brainX

Profiles

Package: BASIC

1. General

Info

Profiles control access to modules, their fields and functions.

Note

If multiple profiles are selected in the role configuration, the sum of positive permissions from all profiles always takes precedence!

Example

A role has been assigned two profiles. One profile allows the Invoices module to be seen, the other does not. Since the sum of positive permissions prevails, the user has the right to view the Invoices module.

2. Profile Overview

The profile overview displays all profiles in a table-like structure. The following columns are shown here:

  • No. → internal number of the profile
  • Name → name of the profile
  • Description → brief description of the profile
  • Roles → display of the assigned roles of the profile
  • Actions → for each profile, the actions "Copy", "Edit" and "Delete" are available here

globale_einstellungen_profile_uebersicht_monitor.pngList View Profiles

2.1. Creating a New Profile

New profiles can be created in two ways:

  • New profile → "New Profile" button in the profile overview
  • Copy profile → Click the "Actions" icon (icon "three dots") on an existing profile and then click the "Copy" action in the flyout menu.

2.1.1. New Profile

New profiles are created using the "New Profile" button. After clicking the button, the profile creation view opens.

After entering the profile name and an optional description, the module privileges can now be configured.

2.1.2. Copy Profile

To create profiles with similar attributes more quickly, it is possible to copy an existing profile.

In the "Actions" column, click the actions icon (icon "three dots") on the profile to be copied. A flyout menu opens with the actions Edit, Copy and Delete.

After clicking the "Copy" action, the profile creation view opens. All information from the underlying profile has been carried over.

The profile name must be reassigned, as identical profile names are not permitted.

For both the creation of a new profile and the creation by copying: to save the changes made, the "Save" button at the top right must be clicked at the end.

As soon as changes have been made to a profile, the rights must be recalculated. A corresponding notice is displayed after saving:

globale_einstellungen_benutzer_und_rechte_popup_aenderungen_erkannt.pngNotice: Changes Detected

Note

The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!

2.2. Editing a Profile

There are two ways to open the edit mode of a profile:

  • Click on the profile name in the profile overview
  • In the "Actions" column, click the actions icon (icon "three dots") on the profile to be edited and select the "Edit" action in the flyout menu.

After clicking the "Edit" action, the profile edit view opens.

globale_einstellungen_profil_bearbeiten_monitor.pngProfile Detail View

To apply the changes, the "Save" button must be clicked. As soon as changes have been made to a profile, the rights must be recalculated. A corresponding notice is displayed after saving:

globale_einstellungen_benutzer_und_rechte_popup_aenderungen_erkannt.pngNotice: Changes Detected

Note

The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!

2.3. Deleting a Profile

In the "Actions" column, click the actions icon (icon "three dots") on the profile to be deleted. A flyout menu opens with the actions Edit, Copy and Delete.

After clicking the "Delete" action, a confirmation dialog opens with the question "Are you sure you want to delete the profile "Profile name"?"

After clicking the "Confirm" button, the profile is deleted.

Note

A profile can only be deleted if it is no longer used in any role.

If the profile is still being used in a role, a corresponding dialog "Deletion not possible" is displayed, which lists the role(s) in which the profile is still in use.

2.4. Searching in Profiles

In the "Search for profiles" input field, the searched names/terms can be entered. After pressing the Enter key, the search is started. The list view of profiles is reloaded and – if there are matches – restricted to the matching profiles.

Only the "Name" column is searched! The description and role names are ignored!

Case sensitivity is ignored in the search. It is also irrelevant whether the search term is at the beginning, middle or end of the found value.

3. Profile View

When a profile is opened from the list view, the detail view of the profile is displayed, showing both the profile information and the module privileges.

globale_einstellungen_profil_bearbeiten_monitor.pngProfile Detail View

3.1. Profile Information

The following fields are available in the "Profile Information" block:

  • Profile name → name of the profile
  • Description → brief description of the profile

3.2. Module Privileges

The "Module Privileges" block displays all module permissions in a table-like structure. The module permissions can be configured here on a module-by-module basis.

The following columns are displayed:

  • Module → module name and the "Read access" toggle
  • Permissions → display of permissions (no access, edit and delete)
  • Active Fields → number of total and active fields
  • Read-only Fields → number of total and active read-only fields

3.2.1. Module Permissions

Permissions can be configured on a module-by-module basis. If read access for a module has been activated, the permissions for viewing/editing individual fields can be set at field level. The use of tools (e.g. merge duplicates and PDF export) can also be controlled here.

Note

If the Comments module is not activated for a profile, users with this profile cannot see comments in the detail views of records. If the Comments module is active, however, comments are displayed in the detail view of all modules, provided the user has the right to see the respective record.

3.2.1.1. Read Access

The "Read access" toggle in the "Module" column determines whether a profile – or the assigned users and groups of the profile – has read access to a module. If no read access is configured, access to the module is not possible.

If read access is active, additional edit and delete permissions can be configured. Field and action permissions can also only be granted if read access for a module has been permitted.

3.2.1.2. Edit and Delete Permission

If read access has been activated for a module, the "Permissions" column can now be used to configure whether records in the module can only be edited, or edited and deleted.

globale_einstellungen_profil_bearbeiten_spalte_berechtigungen.pngProfile - Configure Permission

3.2.1.3. Field and Action Permissions

After clicking a module name, the sidebar for configuring the module's permissions opens.

The sidebar is divided into two tabs:

3.2.1.3.1. Permissions for Individual Fields

globale_einstellungen_profil_bearbeiten_modulberechtigungen_felder.pngSidebar of Module Permissions for Fields

The "active/inactive" toggle controls whether a field is displayed. The "Pencil" actions icon configures whether a field is read-only or editable.

Note

Required fields must always be enabled for write access and are therefore not editable in the permission settings.

In the profile overview, the number of total and active fields is displayed in the "Active Fields" column, and the number of total and active read-only fields in the "Read-only Fields" column.

3.2.1.3.2. Permissions for Using Tools

globale_einstellungen_profil_bearbeiten_modulberechtigungen_werkzeuge.pngSidebar of Module Permissions for Tools

The "active/inactive" toggle controls whether a tool is displayed for a profile – or the assigned users and groups of the profile.

"Tools" generally refers to all types of actions. See also the sections Actions (List View) and Actions (Detail View).

3.2.2. Actions Button

The "Actions" button is displayed at the top right in the "Module Privileges" block. The actions available here allow certain permissions to be configured for a profile that are valid for all modules without having to configure each module individually.

After clicking, a flyout menu opens with the following actions:

  • May view all modulesread access is activated for all modules
  • May view no moduleread access is deactivated for all modules
  • "Edit" for active modules → the "edit" permission is granted for all active modules (read access is activated)
  • "Edit and delete" for active → the "edit" and "delete" permission is granted for all active modules (read access is activated)

globale_einstellungen_profil_bearbeiten_button_aktionen.pngModule Privileges - Actions Button - Flyout Menu

3.3. Functions

The "Functions" block displays the permissions in a table-like structure. The permissions of functions can be configured here per function.

The following columns are displayed:

  • Module → module/function name and the "Read access" toggle
  • Permissions → no explicit display of permissions for functions
  • Active Fields → number of total and active fields (only for Product Block)
  • Read-only Fields → number of total and active read-only fields

3.3.1. Function Permissions

The "Functions" block lists three modules/functions:

3.3.1.1. Read Access

The "Read access" toggle in the "Module" column determines whether a profile – or the assigned users and groups of the profile – has access to a function. If no read access is configured, access to the function is not possible.

3.3.1.2. Field and Action Permissions
Note

Field-level permissions are only available for the product block. Action permissions are not possible here.

After clicking the "Product Block" function, the sidebar for configuring field permissions opens.

The sidebar is divided into two tabs:

  • Fields → settings for individual field permissions, see section Permissions for Individual Fields
  • Tools → No configuration options are available in the "Tools" tab.

globale_einstellungen_profil_bearbeiten_berechtigungen_fuer_produktblock.pngSidebar of Permissions for Product Block Fields

4. Practical Examples

1 – Profile for field sales without purchase prices

The field sales team should be able to create quotes but not see purchase prices or contribution margins. A new profile Field Sales is created. For the Quotes module, read access is enabled and the Edit permission is granted. In the Fields tab for the module, the fields Purchase Price and Contribution Margin are deactivated. The profile is assigned to the role Sales Employee Field.

2 – Profile for accounting: full access to invoices, read-only for customers

The accounting team should be able to fully edit invoices but only read customer data. A profile Accounting is created. For the Invoices module, read access + Edit is enabled. For the Organizations module, only read access is activated — the Edit permission remains disabled. The profile is assigned to the Accounting role.

3 – Profile for external service providers: restricted module selection

External service providers should only see the Tasks module — no access to customers, quotes, or invoices. Using the Actions → No modules visible button, all read accesses are deactivated first. Then, only the Tasks module is manually re-enabled for read access. The completed profile is assigned to the External Service Provider role.

4 – Quickly adapt a profile by copying

An existing profile Sales Standard should serve as the basis for a new profile Sales Senior that additionally allows deleting deals. Via the Copy action on the Sales Standard profile, the creation view opens. The profile name is changed to Sales Senior and the Edit and Delete permission is activated for the Deals module. After saving and recalculating permissions, the new profile is ready for role assignment.

5. Frequently Asked Questions

What happens when multiple profiles are assigned to a role?

The sum of positive permissions applies: if even one of the assigned profiles grants read access to a module or allows an action, the user has that right. Profiles cannot restrict each other — they can only add permissions.

Can I delete a profile that is still assigned to a role?

No. Before a profile can be deleted, it must be removed from all roles. brainX shows which roles are still using the profile when a deletion attempt is made.

What is the difference between "deactivating a field" and "setting a field to read-only"?

A deactivated field is invisible to the user — they cannot see it or fill it in. A read-only field is visible but cannot be edited. For fields the user should see for reference but not change (e.g. status fields), read-only is appropriate; for sensitive data (e.g. purchase prices), deactivating is the better choice.

Why are required fields not editable in the field permissions?

Required fields must always be available for write access because a record cannot be saved without them. brainX therefore automatically locks these fields in the profile configuration.

When must "Recalculate now" be clicked after a profile change?

After every change and save of a profile. Only after clicking Recalculate now do the changed permissions take effect in the permission system and become visible to users.