Design roles and keep duties apart

Create roles from the shipped templates, give them to people, and use access review to catch conflicting duties.

Required permission: member.view, member.manage

Before you begin

A role is a named bundle of permissions. People get roles; roles hold permissions. You need member.manage to change roles and member.view to read them.

Open Administration > Users > Roles. The list shows each role with what it is for, its Origin, how many things it can do, its Risk, and how many People hold it. Roles that say Comes with a2NSoft are shipped with the system. They are read-only. Roles that say Yours are your own.

Create a role

  1. Click New role.
  2. Type a Name of at least 2 characters. It must be unique in the company, otherwise: 'This company already has a role with that name.'
  3. Type What it is for (up to 400 characters), for example Runs the till.
  4. Optionally choose Start from a template such as Accountant. This fills in permissions and, if blank, the name and description. It is offered for new roles only.
  5. Tick the permissions the role needs, grouped by module. Ticking one also ticks what it depends on, with the note Also turned on, because the choice needs it. Unticking a base permission removes the ones that depend on it.
  6. Use the editor tools if the list is long: search the permissions, filter by All, Enabled, Disabled, Approval or High risk, or Copy permissions from a role.
  7. Click Save. Nothing is stored until you do; an Unsaved changes badge shows and leaving asks you to confirm.

Copy a shipped role

A shipped role cannot be edited. Open it and click Copy role, accept or change the default name <name> (copy), add a description, and save. Adjust the copy.

Give a role to people

  • From the role: choose Who has it, then give it to a member or take it off.
  • From the person: open Administration > Users > System users, the Roles tab, and tick or untick the role.

Changes apply at once.

Keep duties apart

Some pairs of roles should not be held by one person, for example one who grants access and also approves. Open Administration > Users > Access review. It shows four tiles (People, Duty conflicts, Exceptions in force, Never reviewed) and three lists: the conflicts found, the 18 conflict rules, and the people.

For each rule, click it and decide what the company does when somebody would hold both duties:

  • Record it and let it through
  • Refuse the grant
  • Accept the risk, which needs a Because of at least 10 characters ('Say why this risk is accepted.')

Once a rule is set to Refuse the grant, giving the second conflicting role on the user's Roles tab is refused with the conflict message.

Review a person's access

  1. In Access review, find the person and click Review.
  2. Choose the Conclusion: Access is right, Needs narrowing or Should be removed.
  3. Add a Note (up to 500 characters) and save.

The review records the date and the reviewer. It does not change access by itself; follow up on the user's record. You cannot review yourself: 'Somebody else has to review your access.' Use Why? next to a person to see, record by record, what they can do and the reason.

Worked example

You want accountants who post journals to be unable to also approve payments. Copy the shipped Accountant role as Journal poster, remove approval permissions, and set the matching conflict rule in Access review to Refuse the grant. Later a second administrator reviews each accountant and records Access is right.

Good to know

  • Menus follow permissions held through roles. Hiding a menu under Configuration > Menus never removes a permission.
  • The conflict check applies when you add a role on the user's Roles tab. The create-user wizard and Clone user do not run it, so review new users afterwards.
  • Renaming a role to a name another role already has is not stopped; keep names distinct yourself.
  • A company needs at least one administrator at all times.

See also Limit what people can see and do.