Role Edit Role

Company > Users > Roles > Role Edit Role

Users who have the capability to create and manage other user accounts are called user-administrators. This screen defines the scope of the roles that may be assigned user-administrators.

In special situations where specific users need to manually create and manage other user accounts, use the User edit roles screen instead to assign the permission to the specific user. However, assigning permission with this screen is a better practice.

Properties

Setup User Permission

Scope of roles that this role can access and edit on the Users screen. If 'Assigned Roles' is selected, the selected roles from the shuttle box are respected.

  • None — No specific permissions are assigned to this user account.
  • OWNED_USERS_ONLY — See only the accounts this user-administrator created.
  • ASSIGNED_ROLES_PERMISSION_RESTRICTED — Manage any account that has a role in the Member Edit Roles list and which has the same or more restrictive data access permissions.
  • ASSIGNED_ROLES (standard permission to assign) — Manage any account whose primary role is one of the roles specified in the Member Edit Roles list.
    Note: Member capabilities granted to individual users and User Edit Roles settings configured in Classic setup are not be configurable or respected by Admin Suite.
  • ALL_USERS — Manage any account that belongs to a roles specified in the Member Edit Roles list, and can view user accounts in other roles.. Further, user-administrators with full access to all data in the system can edit all user accounts.
Note: A user account with ALL_USERS on the User edit roles screen can manage any account, regardless of the user's role permissions specified on this screen.

When a user has ASSIGN_ROLES, but that user's primary role has ASSIGNED_ROLES_PERMISSION_RESTRICTED, the role's permission has priority.

Member Edit Roles
Only accounts with these roles may be edited or created by this user.

Troubleshooting tips

  • Verify this account's User Capabilities has Setup accounts.

  • Check the data scope of the User you are trying to give these admin capabilities to. If the User only has access to limited units / unit groups, they will only be able to edit the Users who have this same limited scope of data.