Permissions
User permissions are managed through various pre-configured roles designed to function at a user activity level. Within each role, representing an end user activity, users can be given simple read, write, and/or delete permissions. Examples of such activity roles include:
- Managing asset/component information,
- Configuring classifications,
- System configuration,
- and more.
Roles
As mentioned above, permissions are managed through roles. Essentially, a role is a combination of one or more permissions to create a functional set of things that a user can and cannot do in the system.
To see what permission set each role has, simply navigate to System Admin > Roles, and select one of the listed roles. The role view will provide a breakdown of what permissions are available to the role in terms of ‘Can View’, ‘Create/Edit’, and/or ‘Delete’.
One of the pre-configured roles is “Asset Admin”. This role has a number of permissions assigned to it relating to Asset data, Finance data, Defects, as well as Configuration management options. If you were to view the “Asset Admin” role breakdown, you would note that the role has a full suite of permissions when it comes to Asset data (view/edit/delete), but a restricted set of permissions for Finance data (view/edit only - no delete).
This is an example of a role providing enough functionality for managing asset data, including deleting assets, as well as viewing and modifying finance data, but not deleting it.
Permissions
As indicated above, permissions are accessed (by users) through their assigned roles. Below is a brief breakdown of what each permission category enables when allowed for VIEW, CREATE/EDIT, or DELETE.
- Asset/Components: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) records within the core asset/component register within the system. This is a foundational permission set.
- Finance: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) the financial records associated with asset components within the system.
- Programming: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Operations module as it pertains to tasks (condition, attribute, and other). That is, see and/or manage Mobile App programmes.
- Defects: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Defects sub-module of the Operations module. For example, the ability to VIEW defects would permit a user to see captured defects and their configuration options.
- Budgets: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Capital module as it pertains to viewing and/or setting capital works budget/bucket items and spends. Note; in order to capitalise spends from a budget bucket, a user would still need ‘finance edit’ in their role.
- Asset Config: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the asset configuration menu. That is, viewing/setting classification structures, form definitions, report categories, etc.
- Manage Users: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the user management page of the System Admin seciton. That is, view/modify users of the system.
- Mobile Users: Roles containing permissions of this category are allowed to use the Metrix Mobile app.