Skip to content

Permission profiles

Using Permissions, system admins can grant or restrict access for the following profiles:

  • Users
  • Groups
  • Systems

Permissions let an admin control which parts of an Apteco software installation a given profile can access. This limits interaction to the features and functionality the admin specifies.

For a new system, the default system-level permissions let an admin access all resources. After installation, you should adjust system permissions to reflect your organisation's security requirements.

Permission states

A permission can be in one of three states:

  • Granted (a tick): A granted permission resource is visible to a profile.
  • Denied (a cross): A denied permission resource stays hidden and isn't visible to a profile.
  • Undefined (empty): An undefined permission denies access to a resource if no overriding permission exists.

Permissions for multiple groups

Note

Permissions work through inheritance. A user receives all permissions assigned to their user, group, and system profile.

Use multiple groups to conveniently apply multiple permissions to a user. Having multiple groups only makes a difference when you use users & groups and permissions features together.

You can place a user in multiple groups if you're not using user permissions. However, FastStats only recognises the starred group.

Some general guidelines on permissions assignment are:

  • Users should belong to one or more groups
  • Groups should represent a function of the user, perhaps a country, region, or product
  • Permissions should typically apply to groups, to make resolving security issues easier
  • Permissions should only apply to users as an exception