Granting and controlling authorisations
Every authorisation is made up of the action authorisation and the associated view authorisation.
An action authorisation determines who can call up an action. To allow individual assignments, there are various authorisation types.
The view permission, also
referred to as the competence target, corresponds to an
explicit definition of particular persons, groups, etc. that may be viewed when
an action is carried out.
Example: in an evaluation list, the view permission defines persons or
groups that can be called up in the query.
An authorisation for various actions can be assigned in two ways:
Assignment via the action
To assign the action authorisation directly via the action, call up the action overview under:
Menu and actions
--> Actions
Use the filter options or the search to call up the action for which authorisations are to be assigned/changed. Under the Authorisations tab you will find an overview of all action authorisations already assigned; they can also be deleted and edited here.
- Authorisation for all clients: if this checkbox is activated, the authorisation check is not carried out when the action is called up. This means every user of every client is authorised to execute the action.
- "View permission (default)": this setting relates to the parameter "Authorisation for all clients" above and defines the default view permission
The "New action authorisation" button can be used to add a new authorisation; the following options are configurable:
|
Type |
Selection of the type for the action authorisation: client/group/person/role authorisation |
|---|---|
|
Executor |
Selection of the corresponding group/person/etc. for which the defined authorisation is to be valid |
|
Negative |
The negative authorisation is used to exclude someone from a general authorisation. If YES is selected here, the chosen group/role/person or the client may not call up the action. |
|
Inherit authorisation to subgroups? |
This parameter is only offered for the type "group authorisation": if the parameter is set to YES, all subgroups of the selected group can also access this action |
|
View permission |
Selection of the view permission |
|
View access to subgroups? |
Only for the type "group authorisation": if the parameter is set to YES, subgroups of the selected group can also be viewed. |
|
Valid from |
Start of validity of the authorisation (if nothing is specified, the current date) |
|
Valid to |
Expiry date of the authorisation (if nothing is specified, the longest possible validity) |
Clicking "Save" applies the new authorisations and completes the process.
Assignment via person/group/role
Alternatively, authorisations can also be assigned directly via the respective group/person/role options. Here the selection of "authorisation type" and "executor" is omitted, since the authorisation is already defined explicitly for a person, group, role or client.
First call up, under
MASTER DATA
--> Persons/Groups/Roles
the corresponding person/group/role for which the action authorisation is to be assigned.
After selecting the corresponding subject you will find, under the "Action authorisations" tab, an overview of all actions for which an authorisation exists. The "New action authorisation" button can be used to assign a further authorisation; the following fields are to be filled in:
|
Name |
Name of the action/configuration for which the authorisation is to be granted |
|---|---|
|
Negative |
The negative authorisation is used to exclude someone from a general authorisation. If YES is selected here, the chosen action may not be called up. |
|
Valid from |
Start of validity of the authorisation (if nothing is specified, the current date) |
|
Valid to |
Expiry date of the authorisation (if nothing is specified, the longest possible validity) |
|
View permission |
Selection of the view permission |
|
Inherit view authorisation to subordinate groups |
only when assigning via a group: if the parameter is set to YES, subgroups of the user's own group can also be viewed. |
Clicking "Save" applies the new authorisations and completes the process
Keine Kommentare vorhanden.