Granting and controlling authorisations

Every authorisation is made up of the action authorisation and the associated view authorisation.

An action authorisation determines who can call up an action. To allow individual assignments, there are various authorisation types.

The view permission, also referred to as the competence target, corresponds to an explicit definition of particular persons, groups, etc. that may be viewed when an action is carried out.
Example: in an evaluation list, the view permission defines persons or groups that can be called up in the query.

An authorisation for various actions can be assigned in two ways:

Assignment via the action

To assign the action authorisation directly via the action, call up the action overview under:

Menu and actions
--> Actions

Use the filter options or the search to call up the action for which authorisations are to be assigned/changed. Under the Authorisations tab you will find an overview of all action authorisations already assigned; they can also be deleted and edited here.

  • Authorisation for all clients: if this checkbox is activated, the authorisation check is not carried out when the action is called up. This means every user of every client is authorised to execute the action.
  • "View permission (default)": this setting relates to the parameter "Authorisation for all clients" above and defines the default view permission

The "New action authorisation" button can be used to add a new authorisation; the following options are configurable:

Type

Selection of the type for the action authorisation: client/group/person/role authorisation

Executor

Selection of the corresponding group/person/etc. for which the defined authorisation is to be valid

Negative

The negative authorisation is used to exclude someone from a general authorisation. If YES is selected here, the chosen group/role/person or the client may not call up the action.

Inherit authorisation to subgroups?

This parameter is only offered for the type "group authorisation": if the parameter is set to YES, all subgroups of the selected group can also access this action

View permission

Selection of the view permission

View access to subgroups?

Only for the type "group authorisation": if the parameter is set to YES, subgroups of the selected group can also be viewed.

Valid from

Start of validity of the authorisation (if nothing is specified, the current date)

Valid to

Expiry date of the authorisation (if nothing is specified, the longest possible validity)

Clicking "Save" applies the new authorisations and completes the process.

Assignment via person/group/role

Alternatively, authorisations can also be assigned directly via the respective group/person/role options. Here the selection of "authorisation type" and "executor" is omitted, since the authorisation is already defined explicitly for a person, group, role or client.

First call up, under

MASTER DATA
--> Persons/Groups/Roles

the corresponding person/group/role for which the action authorisation is to be assigned.

After selecting the corresponding subject you will find, under the "Action authorisations" tab, an overview of all actions for which an authorisation exists. The "New action authorisation" button can be used to assign a further authorisation; the following fields are to be filled in:

Name

Name of the action/configuration for which the authorisation is to be granted

Negative

The negative authorisation is used to exclude someone from a general authorisation. If YES is selected here, the chosen action may not be called up.

Valid from

Start of validity of the authorisation (if nothing is specified, the current date)

Valid to

Expiry date of the authorisation (if nothing is specified, the longest possible validity)

View permission

Selection of the view permission

Inherit view authorisation to subordinate groups

only when assigning via a group: if the parameter is set to YES, subgroups of the user's own group can also be viewed.

Clicking "Save" applies the new authorisations and completes the process

Kommentare (0)