Profiles
Package: BASIC
1. General
Profiles control access to modules, their fields and functions.
If multiple profiles are selected in the role configuration, the sum of positive permissions from all profiles always takes precedence!
A role has been assigned two profiles. One profile allows the Invoices module to be seen, the other does not. Since the sum of positive permissions prevails, the user has the right to view the Invoices module.
2. Profile Overview
The profile overview displays all profiles in a table-like structure. The following columns are shown here:
- No. → internal number of the profile
- Name → name of the profile
- Description → brief description of the profile
- Roles → display of the assigned roles of the profile
- Actions → for each profile, the actions "Copy", "Edit" and "Delete" are available here
List View Profiles
2.1. Creating a New Profile
New profiles can be created in two ways:
- New profile → "New Profile" button in the profile overview
- Copy profile → Click the "Actions" icon (icon "three dots") on an existing profile and then click the "Copy" action in the flyout menu.
2.1.1. New Profile
New profiles are created using the "New Profile" button. After clicking the button, the profile creation view opens.
After entering the profile name and an optional description, the module privileges can now be configured.
2.1.2. Copy Profile
To create profiles with similar attributes more quickly, it is possible to copy an existing profile.
In the "Actions" column, click the actions icon (icon "three dots") on the profile to be copied. A flyout menu opens with the actions Edit, Copy and Delete.
After clicking the "Copy" action, the profile creation view opens. All information from the underlying profile has been carried over.
The profile name must be reassigned, as identical profile names are not permitted.
For both the creation of a new profile and the creation by copying: to save the changes made, the "Save" button at the top right must be clicked at the end.
As soon as changes have been made to a profile, the rights must be recalculated. A corresponding notice is displayed after saving:
Notice: Changes Detected
The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!
2.2. Editing a Profile
There are two ways to open the edit mode of a profile:
- Click on the profile name in the profile overview
- In the "Actions" column, click the actions icon (icon "three dots") on the profile to be edited and select the "Edit" action in the flyout menu.
After clicking the "Edit" action, the profile edit view opens.
Profile Detail View
To apply the changes, the "Save" button must be clicked. As soon as changes have been made to a profile, the rights must be recalculated. A corresponding notice is displayed after saving:
Notice: Changes Detected
The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!
2.3. Deleting a Profile
In the "Actions" column, click the actions icon (icon "three dots") on the profile to be deleted. A flyout menu opens with the actions Edit, Copy and Delete.
After clicking the "Delete" action, a confirmation dialog opens with the question "Are you sure you want to delete the profile "Profile name"?"
After clicking the "Confirm" button, the profile is deleted.
A profile can only be deleted if it is no longer used in any role.
If the profile is still being used in a role, a corresponding dialog "Deletion not possible" is displayed, which lists the role(s) in which the profile is still in use.
2.4. Searching in Profiles
In the "Search for profiles" input field, the searched names/terms can be entered. After pressing the Enter key, the search is started. The list view of profiles is reloaded and – if there are matches – restricted to the matching profiles.
Only the "Name" column is searched! The description and role names are ignored!
Case sensitivity is ignored in the search. It is also irrelevant whether the search term is at the beginning, middle or end of the found value.
3. Profile View
When a profile is opened from the list view, the detail view of the profile is displayed, showing both the profile information and the module privileges.
Profile Detail View
3.1. Profile Information
The following fields are available in the "Profile Information" block:
- Profile name → name of the profile
- Description → brief description of the profile
3.2. Module Privileges
The "Module Privileges" block displays all module permissions in a table-like structure. The module permissions can be configured here on a module-by-module basis.
The following columns are displayed:
- Module → module name and the "Read access" toggle
- Permissions → display of permissions (no access, edit and delete)
- Active Fields → number of total and active fields
- Read-only Fields → number of total and active read-only fields
3.2.1. Module Permissions
Permissions can be configured on a module-by-module basis. If read access for a module has been activated, the permissions for viewing/editing individual fields can be set at field level. The use of tools (e.g. merge duplicates and PDF export) can also be controlled here.
If the Comments module is not activated for a profile, users with this profile cannot see comments in the detail views of records. If the Comments module is active, however, comments are displayed in the detail view of all modules, provided the user has the right to see the respective record.
3.2.1.1. Read Access
The "Read access" toggle in the "Module" column determines whether a profile – or the assigned users and groups of the profile – has read access to a module. If no read access is configured, access to the module is not possible.
If read access is active, additional edit and delete permissions can be configured. Field and action permissions can also only be granted if read access for a module has been permitted.
3.2.1.2. Edit and Delete Permission
If read access has been activated for a module, the "Permissions" column can now be used to configure whether records in the module can only be edited, or edited and deleted.
Profile - Configure Permission
3.2.1.3. Field and Action Permissions
After clicking a module name, the sidebar for configuring the module's permissions opens.
The sidebar is divided into two tabs:
- Fields → Permissions for individual fields
- Tools → Permissions for using tools
3.2.1.3.1. Permissions for Individual Fields
Sidebar of Module Permissions for Fields
The "active/inactive" toggle controls whether a field is displayed. The "Pencil" actions icon configures whether a field is read-only or editable.
Required fields must always be enabled for write access and are therefore not editable in the permission settings.
In the profile overview, the number of total and active fields is displayed in the "Active Fields" column, and the number of total and active read-only fields in the "Read-only Fields" column.
3.2.1.3.2. Permissions for Using Tools
Sidebar of Module Permissions for Tools
The "active/inactive" toggle controls whether a tool is displayed for a profile – or the assigned users and groups of the profile.
"Tools" generally refers to all types of actions. See also the sections Actions (List View) and Actions (Detail View).
3.2.2. Actions Button
The "Actions" button is displayed at the top right in the "Module Privileges" block. The actions available here allow certain permissions to be configured for a profile that are valid for all modules without having to configure each module individually.
After clicking, a flyout menu opens with the following actions:
- May view all modules → read access is activated for all modules
- May view no module → read access is deactivated for all modules
- "Edit" for active modules → the "edit" permission is granted for all active modules (read access is activated)
- "Edit and delete" for active → the "edit" and "delete" permission is granted for all active modules (read access is activated)
Module Privileges - Actions Button - Flyout Menu
3.3. Functions
The "Functions" block displays the permissions in a table-like structure. The permissions of functions can be configured here per function.
The following columns are displayed:
- Module → module/function name and the "Read access" toggle
- Permissions → no explicit display of permissions for functions
- Active Fields → number of total and active fields (only for Product Block)
- Read-only Fields → number of total and active read-only fields
3.3.1. Function Permissions
The "Functions" block lists three modules/functions:
- Product Block → settings for the product block in billing modules
- Change Tracking → permission for displaying change tracking
- Digital Assistant - brainX Support → permission to use the Digital Assistant - brainX Support
3.3.1.1. Read Access
The "Read access" toggle in the "Module" column determines whether a profile – or the assigned users and groups of the profile – has access to a function. If no read access is configured, access to the function is not possible.
3.3.1.2. Field and Action Permissions
Field-level permissions are only available for the product block. Action permissions are not possible here.
After clicking the "Product Block" function, the sidebar for configuring field permissions opens.
The sidebar is divided into two tabs:
- Fields → settings for individual field permissions, see section Permissions for Individual Fields
- Tools → No configuration options are available in the "Tools" tab.
Sidebar of Permissions for Product Block Fields
4. Practical Examples
1 – Profile for field sales without purchase prices
The field sales team should be able to create quotes but not see purchase prices or contribution margins. A new profile Field Sales is created. For the Quotes module, read access is enabled and the Edit permission is granted. In the Fields tab for the module, the fields Purchase Price and Contribution Margin are deactivated. The profile is assigned to the role Sales Employee Field.
2 – Profile for accounting: full access to invoices, read-only for customers
The accounting team should be able to fully edit invoices but only read customer data. A profile Accounting is created. For the Invoices module, read access + Edit is enabled. For the Organizations module, only read access is activated — the Edit permission remains disabled. The profile is assigned to the Accounting role.
3 – Profile for external service providers: restricted module selection
External service providers should only see the Tasks module — no access to customers, quotes, or invoices. Using the Actions → No modules visible button, all read accesses are deactivated first. Then, only the Tasks module is manually re-enabled for read access. The completed profile is assigned to the External Service Provider role.
4 – Quickly adapt a profile by copying
An existing profile Sales Standard should serve as the basis for a new profile Sales Senior that additionally allows deleting deals. Via the Copy action on the Sales Standard profile, the creation view opens. The profile name is changed to Sales Senior and the Edit and Delete permission is activated for the Deals module. After saving and recalculating permissions, the new profile is ready for role assignment.
5. Frequently Asked Questions
What happens when multiple profiles are assigned to a role?
The sum of positive permissions applies: if even one of the assigned profiles grants read access to a module or allows an action, the user has that right. Profiles cannot restrict each other — they can only add permissions.
Can I delete a profile that is still assigned to a role?
No. Before a profile can be deleted, it must be removed from all roles. brainX shows which roles are still using the profile when a deletion attempt is made.
What is the difference between "deactivating a field" and "setting a field to read-only"?
A deactivated field is invisible to the user — they cannot see it or fill it in. A read-only field is visible but cannot be edited. For fields the user should see for reference but not change (e.g. status fields), read-only is appropriate; for sensitive data (e.g. purchase prices), deactivating is the better choice.
Why are required fields not editable in the field permissions?
Required fields must always be available for write access because a record cannot be saved without them. brainX therefore automatically locks these fields in the profile configuration.
When must "Recalculate now" be clicked after a profile change?
After every change and save of a profile. Only after clicking Recalculate now do the changed permissions take effect in the permission system and become visible to users.