Permission profiles
Using Permissions, system admins can grant or restrict access for the following profiles:
- Users
- Groups
- Systems
Permissions let an admin control which parts of an Apteco software installation a given profile can access. This limits interaction to the features and functionality the admin specifies.
For a new system, the default system-level permissions let an admin access all resources. After installation, you should adjust system permissions to reflect your organisation's security requirements.
Permission states¶
A permission can be in one of three states:
- Granted (a tick): A granted permission resource is visible to a profile.
- Denied (a cross): A denied permission resource stays hidden and isn't visible to a profile.
- Undefined (empty): An undefined permission denies access to a resource if no overriding permission exists.
Permissions for multiple groups¶
Note
Permissions work through inheritance. A user receives all permissions assigned to their user, group, and system profile.
Use multiple groups to conveniently apply multiple permissions to a user. Having multiple groups only makes a difference when you use users & groups and permissions features together.
You can place a user in multiple groups if you're not using user permissions. However, FastStats only recognises the starred group.
Some general guidelines on permissions assignment are:
- Users should belong to one or more groups
- Groups should represent a function of the user, perhaps a country, region, or product
- Permissions should typically apply to groups, to make resolving security issues easier
- Permissions should only apply to users as an exception