A matrix chart showing the user permissions in relation to other system profiles. See User Profiles to set permissions on a per action basis per user profile. This is a "who can see who" display of permissions, showing the degree of interaction possible between user profiles. Along the X-axis is each user profile, with an entry representing that user's profile permissions compared to the corresponding profiles along the the Y-axis.
The users of one profile can administer users of another profile. This privilege includes adding users of the specified type (if the âadd_usersâ privilege is set for the profile of the creating user), âbecome this userâ (the administrator can convert itself into the administered user and it also includes the following Write, Read and View permissions.
Examples: â]po[ Adminsâ for example should, in general, be able to administer all other types of users. "Freelancers", in the example below, all âEmployeesâ are allowed to administer freelancers.
The permission to modify user data.
The permission to read the user data (name, email, contact information, âŠ).
The permission to view the name of the user, but not the right to see the user's data.
|
Accoun
|
Custo
|
Emplo
|
Free
|
]po[ Admins |
Project Mana
|
Sales |
Senior Mana
|
Accounting |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R W A |
Customers |
v R w a |
v r w a |
v r w a |
v r w a |
V R W A |
v r w a |
V R W A |
V R W A |
Employees |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R W A |
Freelancers |
V R W A |
v r w a |
V R W A |
v r w a |
V R W A |
V R W A |
v R w a |
V R W A |
]po[ Admins |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R w a |
Project Managers |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R W A |
Sales |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R W A |
Senior Managers |
v R w a |
V r w a |
v R w a |
V r w a |
V R W A |
v R w a |
v R w a |
V R W A |
(Upper Case letters signify that the user has the permission, lower case that they do not.)
For users that belong to more than one profile group their total permissions are the union of their various profiles. For example, a user who is both a "Senior Manager" and an "HR Manager" will have the aggregate permissions of these two profiles when interacting with other users, so belonging to multiple user profiles is not mutually exclusive.
For users wishing to interact with other users belonging to multiple profiles, their rights over the user are the intersection of their permissions over the multiple profiles. For example an "Employee" wishing to view a user who is both a "Senior Manager" and an "HR Manager" must have view rights over both these profiles, not just one in order to view the other user.
USER 1 belongs to Profile A and B
USER 2 belongs to Profile C
USER 3 belongs to Profile C and D
USER 1 Permissions on USER 2 = { Profile A Permissions (w/respect to C) âȘ Profile B Permissions (w/respect to C) }
USER 1 Permissions on USER 3 = { Profile A Permissions (w/respect to C) âȘ Profile B Permissions (w/respect to C) } â© { Profile A Permissions (w/ respect to D) âȘ Profile B Permissions (w/ respect to D) }
Calle Aprestadora 19, 12o-2a
08902 Hospitalet de Llobregat (Barcelona)
Spain
Tel Europe: +34 609 953 751
Tel US: +1 415 200 2465
Mail: info@project-open.com