Skip to main content

Assigning Groups to Users

A user has whatever their assigned permission groups give them. Assigning is done from either end — the user's record, or the group.

From the user​

Open the person in the user list, go to Permissions, and use Assign permission group. This is the right direction when setting somebody up: you are thinking about one person and what they need.

From the group​

Open the group under Settings ▸ Administration ▸ Permissions and use its Users panel. This is the right direction for a change of policy — everyone who should gain or lose a capability, handled in one place.

Several groups at once​

A user can hold more than one group, and their rights are the union. Holding Operator and Report Author gives everything in both.

Rights only add. There is no group that takes something away, so removing a capability means removing it from a group the person holds, not adding a restrictive one.

That makes composition the natural approach: a base group for the role, plus small additive groups for extra capabilities.

A new user with no group sees nothing​

The commonest support call after account creation. A user with no permission group can sign in, lands on an empty Home, and reports that eConnect is broken.

Assigning a group is step two of creating a user, not an optional follow-up.

When changes take effect​

Some changes apply immediately; others at the person's next sign-in. If somebody reports that a change has not taken, having them sign out and back in is the first thing to try.

Checking what somebody actually has​

Three ways, in increasing formality:

  1. The Permissions section of their user record — what is assigned
  2. Their session history — what they have actually done
  3. The Security and Access Report — a point-in-time document of who holds what

The third is the one for an access review, because it covers everybody at once and can be filed.

Removing access​

For someone leaving, disable the account rather than stripping groups — see The User List. Disabling stops access immediately and keeps their history attributable.

Remove groups when somebody changes role rather than leaves. Removing the old role's group is the step most often forgotten, and it is how people accumulate access they no longer need.

Scope is separate​

Permission groups decide what somebody may do. Which records they may do it to is logical groups. A user with full permissions and a narrow logical group has broad rights over a small slice of data — often exactly what you want.

What is recorded​

Assigning and removing permission groups is audited under the permissions administration type, so a change in access can be traced to who made it. See Reading the Audit Trail.