I’m using Apache Tomcat on a windows server with the Kanisa platform running on top of it. Kanisa and Tomcat both use the same service account. Users log into Kanisa. My problem is anyone can get access to anything on the site as long as they know the URL to the share/directory/page they want to view. I believe they can do this because Tomcat and Kanisa both use the same service account. Is there any way to keep people out of the site?