Everything you need to know about permissions

Was this article helpful?

What are Permissions?

Global Permissions and Role-based Permissions

Global Permissions

A global permission is a system control that defines WHAT a user is able to do in the application. For example, a user who has the Admin Access permission has access to administration.

Permission Sets

Permissions are granted to users through permission sets. A permission set is a group of global permissions created for users with common permission requirements. For example, you are a system administrator, a system administrators permission set is created and assigned to a system administrators team, and as a member of that team, you would gain those permissions.

If you are also a member of the finance team then your personal permissions would be the accumulation of both the supervisors and finance permission sets.

Updates to a permission set are applied to all users with that permission set.

Permission Sets and ACL Teams

Permissions sets are most efficiently assigned by using ACL teams. Add your users to ACL teams to determine what they can do in the system. Adding your permissions in this way allows you to easily maintain your permissions.

See Teams

Adding Permissions to User Interface Elements

Permissions can be used to control the display of data elements on a screen. This is controlled in the configuration for individual data capture elements.

Data Capture Elements Permissions Control
Aspects

Aspects add sections onto the blade forms within the application.

These can be added to users, teams, people, organisation, work types, connections and other elements within the application.

To add permissions to an aspect click on the next to the aspect and select the permissions you wish to add.

Portals

Portal widget can be configured to appear based on permissions.

Go to Launchpad > Modeller > Work Types

Select the work type you wish to work on and then go to Portal Designer

Service Portfolios Creating a service portfolio will automatically create a permissions to access the portfolio, add this permission into your permissions sets to enable access.
Features Some product features allow the definition of permissions to access the feature.

Work Type Role Permissions

If global permissions control WHAT you can do, then role permissions control WHEN you can do it. Every organisation, team, or user has a role on a particular work type; the role permissions allocated to this role control what you can do on a work type.

Role permissions are limited to Read, Update, View Participants, and Assign Participants. Each user role on a work type should be granted role permissions.

 
 

Create a Permission Set

Create a Permission Set

You can create a permission set in administration. Permission sets can be assigned to teams or users.

To access permissions sets.

  1. Select LaunchpadGo to AdminSecurityGlobal Permissions - Granted
  2. You can now choose to create a whole new permission set, or copy and modify an existing permission set.

Creating a New Permission Set

  1. In the top right corner of the Global Permissions screen click Permission SetsAdd
  2. Enter Name and Description in their respective fields
  3. Your new permission set will be active by default, you can make it inactive by deselecting the Active check box
  4. Specify the global permissions of your new permission set by opening the top level drop down option (e.g. Admin) and selecting the check boxes of the permissions required (e.g. Admin Access)
  5. When you have added all the required permissions to your permission set, click Save

Cloning a Permission Set

  1. In the top right corner of the Global Permissions screen click Permission Sets
  2. Click on the burger menu of the permission set you want to copy > EditClone
  3. Enter Name and Description in their respective fields
  4. Your new permission set will be active by default, you can make it inactive by deselecting the Active check box
  5. You can modify your new permission set by opening the top level drop down option (e.g. Admin) and selecting or deselecting the required permissions
  6. When you have added all the required permissions to your permission set, click Save on the new permission set blade.

Review

You have now successfully created a permission set. Now you can assign permissions to a team or user.

 
 

Assign Permissions to a Team

Assign Permissions to a Team

You don't have to manage every user's permissions individually, you can assign permissions to a team. Every team member will then inherit those permissions.

  1. Select Launchpad > Go to Admin > Teams > Internal Teams or External Teams.
  2. Select the team to which you want to assign permissions and click on its burger menu. (We strongly recommend that you only apply permissions to access control teams (ACL), signified by the lock icon)
  3. View/Edit Permissions You could manually add permissions to the team here, but we recommend using a permission set as it makes permissions management much easier. You can assign a default permission set or learn to create your own here: Create a permission set.
  4. Click on the Permission Set icon > click the burger menu of the permission set you want to assign > Apply Permission Set.

Review

You have now successfully assigned permissions to a team, all the members of this team will be granted these permissions.

 
 

Work Type Role Permissions

Add a New Work-type Role Permission

Modeller > Work Types > Edit work type > Participant Roles > Click the arrow at the end of the row or Actions > Configure

Select the Role Permissions nav bar

Set the permission:

  • No will not grant the permission to holders of this role
  • Yes will grant the permission to holders of this role. Where this role is assigned to a team, all members of that team will be granted this permission.
  • User only will grant the permission to holders of this role, but only where the role is assigned directly to a user. When the role is assigned to a team, the members of that team will not be granted this permission.
  • By phase allows you to specify a variation in the permission grant depending on what phase the work item is in.  When you select By Phase the phases for that work type display - you can then set the permission for each phase.

 

 
 

 

Was this article helpful?

Related Articles

Related articles in the knowledge base