Yes, only an administrator file can add identity selection rules.
I think you can use the same format for both, introducing an element for
an identity selection rule, which you only accept in administrator mode.
Yes, you should delete the file after processing.
|