User roles define which functionalities a user can utilize within the system (sharing, creating, or managing user groups).
User roles allow the admin to supervise or access minor configuration capabilities (e.g., the user can create more system templates for different groups but cannot make general changes) and to diversify responsibilities and roles. The default user roles are System Admin and Standard User.
Tabs to configure:
- Administration: Defines who can access the system configuration.
- A best practice is to have at least two system admins.
Note: Having two administrators will maintain full administrative access to the tenant even if an administrator leaves or is out of the office. There is no additional cost to having two users with administrator access.
-
- Configure System provides access to the system configuration panel but not all features (only attributes, group associations, system templates, and security policy).
- Manage System Templates includes Notebook, Experiment, Inventa Analysis, and System object templates.
- Manage Groups makes the group menu icon available to end users and lets the admin create user groups.
- Manage Attributes provides access to configure attributes, group associations, and security policy.
- Author: Defines responsibilities related to objects like notebooks and experiments.
- Sharing notebooks/experiments overrides anything set with Dynamic Access Controls.
- When Share experiment is disabled from the Standard User Role, Administrators can still grant read privileges through the Security Policy.
- Read Dependent Share allows sharing only to users who already have read access via the security policy.
- This option is recommended to prevent users from overriding the security policy.
- When this permission is granted to a role, the share privilege must be deactivated.
- Be aware that Share will override the read dependent share, allowing users to share to other users without read access.
- Add/Edit/Delete Comments allows users to add, edit, and delete comments in notebooks and experiments.
- Broad User Search allows users to search for users across email domains.
- If deactivated, users with different email domains can be searched only by typing the complete email address.
- If activated, users with different email domains can be searched by typing other users’ first or last name, as well as the complete email address.
- Share Templates allows the user to share personal text and experiment templates.
- Move Experiments.
- Trash Experiments/Notebooks.
- Export Notebooks.
- Archive and Return From Archive – users can archive closed experiments.
- Trash Mandatory Entities – users can edit experiments created with a system template and delete items that were marked as mandatory.
- Sharing notebooks/experiments overrides anything set with Dynamic Access Controls.
- VitroVivo: Defines responsibilities related to managing VitroVivo and files.
- Inventa: Defines responsibilities related to accessing and managing the Inventa Analysis object.
- Create new Inventa Analysis.
- Edit Inventa Analysis.
- Move Inventa Analysis to another parent entity.
- Share Inventa Analysis with other users.
- Trash Inventa Analysis.
- Export Inventa Analysis.
Default roles available:
- System Admin: Always exists and cannot be changed.
- Standard User: Always exists; some of the accesses can be changed.
- Config Admin: This role can be removed if it is not needed.
The Configure System option provides access to the system configuration panel but with limited capabilities. Users with this access can manage attributes, group associations, system templates, and security policy. The admin must be able to configure the system to manage system templates and metadata types.
Comments
0 comments
Article is closed for comments.