In this release, we’ve expanded the available system role permissions in v6 user management.
The permissions are now grouped under actions, making it easier to access the type of permissions users want to assign:
- View
- View permissions allow users to see, but not edit, user management items like users, user groups, and system roles. Best for users who need to access this information but should not make user management changes.
- Create
- Create permissions allow users to make new changes in the app, but usually can’t edit or delete any user management items created previously.
- Edit
- Edit permissions allow users to make changes to previously-created user management items.
- Delete
- Delete permissions allow users to delete previously-created user management items, currently limited to user groups and system roles.
Some permissions have prerequisite permissions that are required for the permission to work properly (e.g. “View users” is required for “Edit users”). Setting a permission with a prerequisite will automatically set its prerequisite permissions. For more information on permission prerequisites, see Permission prerequisite table below.
Permission details
Permission name | Behavior | Additional details |
---|---|---|
View users | See users, their account details, and their access control pages. Permission is view-only. | |
View direct reports | See account details of users that directly report to them only. Permission is view-only. | Direct reports are users that have a manager assigned on their account details page. This permission gives view ability to the manager only, and they can only see their direct reports. |
View user groups | See all user groups and user group details, including permissions. Permission is view-only. | Does not include viewing the users assigned to the user groups. |
View system roles | See all system roles and system role details, including permissions. Permission is view-only. | |
Create users | Make new, inactive user accounts. New users won’t take up a paid license (seat) until activated. This permission does not give activation privileges. | Checking this permission will automatically check “View users”. |
Create user groups | Create new user groups and add descriptions. Can’t edit user group permissions or assign users to the user group. | Checking this permission will automatically check “View user groups”. |
Create system roles | Create new system roles and add descriptions. Can’t edit permissions or assign users to system roles. | Checking this permission will automatically check “View system roles”. |
Edit users | Make changes to user details, including name, email address and reset password. Assign users to user groups and system roles. | Checking this permission will automatically check “View users”. |
Edit user status | Change user statuses to active, passive, or deactivated. Activating a user may send an account activation email and requires a license (seat). | Checking this permission will automatically check “View users”. |
Edit direct reports | Make changes to user details, reset passwords, and deactivate their direct reports only. |
Direct reports are users that have a manager assigned on their account details page. This permission gives editing ability to the manager only, and they can only edit their direct reports. Checking this permission will automatically check “View direct reports” |
Edit user groups | Make changes to user group names, descriptions, and permissions. |
Does not include editing which users are assigned to the user groups. Checking this permission will automatically check “View user groups”. |
Edit system roles | Make changes to system role names, descriptions, and permissions. |
Does not include editing which users are assigned to the system role. Checking this permission will automatically check “View system roles”. |
Delete user groups | Permanently delete user groups. | Checking this permission will automatically check “View user groups”. |
Delete system roles | Permanently delete system roles. | Checking this permission will automatically check “View system roles”. |
Permission prerequisite details
Checking a permission with a prerequisite will automatically check its required prerequisite permission. Unchecking a permission will not uncheck any prerequisites.
Permission | Prerequisite permission (will automatically turn on) |
---|---|
Create users | View users |
Edit users | |
Edit user status | |
Edit direct reports | View direct reports |
Create user groups | View user groups |
Edit user groups | |
Delete user groups | |
Create system roles | View system roles |
Edit system roles | |
Delete system roles |