Security roles

5 min read

Print

Security roles control which screens and reports a user can open.

Manage security roles and access #

Security Roles allow you to create user groups (i.e. Employees, Managers, etc.) and then apply access restrictions to each group. Users can then be added to these groups to restrict their access to various items throughout the MindSalt Time & Expense system. Basic groups are set up at the time your account is created. You may modify these groups and create new ones on the Security Roles screen.

Tip: New systems come pre-populated with common Security Roles.

Options and field descriptions #

Name – A name for the Security Role. Each Security Role in your account must have a unique name. When creating/editing users you will refer to this name when selecting which Security Roles that the user will be a member of.

Description – An optional field that provides a means for adding a description of the Security Role. This can be useful when creating unique Security Roles and you need to document why the group was created and how it is used.

Automatically add new users to this group when they are added to the system – This option simplifies the process of adding new users to the system. When adding a new user to your system, the Security Roles you mark 'use as default' will automatically be selected by default. This feature is helpful if you have default permissions you wish to apply to all new users within your system. You will have the option to deselect any default Security Role from the user administration screen. You may specify more than one default Security Role.

Screens – Security Role screens are the system screens the user is allowed access to. If a user does not have access to a menu item they will not have access to the corresponding screen.

For example, let's assume your organization wants to allow managers the ability to approve/reject timesheets but does not want them to be able to modify their employees' timesheets. In this scenario you would select 'Manage Approvals' and deselect 'Manage Timesheets' from the screens section.

Note: Use caution when selecting screens from under the 'Administrator Reports' branch in the Screens selection. Should you decide to enable, for example, 'Timesheets' from the screens section, all members of this Security Role will have access to all sections under Administration -> Timesheets. This includes items such as the ability to modify any user's timesheet, bulk modifications, accounting corrections, etc.

Tip: A System Administrator automatically has full access to all screens throughout the system, regardless of the Security Role's options & parameters he or she may be a member of.

Reports – Security Role report items are the system reports the user is allowed access to. If a user does not have access to a particular report, the report will not be displayed in their report list.

The report items section is divided into 3 main branches:

  1. Administrator Reports – Reports under this branch contain information pertaining to the entire company/organization. Typically you would not want a regular employee to view information of this kind.
  2. Manager Reports – Reports under this branch contain information pertaining only to that manager's employees. Users that are a member of an Security Role that has access to one or more manager reports will only be able to view information regarding their employees. If a user who is not a manager but happens to be a member of an Security Role that has access to manager reports, he or she will see the reports listed but will not be able to generate any data. Data will only be generated for those employees he or she is the designated manager of.
  3. Employee Reports – Reports under this branch contain information only related to the user generating the report. Users that are a member of an Security Role that has access to one or more employee reports will only be able to view their own timesheet (or expense) information.

Note: Use caution when selecting report items from under the 'Administrator Reports' branch in the Report Items selection. Should you decide to enable, for example, 'Profitability Report' from the report items section, all members of this Security Role will have the ability to view which projects and employees are profitable for your organization and which are not.

Tip: A System Administrator automatically has full access to all reports within the system, regardless of the Security Role's options & parameters he or she may be a member of.

Creating or Modifying an Security Role #

  1. Browse to Admin, select System, and then select Security Roles.
  2. Select New to create a new Security Role or select an existing Security Role from the list.
  3. Provide a unique name for the Security Role.
  4. Optional: Provide a description if desired.
  5. Select whether or not this Security Role will be a default for new users.
  6. Select the Screens that members of this Security Role will have access to.
  7. Select the Reports that members of this Security Role will have access to.
  8. Select Save.

Note: Changes to a security role do not change the menus for someone who is already signed in. The user must sign out and sign back in. Report access changes take effect immediately.

Active and archived records #

MindSalt uses Active and Archived. Archived records stay in your account but do not appear in active lists. To archive a record, open its three-dot menu and select Archive. When a record can be copied, Copy is in the same menu.

Was this article helpful?

  • Yes
  • Somewhat
  • No