image from users outside the CDTN contour to device memory.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to forward, share, or save the image from users inside the CDTN contour to device memory.
Everyone except users from trust servers The user from the group will not be able to forward, share, or save the image from users on non-trusted or public servers to device memory.
Everyone except users from their servers The user from the group will not be able to forward, share, or save the image from users on any other server to device memory.
Specific user The user from the group will not be able to forward, share, or save the image from the specified user to device memory.
Public users and guests The user from the group will not be able to forward, share, or save the image from public users and guests to device memory.
The chat will display “Forwarding images is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except internal users
This rule applies if the user from the group is inside CDTN.
The user from the group, located in the CDTN contour, will not be able to forward, share, or save the video from users outside the CDTN contour to device memory.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to forward, share, or save the video from users inside the CDTN contour to device memory.
Everyone except users from trust servers The user from the group will not be able to forward, share, or save the video from users on non-trusted or public servers to device memory.
Everyone except users from their servers The user from the group will not be able to forward, share, or save the video from users on any other server to device memory.
Specific user The user from the group will not be able to forward, share, or save the video from the specified user to device memory.
Public users and guests The user from the group will not be able to forward, share, or save the video from public users and guests to device memory.
The chat will display “Forwarding videos is restricted” when the prohibition is triggered for the user from the group.
Documents
Parameter Action
Everyone except internal users
This rule applies if the user from the group is inside CDTN.
The user from the group, located in the CDTN contour, will not be able to forward, share, or save the document from users outside the CDTN contour to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Everyone except external users
This rule applies if the user from the group is outside CDTN.
The user from the group, located outside the CDTN contour, will not be able to forward, share, or save the document from users inside the CDTN contour to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Everyone except users from trust servers The user from the group will not be able to forward, share, or save the document from users on non-trusted or public servers to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Everyone except users from their servers The user from the group will not be able to forward, share, or save the document from users on any other server to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Specific user The user from the group will not be able to forward, share, or save the document from the specified user to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
Public users and guests The user from the group will not be able to forward, share, or save the document from public users and guests to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.
The chat will display “Forwarding documents is restricted” when the prohibition is triggered for the user from the group.
Apply in all SmartApps/Apply in specific SmartApps Not applicable to the messenger, only to Smart Apps and personal chats with their bots.
Type Results
Images In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to forward, share, or save the image to device memory.

When attempting to forward, share, or save the image to device memory, the user from the group will see “Forwarding images is restricted” in the chat with the bot or “Downloading images is restricted.”
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to forward, share, or save the video to device memory.

When attempting to forward, share, or save the video to device memory, the user from the group will see “Forwarding videos is restricted” in the chat with the bot or “Downloading videos is restricted.”
Documents In all or specific Smart Apps and in personal chats with their bots, the user from the group will not be able to forward, share, or save the document to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.

When attempting to forward, share, or save the document to device memory, the user from the group will see “Forwarding documents is restricted” in the chat with the bot or “Downloading documents is restricted.”
Enter the maximum file size Applicable to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Results
Images The user from the group will not be able to forward, share, or save the image larger than the specified size to device memory.

The chat will display “Forwarding images larger than N MB is restricted” when the prohibition is triggered for the user from the group.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
The user from the group will not be able to forward, share, or save the video larger than the specified size to device memory.

The chat will display “Forwarding videos larger than N MB is restricted” when the prohibition is triggered for the user from the group.
Documents The user from the group will not be able to forward, share, or save the document larger than the specified size to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.

The chat will display “Forwarding documents larger than N MB is restricted” when the prohibition is triggered for the user from the group.
Enter the type of restricted extentions Applicable to both the messenger and Smart Apps (including personal chats with Smart App bots).
Type Result
Images Not applicable to images.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Not applicable to videos.
Documents A received (even from oneself) document with a prohibited extension cannot be forwarded, shared, or saved to device memory. Printing the document in the web or desktop app (View > Ctrl(Cmd)+P) outputs empty pages.

The chat will display “Forwarding N documents is restricted” when the prohibition is triggered for the user from the group.
Exception chats/Exception smartapps The rule will not apply to the selected chats or Smart Apps. Selecting excluded chats is only available when creating a local rule (when a field is filled in the Restriction target group). Selecting excluded Smart Apps is available when the rule applies to all Smart Apps, not specific ones.

“Recipients are not allowed to download attachments from cts users”

This rule applies only within the messenger. This prohibition is analogous to the Corporate files can read setting in the File Service > Contour section. The only difference is that this prohibition has an additional division of contour users:
  • internal contour — a user in the CDTN contour from the same server;
  • trusted contour — a user in the CDTN contour from a trusted server.

Sender and Recipient

In this prohibition:
  • the sender is a user from the group for which this rule is configured. The prohibition will apply to attachments sent by users of this group.
  • the recipient is a user who meets the criteria specified in the rule.

Mandatory Rule Fields

When creating the rule, at least one of the following fields must be filled in:
  • Select contour
  • Select the users for whom the action will be restricted
⚠️ If both fields are filled, the stricter restriction will apply.

Instant Action of the Restriction

Once the prohibition is enabled and an attachment is sent, the prohibition immediately applies to the attachment — no client restart or network reconnection is required. After disabling, the prohibition continues to apply only to attachments sent while the prohibition was active — previously sent attachments are not affected.

Contour and Role Model Rules Comparison

If the Contour is disabled on the recipient’s server in the File Service section, but the contour IP mask is filled in, and a contour user receives an attachment that can only be viewed within the contour, the prohibition via the contour and the prohibition via the role model will behave differently:
  • with a prohibition via the CDTN contour using the Corporate files can read field, the attachment will be available to the recipient under these conditions — the contour is disabled, but the IP mask is filled in, and the user is within this network;
  • with a prohibition via the role model (with contour restriction), the attachment will be unavailable to the recipient under these conditions.
For descriptions of the rule fields and their effects, see below.
Select contour Not applicable to Smart Apps, applies only to the messenger. Requires a configured CDTN contour.

This rule makes sense if the user from the group is inside the CDTN.
Type Results
Images
Parameter Action
All except internal contour users Only users who are both on this server and in the same contour will be able to download the image.
All except trusted contour users Only users who are both on this or a trusted server and in their own contour will be able to download the image.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
All except internal contour users Only users who are both on this server and in the same contour will be able to download the video.
All except trusted contour users Only users who are both on this or a trusted server and in their own contour will be able to download the video.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Documents
Parameter Action
All except internal contour users Only users who are both on this server and in the same contour will be able to download the document.
All except trusted contour users Only users who are both on this or a trusted server and in their own contour will be able to download the document.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Select the users for whom the action will be restricted Not applicable to Smart Apps, applies only to the messenger.
Type Results
Images
Parameter Action
Everyone except users from trust servers Only users from the group who are on the current or trusted server will be able to download the image. Others will receive an error.
Everyone except users from their servers Only users from the group who are on the current server will be able to download the image. Others will receive an error.
Public users and guests Only corporate users on any corporate server will be able to download the image. Public users will receive an error.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Everyone except users from trust servers Only users from the group who are on the current or trusted server will be able to download the video. Others will receive an error.
Everyone except users from their servers Only users from the group who are on the current server will be able to download the video. Others will receive an error.
Public users and guests Only corporate users on any corporate server will be able to download the video. Public users will receive an error.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Documents
Parameter Action
Everyone except users from trust servers Only users from the group who are on the current or trusted server will be able to download the document. Others will receive an error.
Everyone except users from their servers Only users from the group who are on the current server will be able to download the document. Others will receive an error.
Public users and guests Only corporate users on any corporate server will be able to download the document. Public users will receive an error.
The chat will display “This file is unavailable” when the prohibition applies to an external user.
Select the chat type to be restricted Not applicable to Smart Apps, applies only to the messenger. This is an additional parameter that limits the scope of the rule.
Type Results
Images
Parameter Action
Select chat The prohibition for recipients to download images from users with CTS will only apply in this specific chat.
Only group chats and channels without end-to-end encryption The prohibition for recipients to download images from users with CTS will only apply in group chats or channels without end-to-end encryption.
Only group chats and channels with end-to-end encryption The prohibition for recipients to download images from users with CTS will only apply in group chats or channels with end-to-end encryption.
Only personal chats The prohibition for recipients to download images from users with CTS will only apply in personal 1-1 chats.
Videos
⚠️ Note that videos are sent as documents if their size exceeds 50 MB!
Parameter Action
Select chat The prohibition for recipients to download videos from users with CTS will only apply in this specific chat.
Only group chats and channels without end-to-end encryption The prohibition for recipients to download videos from users with CTS will only apply in group chats or channels without end-to-end encryption.
Only group chats and channels with end-to-end encryption The prohibition for recipients to download videos from users with CTS will only apply in group chats or channels with end-to-end encryption.
Only personal chats The prohibition for recipients to download videos from users with CTS will only apply in personal 1-1 chats.
Documents
Parameter Action
Select chat The prohibition for recipients to download documents from users with CTS will only apply in this specific chat.
Only group chats and channels without end-to-end encryption The prohibition for recipients to download documents from users with CTS will only apply in group chats or channels without end-to-end encryption.
Only group chats and channels with end-to-end encryption The prohibition for recipients to download documents from users with CTS will only apply in group chats or channels with end-to-end encryption.
Only personal chats The prohibition for recipients to download documents from users with CTS will only apply in personal 1-1 chats.
Exception chats The rule will not apply to selected chats. Selecting excluded chats is only available when creating a local rule (when a field is filled in the Restriction target group).

“Require pin” Rule

This role model rule adds a mandatory requirement to create a PIN code for the app additional protection.

When Does the Rule Trigger?

  • A user logging into the app will see a screen for creating a mandatory PIN code, which cannot be skipped:
    Platform Action
    iOS Immediately after authentication.
    Android, Desktop (any app)
    or Web (ETS app only)
    Upon the next app launch.
  • A user already logged into the app will see the mandatory PIN creation screen upon app restart, reconnecting to the network on all platforms, or after a post-check (where rules are re-requested, and the user receives all applicable rules).

How Does the Rule Work in Client Apps?

Platform Action
iOS and Android Disable PIN button disappears.
Desktop (any app)
or Web (ETS app only)
Disable PIN Code button remains, as it is used to change the PIN code, which remains available to the user. After clicking this button in the web/desktop app, the user is immediately taken to the screen for creating a new mandatory PIN code.

I Switched the Rule, but Nothing Happened. Why?

Enabling or disabling the “Require pin” rule or the role model itself may not immediately show or hide the PIN creation screen, but only after restarting the app or reconnecting to the network. This behavior is more common on Android and less frequent on iOS — for example, when disabling the rule.


How to Set the Time After Which Auto-Lock by PIN Code Will Be Activated?

In the web/desktop app, the auto-lock timeout for entering a PIN code cannot be set, so such a setting is currently unavailable in the role model.

In mobile apps, auto-lock occurs by default after 5 minutes, and this time can be changed in the app settings. However, on Android, if the user has already set a different auto-lock time, it will be preserved — the user can change it at any time.


Configuring SmartApps Visibility in the SmartApps Catalog

Currently, this is the only rule that is configured not in the Role Model section but in the bot or SmartApp settings under “Bots”.

What Is Required for the Rule to Work?

For the rule to work:

  • Activate the role model.
  • Use the standard catalog: in the admin panel, open the SmartApps > Display in main menu > APP_ID > select Default catalog or homescreen-smartapp-catalog.

How to Restrict SmartApp Visibility?

To configure SmartApp visibility in the SmartApps catalog in the app:

  1. In the admin panel, go to the “Bots” section.
  2. Click the pencil button next to the desired SmartApp.
  3. Specify the desired Availability: for all users or specific user groups. If specific groups are selected, the SmartApp will only appear in the catalog for users from these groups. In the Contacts section, it will remain available to everyone regardless of the settings.
  4. Save the changes.

How to Hide a SmartApp on a Specific Client Platform?

In the settings of the user group that should see the SmartApp, clear the checkbox for that client platform (for example, iOS).

Rule Operation Example

The impact of availability settings using the Calendar SmartApp as an example:

Availability Setting Visibility in Contacts Visibility in SmartApps Catalog
All Calendar SmartApp is available in the Contacts section. A user not in the group sees Calendar SmartApp in the smart apps catalog (the “9 dots” menu).
Specific Role Model User Group (user is NOT in the group) Calendar SmartApp is available in the Contacts section. A user not in the group does not see Calendar SmartApp in the smart apps catalog (the “9 dots” menu).

How Do I Hide All SmartApps From Everyone Except One Group?

Make all SmartApps available only to this group. What other users see depends on what is selected as the catalog in the SmartApps section.

What Is Selected in the Catalog What Happens and What to Do
A separate SmartApp In its settings, set Availability to all users. Make the other SmartApps available only to the required group.
Default catalog This catalog is a feature of the application itself: it shows the list of SmartApps available to the user. It is not in the list of bots, so availability settings do not apply to it. Users without access will see an empty catalog or the message “The catalog is hidden by your server admin” in the mobile app.

To make sure no one sees an empty catalog:

  1. In the SmartApps section, clear the SmartApps Catalog enabled check box.
  2. Open SmartApps > Mobile clients menu and select the Menu configuration enabled check box.
  3. Drag each SmartApp into the Quick features block and click Save.

In the mobile app, SmartApps appear in quick features only for users who have access to them.

In the web and desktop app, if the SmartApps Catalog enabled check box is cleared, no one has the catalog: the catalog button on the left pane and the catalog in the Home SmartApp disappear. The user can still find available SmartApps in the Contacts section.

Forbid Clipboard Usage in Application

This rule can apply to both the messenger and Smart App. Available since 3.46 version.


If enabled:

  • Disables the use of the device's clipboard while the app is open: forbids copying message text, pasting text, copying text when viewing documents, etc. Copying and pasting within the message field is still available BEFORE the message is sent.
  • The Copy/Paste context menu buttons are hidden; pressing the keyboard shortcuts for copy/paste has no effect.

If the Branded Build of the App for ETS Also Has a Clipboard Restriction, How Do They Interact?

Works with the built-in restrictions in the ETS app as follows:
  • If a restriction is configured in the role model, use it;
  • If a restriction is not configured in the role model, the built-in restriction from the ETS app build is used (if available).

Forbid Screenshot Creation

This rule applies to both messenger and Smart App — cannot apply separated. Available since 3.46 version.


If enabled:

  • Disables the ability to take screenshots while the app is active (does not work when the focus is on another window or application).
  • The area of the client app that is not in focus turns black.

The Rule Is Enabled. Why Can Screenshots Still Be Taken in the Web App?

⚠️ It is technically impossible to block screenshots in the web app, so this restriction does not work there.

If the Branded Build of the Application for ETS Also Has a Screenshot Restriction, How Do They Interact?

Works with the built-in restrictions in the ETS app as follows:
  • If a restriction is configured in the role model, use it;
  • If a restriction is not configured in the role model, the built-in restriction from the ETS app build is used (if available).