Manage security roles and access

2 min read

Print

Security Roles control which screens and reports users can access. Employees can belong to more than one role.

Open Security Roles #

Browse to Admin System Preferences Security Roles.

Notice: System administration access is required. Grant only the access a person needs for their work.

Create a security role #

  1. Open Admin, System, then Security Roles.
  2. Select the new-role action.
  3. Enter Name and Description.
  4. Save the role.
  5. Open its Screens, Reports, and Employees areas to finish configuration.

Configure a security role #

Build each role around a job responsibility instead of an individual employee. This makes access easier to review and lets multiple employees receive the same permissions consistently.

Add screens #

  1. Open the role's Screens area.
  2. Search available screens.
  3. Select the menus and screens the role requires.
  4. Save.

Module gates still apply. Giving a role an expense screen does not enable expenses for the account.

Add reports #

  1. Open the role's Reports area.
  2. Search available reports.
  3. Select only the reports this role needs.
  4. Save.

Report data is also limited by the user's role, the employees they can access, and their project access.

Add employees #

  1. Open the role's Employees area.
  2. Select Add Employee to Security Role.
  3. Choose one or more Available Employees.
  4. Confirm.

You can also assign roles from an employee's Account & Security screen.

Example: Project manager role #

A project manager may need project dashboards, team timesheets, approval screens, and a limited set of reports without needing system administration or subscription settings. Create a role with only those screens and reports, then assign it to the employees who manage projects.

Change or remove a role #

Open the role and update its screens, reports, or employees. Review the employee list before removing access.

Warning: Deleting a security role removes access that the role provides to its employees. Confirm that another role supplies required access before deleting it.

Verify access safely #

  1. Review the role's screen and report lists.
  2. Confirm module settings.
  3. Assign the role to a test user who has no other roles, so you can see exactly what this role allows.
  4. Have the test user sign out and sign back in.
  5. Confirm expected menus and reports, without granting System Administrator.

Was this article helpful?

  • Yes
  • Somewhat
  • No