View permission
The view permission serves as a further control element when assigning
authorisations, since it defines the competence target.
The competence target determines who may be viewed when an action is carried
out, and for whom particular requests may be submitted.
The view permission is - except in the case of role competence - determined directly when the action authorisation is assigned (via action or via person/group/client). In the case of role competence it is already defined on the role.
Where there are several view permissions they are added together > e.g. with a view permission for an org unit AND additionally a view permission according to role competence (for example for group A1), the role holders have view access to both: the org unit AND group A1.
View permission: own person
The view permission applies only to the person themselves, i.e. in evaluations or lists only their own data is displayed, and requests may only be submitted for themselves.
View permission: org unit
Only the user's own department (team, group, ...) may be viewed. This is useful, for example, for the group calendar, where all colleagues from the department are displayed. This view permission is also useful for sick leave notifications, since all colleagues from the user's own department are then displayed and can therefore be selected.
View permission: org unit and subordinate units
The view permission applies to the user's own department and the departments (groups, ...) subordinate to it, i.e. all groups that lie hierarchically below it.
View permission according to role competence
Here the view permission is assigned according to the role competence. The role competence has already been defined directly on the role:
- Competence target Person > only one particular person may be viewed
- Competence target Group > view permission for a particular group
- Competence target All > view access to all employees in the company
Several assignments can be made independently of one another, for example: the role holder sees a particular group and individual persons from other groups.
If the respective competence target has already been defined on the role, it does not have to be entered again here; it is simply assigned according to the role competence.
View permission: client
The view permission extends to all persons of the user's own client, i.e. all employees are also displayed:
View permission: all clients
The view permission extends to all persons of all clients.
View permission: special
With group and person authorisations there is also the
option of selecting a special view permission.
This special view permission allows individual persons (several as well) from
different groups, or several groups at once, to be selected. This parameter
saves having to enter various groups and/or persons repeatedly, since several
can be selected at the same time.
Keine Kommentare vorhanden.