Security Roles control which screens and reports users can access. Employees can belong to more than one role.
Open Security Roles #
Browse to Admin System Preferences Security Roles.
Notice: System administration access is required. Grant only the access a person needs for their work.
Create a security role #
- Open Admin, System, then Security Roles.
- Select the new-role action.
- Enter Name and Description.
- Save the role.
- Open its Screens, Reports, and Employees areas to finish configuration.
Configure a security role #
Build each role around a job responsibility instead of an individual employee. This makes access easier to review and lets multiple employees receive the same permissions consistently.
Add screens #
- Open the role's Screens area.
- Search available screens.
- Select the menus and screens the role requires.
- Save.
Module gates still apply. Giving a role an expense screen does not enable expenses for the account.
Add reports #
- Open the role's Reports area.
- Search available reports.
- Select only the reports this role needs.
- Save.
Report data is also limited by the user's role, the employees they can access, and their project access.
Add employees #
- Open the role's Employees area.
- Select Add Employee to Security Role.
- Choose one or more Available Employees.
- Confirm.
You can also assign roles from an employee's Account & Security screen.
Example: Project manager role #
A project manager may need project dashboards, team timesheets, approval screens, and a limited set of reports without needing system administration or subscription settings. Create a role with only those screens and reports, then assign it to the employees who manage projects.
Change or remove a role #
Open the role and update its screens, reports, or employees. Review the employee list before removing access.
Warning: Deleting a security role removes access that the role provides to its employees. Confirm that another role supplies required access before deleting it.
Verify access safely #
- Review the role's screen and report lists.
- Confirm module settings.
- Assign the role to a test user who has no other roles, so you can see exactly what this role allows.
- Have the test user sign out and sign back in.
- Confirm expected menus and reports, without granting System Administrator.