Getting started with roles
Who is this article for?
Users and Administrators seeking information on role.
No elevated permissions are required.
In every environment, there can be up to three distinct types of roles, each serving a unique purpose and function:
- Administrative - These are standard roles that are available for individuals such as module developers and customer administrators who manage various aspects of the system. It is important to note that regular users do not require access to these roles, as they are designed for those who have specific responsibilities. It is crucial that these roles are only assigned to individuals who have received appropriate professional training to ensure they can handle the responsibilities effectively and mitigate any potential risks.
- Subscriber - These roles can grant rights to multiple applications or modules within the system. Both administrators and regular users can be assigned these roles, making them quite flexible. User Administrators can monitor which modules are associated with a subscriber role through the Subscriber Roles admin screen, allowing for better management and oversight of user permissions across the various applications.
- Module - These roles are specific to individual modules within the system. However, it is important to highlight that module roles are currently being phased out and will be replaced with Subscriber roles. This transition aims to streamline role management and enhance the overall efficiency of user permissions within the environment.
The mass update tool provides administrators with an effective way to manage user roles. It enables bulk updates, ensuring that changes are applied uniformly and swiftly, eliminating the need for individual adjustments for each user.
Roles are assigned to a reporting authority that allows the platform to further decide who has access to what, and what actions they can perform.
Some applications, especially those containing sensitive data, may require a finer level of Record Access Control (RAC) than by role or reporting authority. For cases like these, module developers can add custom rules to govern who is eligible to see a given record. These custom rules determine a list of persons or teams with access, and all others will be denied access.
Classic UI documentation
For information on Assigning administrative roles in the Classic UI and Understanding subscriber roles in the Classic UI visit the Classic Admin Guide, User Management documentation.