brainX

Users and Rights

Package: BASIC

1. Rights Management

Note

Depending on requirements, rights management can be very complex. Changes to permissions should therefore be made with particular care to avoid unintended access rights or functional restrictions.

brainX has a very extensive rights management system. The rights settings allow you to define:

  • which user is allowed to see/edit which modules
  • which user is allowed to see/edit which fields within a module
  • which user is allowed to perform which actions
  • which user is allowed to see/edit/delete which records
  • which user has administrative rights

The rights settings are configured via Global Rights Assignment as well as Roles, Profiles, Users and Groups.

The rights settings are accessed via "Global Settings → Users and Rights".

globale_einstellungen_benutzer_und_gruppen_monitor.pngGlobal Settings - Users and Groups

2. Administrative Rights

Independently of roles and profiles, it is possible to grant a user administrative rights.

Administrative rights are granted using the "Rights Management" field in the user settings. At user level, the following settings are distinguished for rights management:

  • –none– = The user has no administrative rights whatsoever and is fully subject to the role concept.
  • Admin = This is the highest level of this setting. A user with this permission may configure, create and delete everything. A user with this attribute is not subject to record authorization and therefore not only ignores the role hierarchy, but also the client check!
  • CustomerAdmin = This is one level below the Admin. A user with the "CustomerAdmin" attribute is not subject to record authorization and therefore not only ignores the role hierarchy, but also the client check!
    Permissions/Restrictions:
    • They may not delete or create Admin and CustomerAdmin users.
  • Superuser = A user with additional, restricted administrative permissions (permissions are applied with regard to roles and profiles).
    Permissions/Restrictions:

3. Quick Reference: Roles, Profiles and Groups

  • Roles: Control access to records, to my records and to subordinate roles. Every role has at least one profile.
  • Profiles: Control access to modules and their fields.
  • Role + Profile: The sum of positive rights applies.
  • Groups: Used to share records.
    Recommendation: Create groups from users or roles and subordinates only.
  • Custom Access Rules: Can be used to override part of the permissions/rights.
Note

As a general rule:

  • Profiles are for modules
  • Roles are for the hierarchy

Detailed information on the individual topics can be found in the following sections: