Assigning permissions to a role or group
Who is this article for?
Administrators responsible for managing access to the system.
Administrator permissions are required.
Permissions are never given to a user directly. They always inherits them from the groups they belong to and the roles they hold.
This article explains the difference between roles and groups, and how to assign permissions to each.
Difference between a role and group
Both roles and groups carry permissions, but they apply those permissions in very different ways.:
- Roles are the positions a user holds on a specific record. For example, Risk Manager, Owner, or Stakeholder.
Permissions from a role apply only to the records where the user holds that role. - Groups are collections of users. Permissions from a group apply everywhere, to every record that member can already see. Groups also drive what data users can see by being linked to locations and processes.
Permissions are never given to a user directly, a user always inherits them from the Groups they belong to and the Roles they hold.
Assigning permissions to a role
A role's permissions are tied to the object types it applies to, so you must set those first. The Add option in the Permissions tab stays unavailable until the role applies to at least one object type.
To assign permissions to a role:
- Open the More... menu.
- Select Roles (under Authorization).
- Open the role you want to change by clicking its name.
- Go to the Applies to tab.
- Check that the role has at least one object type assigned.
If it does not, add the object types first. - Go to the Permissions tab.
- Click Add Permissions.
- Select the permissions you want to grant by ticking their boxes.
Only permissions relevant to the role's object types are shown. - Click Save.
You will be returned to the Permissions tab, where you can review the permissions now assigned to the role. Anyone who holds this role will have these permissions the next time they sign in.
Tip
Keep roles focused. Grant only the permissions the role genuinely needs, so access stays easy to understand and audit.
Assigning permissions to a group
To assign permissions to a group:
- Open the More... menu.
- Select Groups (under Authorization).
- Open the group by clicking its name.
- Go to the Permissions tab.
- Click Add Permissions.
- Select the permissions you want to grant by ticking their boxes.
- Click Save.
Every member of the group gains these permissions for all records they can already see. Permissions from groups are additive; a user gets the combined permissions of every group they belong to.