How to set up user access
Tip!
User groups are sorted by access groups. Complete Control comes with some pre-defined access sets: System , Standard, Contract Owners, Read only, Read only + Digital signature. System-users will always have access to everything, whereas users with Read only shall not be able to edit, create or delete entries. This gives you a good starting point as you often only need to do small adjustments.
Read more about the access sets under Access control for user groups.
How to create a user group
-
Go to System settings - Access control.
-
Click + Add a new group.
-
Add a Name of group. The name shall be as self-explanatory as possible.
-
Under Select type, you select now the access set the user group shall be based on.
-
Click Save.
The user group is added to the access set you selected under step 4. Continue with adjusting the user group. Read more below.
How to adjust accesses for a user group
You can adjust and fine-tune all user groups except for those under system administrator: Give access to specific companies, departments, fields and more. Read also the example at the bottom of this file.
-
Open the user group that shall be edited.
-
On the General tab, you can choose if the users in this group must log in via SSO and which companies the users shall have access to. Both functions are related to additional products. Confirm any adjustments with Save.
-
On the Access control tab, you give users now access to the various modules in CC5: Each one has its own access setup, and it is therefore important that you check each side-tab. For details about the related fields, see User access card).
-
Under Functionality, you can define if the users in this group be able to read, update, create or delete entries. By removing all rights (including Read) the user will not see anything.
-
Under Permissions per company, you give access to your company's (first) company.
-
Under Fields you can give access to specific information, e.g. Lablels or File attachments on contracts.
-
Under Content, you can fine-tune access to persons, assets and contracts.
-
All content: The user can see all entries.
-
No content: The user can't see any entry.
Exception! If you selected Own profile under Functionalityon the People, users will get access to their own user profile. -
Customized content: Allows you to fine-tune access.
-
Permissions for selection: Select what the users shall be able to do. Note that you never can give higher rights than what is defined under Functionality.
-
Selection criteria: Allows you to give access to e.g. only entries for a specific department, location or category.
Example: Select User relation Responsible employee to give users access to assets they are responsible for. -
If you selected a department, location or category, you click Selection applies to and check which entries match the selection.
-
-
-
Do you have a company group structure? In this case, repeat step 2 for each company.
-
After you have set-up access for each side-tab, click Save.
-
The user group has now been adjusted. Existing users will be updated. To assign the user group to new users, read below.
How to assign the user group to users
Read How to create a new user.
How to delete a user group
You can only delete user groups without members.
-
Go to System settings - Access control and open the user group you want to delete.
-
Has the user group members? Switch to the Members tab. Select the members and click Remove. The user will now be without user group, and you must assign a new user group to them later.
-
You can now Delete the empty group.
The group is deleted.
Example: Add standard users with access to own user profile, utilized IT-equipment and contracts they are responsible for
In this example ,you shall add a user group "Standard employee". Users in this group shall be able to update their own user profile without access to any other person entries. They shall also be able to view IT equipment they utilize and contracts they are responsible for or have signed.
-
Create a user group "Standard employee" under the access set Standard as described under How to create a user group above.
-
Open the group and switch to the Access control tab.
-
Select the side tab People.
-
Under Functionality, select Update next to People and Own Profile.
Tip: The lower Read right is ticked automatically. -
Under Content, select No content. This means that no other persons are displayed.
-
-
Switch to the Asset side tab.
-
Under Functionality, tick Read. You don't want that employees shall also do changes. They shall only see which equipment they use.
-
Under Content, select Customized content.
-
Select User relation Utilized by. All users in all departments and on all locations will now see their own utilized equipment.
-
Under Category, select the entry IT-equipment (or similar if you have; categories are individual for your company). This will limit the list of assets to only those entries.
-
-
Switch to the Contracts side tab.
-
Under Functionality, select Update next to Contracts.
-
Under Content, select Customized content.
-
Select User relation Responsible employee. This gives the user access to contracts they are responsible for, and they can edit these contracts.
-
-
Click Save.
All Members you add to this group now, will have the access rights described above. For more access e.g. to files or the dashboard, you also need to adjust these side tabs.