User edit roles

Company > Users > Users > User Edit Roles

Users who have the capability to create and manage other user accounts are called user-administrators. This screen defines the scope of the accounts that specific user-administrators may access.

To be a user-administrator, the user needs the Setup Accounts capability. Accounts with this capability may access the Users screen.

Warning: Use this feature only in special situations where users need to manually create and manage other user accounts. It is better practice to use Role Edit Role and grant the permissions to an entire role.

Properties

Setup User Permission

Scope of users the this user administrator can access and edit on the Users screen; the administrator only sees accounts in this scope.

  • None — No specific permissions are assigned to this user account.
  • OWNED_USERS_ONLY — See only the accounts this user-administrator created.
  • ASSIGNED_ROLES_PERMISSION_RESTRICTED — Manage any account that has a role in the Member Edit Roles list and which has the same or more restrictive data access permissions.
  • ASSIGNED_ROLES (standard permission to assign) — Manage any account whose primary role is one of the roles specified in the Member Edit Roles list.
    Note: Member capabilities granted to individual users and User Edit Roles settings configured in Classic setup are not be configurable or respected by Admin Suite.
  • ALL_USERS — Manage any account that belongs to a roles specified in the Member Edit Roles list, and can view user accounts in other roles.. Further, user-administrators with full access to all data in the system can edit all user accounts.
Note: A user account with ALL_USERS can manage any account, regardless of the user's role permissions specified on the Roles edit roles screen. If a user account has ASSIGNED_ROLES but also has ASSIGNED_ROLES_PERMISSION_RESTRICTED assigned as its primary role on the Roles edit roles screen, the role's permission has priority and is applied to the user account.
Member Edit Roles
Only accounts with these roles may be edited or created by this user.

Troubleshooting tips

  • Check the Role Edit Role screen to see if a User Group is setup to edit Users.

  • Verify this account's User Capabilities has Setup accounts.

  • Check the data scope of the User you are trying to give these admin capabilities to. If the User only has access to limited units / unit groups, they will only be able to edit the Users who have this same limited scope of data.