User Permissions Overview

Permissions in the platform control what users can see and do. The system uses a role-based access control structure where users are assigned to user groups, and user groups contain roles that define specific permissions.

How the Permission System Works

The platform uses a three-level permission structure:

Users → are assigned to → User Groups → which contain → Roles

Roles define what actions users can perform and what features they can access. There are two types of roles:

User Groups are collections of roles assigned to users. Key characteristics:

Administrator Rights

A user can hold administrator rights in one of two ways, and the two are tracked separately:

Because these are separate, you can remove direct admin rights from a user who is also in an admin group; they keep admin access through the group until they are removed from it as well.

Only administrators can create or edit other administrators, mark a user group as an admin group, or reset the password of an admin user. For non-admins, the option to grant admin rights is not available.

What Permissions Control

Checking a User's Permissions

To confirm what a particular user can see and do, an administrator can log in as that user from the user's profile. This starts a session that shows the platform exactly as that user experiences it, which is the quickest way to verify a permission setup without asking the user to check for you.

While logged in as another user, a banner indicates that you are in their session. You can return to your own administrator account directly from there, without logging out and back in. Returning works even when the other user has very limited permissions.

Tips


Related Articles

Start Free Today


Get free DAM

Information

+354 525 3535Bjargargata 1102 Reykjavikdatadwell@datadwell.com