How to Manage Custom App Permissions Across Multi-Domain UCS Environments?

Hello

I am working on deploying a custom app via the Univention App Center in a multi-domain UCS environment. :innocent:The app requires fine-grained access to LDAP attributes but I am facing challenges in managing consistent permission behavior across different domains especially when domain controllers sync intermittently / are not always online. :slightly_smiling_face:

Has anyone implemented a way to dynamically adjust / sync app permissions (e.g., through a pre/post installation script or policy hook)? :thinking: I am trying to avoid hardcoding anything that might break under variable domain trust or sync latency.

I have checked App Tutorial guide related to this . Also I came across the term what is alteryx while working on this & wanted to understand if it’s relevant here.

Also; if there’s a guide or official best practices for app permission handling in multi-domain setups, I would appreciate it. So far; I have only found general packaging docs. :thinking:

Thank you !! :slightly_smiling_face: