Roles
Package: BASIC
1. General
For a better understanding of the significance of roles, here is a brief overview.
- Roles: Control access to records, to my records and to subordinate roles. Every role has at least one profile.
- Profiles: Control access to modules and their fields.
- Role + Profile: The sum of positive rights applies.
- Groups: Used to share records. Recommendation: Create groups from users or roles and subordinates only.
- Custom Access Rules: Can be used to override part of the permissions/rights.
As a general rule:
- Profiles are for modules
- Roles are for the hierarchy
In contrast to the role concept, the regulation of which modules are available to which user is handled in Profiles.
2. Hierarchy View of Roles
The role concept of brainX is structured hierarchically. The hierarchy determines which records a user can see across all modules.
The hierarchy view graphically shows which roles can see which data:
Role Hierarchy View
As a general rule, a superior role can always view all data of the roles subordinate to it. Access to data of a superior role does not exist unless exceptions have been defined in the Global Rights Assignment. The same behavior also applies to roles at the same level.
3. Creating a New Role
New roles can be created in two ways:
- Button "New Role" in the "Organisation" role area
- Actions icon "New Role" (icon "plus") which is displayed on mouseover of a role. The new role is then created directly below the relevant role in the hierarchy tree.
4. Editing a Role
On mouseover of a role, the "Actions" icon (icon "three dots") is displayed. After clicking the "Actions" icon, the actions menu opens with the following actions:
- Edit role
- Copy role
- Delete role
Roles - Actions Menu
After clicking the "Edit role" action, the "Edit role" popup opens. Both the role name and the assigned profiles can be changed.
To apply the changes, the "Save" button must be clicked. As soon as changes have been made to a role, the rights must be recalculated. A corresponding notice is displayed after saving:
Notice: Changes Detected
The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!
Users assigned to the role will see the change after the next click in the brainX system, as the changes take effect immediately after a browser reload.
If a user is in a module at the time the role is saved that will be denied to them in the future, they will be notified after the next click in the locked module.
If a user is making changes to a record in the future locked module at this time, unsaved changes to the record will be lost in this case!
5. Copying a Role
On mouseover of a role, the "Actions" icon (icon "three dots") is displayed. After clicking the "Actions" icon, the actions menu opens with the following actions:
- Edit role
- Copy role
- Delete role
Roles - Actions Menu
After clicking the "Copy role" action, the "Copy role" popup opens. The role name, the superior, and the assigned profiles can be changed.
To apply the changes, the "Save" button must be clicked. When a new role is created, the rights must be recalculated. A corresponding notice is displayed after saving:
Notice: Changes Detected
The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!
6. Deleting a Role
On mouseover of a role, the "Actions" icon (icon "three dots") is displayed. After clicking the "Actions" icon, the actions menu opens with the following actions:
- Edit role
- Copy role
- Delete role
Roles - Actions Menu
After clicking the "Delete role" action, the "Delete role" popup opens. A replacement role must now be selected.
All users who were previously subject to the role being deleted will subsequently be transferred to the selected role.
To apply the changes, the "Confirm" button must be clicked.
When deleting a role – unlike other actions on roles – no recalculation in the rights system is necessary.
Users assigned to the role will see the change after the next click in the brainX system, as the changes take effect immediately after a browser reload.
If a user is in a module at the time the role is saved that will be denied to them in the future, they will be notified after the next click in the locked module.
If a user is making changes to a record in the future locked module at this time, unsaved changes to the record will be lost in this case!
7. Moving a Role
Moving a role is done using drag & drop. The role to be moved is simply dragged to the desired position in the hierarchy tree.
As soon as changes have been made to a role, the rights must be recalculated. A corresponding notice is displayed after saving:
Notice: Changes Detected
The changes in the rights system are only recalculated and take effect after clicking the "Recalculate now" button!
Users assigned to the role will see the change after the next click in the brainX system, as the changes take effect immediately after a browser reload.
If a user is in a module at the time the role is saved that will be denied to them in the future, they will be notified after the next click in the locked module.
If a user is making changes to a record in the future locked module at this time, unsaved changes to the record will be lost in this case!
8. Practical Examples
1 – Building a sales role hierarchy
A company structures its sales organization across three levels: Sales Management, Team Lead Sales, and Sales Employee. The role Sales Employee is created directly below Team Lead Sales — the team lead can therefore see all their employees' records. Sales Management is positioned above Team Lead Sales and thus has visibility into the data of both levels below.
2 – Creating a role for external service providers
External service providers should maintain their own records but not see data belonging to other users. A new role External Service Provider is created directly below the organization role, without assigning it under any sales role. The assigned profile only allows access to the Tasks module. Since there are no subordinate roles, users in this role see only their own records.
3 – Creating an intern role by copying an existing role
A company wants to create a new role Sales Intern that is nearly identical to Sales Employee — but without delete permissions. Via Copy Role on the Sales Employee role, the creation view opens. The name is changed to Sales Intern and a profile without delete rights is assigned. After saving and recalculating, the role is ready for user assignment.
9. Frequently Asked Questions
How does a role's position in the hierarchy tree affect data visibility?
A superior role always sees all records of the roles below it. Roles at the same level cannot see each other's data — unless custom access rules are configured in the Global Permission Assignment. The higher a role is in the hierarchy, the more data is visible.
What happens to the users of a deleted role?
When deleting a role, a replacement role must be specified. All users of the deleted role are automatically transferred to the replacement role. A permission recalculation is not required in this case.
Must "Recalculate now" be clicked after every role change?
Yes — for all changes except deleting a role. Only after recalculation do changed permissions take effect for the affected users. Deleting a role is the only exception where no recalculation is required.
Can a role have multiple profiles?
Yes. A role can have multiple profiles assigned. The sum of positive permissions of all profiles applies: if even one profile grants read access to a module, the user receives that access.