Roles
Roles are sets of permissions that determine the access and capabilities of a User. Every User is assigned at least one primary role, but they can also have multiple secondary roles. Each role has unique permissions and capabilities.
Properties
- Name
- Name of the role
- Role Type
- Identifies the role as the company-wide role (COMPANY), or a sub-role (NORMAL) that defines permissions for related user accounts. The COMPANY role is created automatically by the system and assigned to the company-level Unit Group. All roles created on this screen are NORMAL roles.
- Category (optional)
Groups all definitions with the same Category value together, which can make them easier to find on the list. Definitions are ordered by Priority inside each category. Definitions with no Category value are listed underneath. Use the filter above the list to see just the definitions of the selected category.
The act of assigning a definition to a category that doesn't exist creates a new category. Note that category names are case sensitive.Note: To delete or change the name of a Category, simply change the Category value in each of the definitions that belongs to it.- Priority
- Relative position of this definition to others when included in a list; lower values appear first and blanks appear at the top in alphabetical order.
- Description
- Description of the purpose of this role. Should include a general description of the permissions and capabilities.
- IP allow-list
-
List of IP addresses (one per line) that are allowed to sign in with this role as their primary role. This option is not available to "all" global role that is the top-most role in the company,
See Logon Restrictions for detailed information about using this option.
- Language
-
Spoken language used for emails and push reports to Users with this primary Role.
This does not affect the User account's language.
Note: Avoid using this option, it doesn't work as expected. - Time Zone
- Formats date-time values for user’s with this Role. When a User has multiple Roles, the system chooses the user’s Primary Role.
- Org Hierarchy
- Selects a Unit Group to use as the top-level group when displaying the organization hierarchy in report filters. The allows the hierarchy to change when the user switches roles, and it can be used to limit the groups the users see. The default value is None , which means the role can see all groups in the company.
- Password Policy
- Selects the Password policies that apply restrictions to user passwords, based on the account's primary role. All users without an explicitly assigned policy use the default policy.
- Guest Segment
-
Limits the role's access to records matching this segment. Choose All Units to allow access to all records — access permissions settings can still limit the records this role can view.
For example, consider a Segment Group called Survey Type that contains Segments that each identify a type of survey the company employs:
Survey Type Sales Service Repairs PartsSetting the role's segment to Sales limits this role to only seeing survey responses for the Sales survey type; the role will not be able to see results for the other types.
Depending on how the Segment Group is defined, you can select a segment from the group, a value from a field in the group, or a field from the group.
- When the Group contains at least one Segment, the list shows just the segment(s). Otherwise,
- When the group has one field assigned to it, the list shows all the values available for the field (based on the AltSet).
- When the group has multiple fields assigned, this list shows those fields. Note: This configuration has no effect on access; all records are still available.
Warning: To be an effective filter and limit access to records, the selection needs to be a segment, or a field value. Just picking a field does not limit access. - Member Capabilities
-
Capabilities specifically granted to this role. These selections add to the capabilities granted to the user's account, if any.
Capabilities are hierarchical in that some are parents to others. Selecting a parent capability grants access to all of the capabilities that one contains. For example, to see the graph on the Satisfaction report, a user needs the View Satisfaction Graph capability. You can assign that access to a role and all of the users of that role will see the graph, but none of the other features of the Satisfaction report. However, selecting the View Satisfaction capability grants access to all of the report features.
For a complete list of the available capabilities, see Capabilities.
- Member Permission Contexts
- Permission contexts specifically granted to this role. These selections add to the permissions granted to the user's account, if any. See Roles, permissions, and capabilities for details.
