About

This section provides background information around users and user management within the Metrix Asset Management system.

Subsections of About

Users

The User Account and Access Control implementation within the Metrix Asset Management system is underpinned by an industry leading cloud-based solution for authentication and authorisation; ensuring the security of your asset data. Each and every user account within your environment can be entirely managed by your own system administrators via the restricted-access system administrations portal in the Metrix Asset Management system. Through this portal, system administrators can:

  • Create new user accounts,
  • Add or Remove role-based permissions for users, and
  • Disable access for user accounts.

The user account creation process is provided as a fully self-service management system for system administrators to extend the accessibility of their environment. When creating a new account, a secure short-lived password will be emailed to the new user along with an invite to complete their account setup. At that point, the user will be prompted to initialise their own password - which is required to meet various constraints, including:

  • Minimum length of 8 characters
  • No spaces
  • At least one uppercase letter
  • At least one lowercase letter
  • t least one number
  • At least one special characters (excluding + and -)

Permissions

User permissions are managed through various pre-configured roles designed to function at a user activity level. Within each role, representing an end user activity, users can be given simple read, write, and/or delete permissions. Examples of such activity roles include:

  • Managing asset/component information,
  • Configuring classifications,
  • System configuration,
  • and more.

Roles

As mentioned above, permissions are managed through roles. Essentially, a role is a combination of one or more permissions to create a functional set of things that a user can and cannot do in the system.

To see what permission set each role has, simply navigate to System Admin > Roles, and select one of the listed roles. The role view will provide a breakdown of what permissions are available to the role in terms of ‘Can View’, ‘Create/Edit’, and/or ‘Delete’.

Example

One of the pre-configured roles is “Asset Admin”. This role has a number of permissions assigned to it relating to Asset data, Finance data, Defects, as well as Configuration management options. If you were to view the “Asset Admin” role breakdown, you would note that the role has a full suite of permissions when it comes to Asset data (view/edit/delete), but a restricted set of permissions for Finance data (view/edit only - no delete).

This is an example of a role providing enough functionality for managing asset data, including deleting assets, as well as viewing and modifying finance data, but not deleting it.

Permissions

As indicated above, permissions are accessed (by users) through their assigned roles. Below is a brief breakdown of what each permission category enables when allowed for VIEW, CREATE/EDIT, or DELETE.

  • Asset/Components: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) records within the core asset/component register within the system. This is a foundational permission set.
  • Finance: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) the financial records associated with asset components within the system.
  • Programming: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Operations module as it pertains to tasks (condition, attribute, and other). That is, see and/or manage Mobile App programmes.
  • Defects: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Defects sub-module of the Operations module. For example, the ability to VIEW defects would permit a user to see captured defects and their configuration options.
  • Budgets: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the Capital module as it pertains to viewing and/or setting capital works budget/bucket items and spends. Note; in order to capitalise spends from a budget bucket, a user would still need ‘finance edit’ in their role.
  • Asset Config: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the asset configuration menu. That is, viewing/setting classification structures, form definitions, report categories, etc.
  • Manage Users: Roles containing permissions of this category are allowed to view/edit/delete (as assigned) functionality within the user management page of the System Admin seciton. That is, view/modify users of the system.
  • Mobile Users: Roles containing permissions of this category are allowed to use the Metrix Mobile app.

Disabled Accounts

Through the user management portal within the Metrix Asset Management system, administrators are able to disable system access completely for any user account. This action will leave the user profile setup within the environment, but prevent that account from logging into Metrix from anywhere.

Administrators, in addition to disabling access, can also re-enable account access via the same portal.