Creating user groups and linking function profiles
Users must belong to a user group. The rights of users in a specific user group are determined by the function profile (and any authorization filter) linked to this user group. This section discusses the general procedure for creating user groups and linking function profiles.
Procedure
1. Go to User groups.
On this level you can add or delete user groups.
2. On the action panel, click Add to add a user group.
3. Enter a name and description.
If necessary, you can add a remark in the Comment field.
The Users section displays the users that belong to the selected user group. When you have just added a new user group, there are no users linked yet.
4. Click Users on the action panel.
A dialog box with available users is displayed; here, you can select the users to be included.
| For more information on adding entirely new users to the list of available users, refer to Adding new users. |
Move the required users to In Use section.
| On the User group details level you can find detailed information on the individual users of the selected user group. The Show unlinked user accounts button on the elements list enables your to display users that are not linked to a user group (keep in mind that filtering and navigation restricts the result in the elements list). |
5. Link a function profile to the user group by using the Function profiles field. Select the appropriate function profile and click OK.
The function profile is now linked to the user group. On User groups level, the related permission type is now displayed in the elements panel.
6. In the Additional security logging field, click Yes if you want to log the login and logout timings of the users (in the selected user group). This data will be stored in the security logging file. To enable this feature, you must first make the security logging settings. For more information, refer to Security logging. | User groups can also be copied, by using the Copy option from the User groups action panel. Copying a user group may save a lot of time, if there are many users and there is a substantial overlap between two user groups. All users and action filters that are linked to the user group are copied to the new user group. You can only link one function profile to a user group. If needed, you can also link one or more authorization filters to a user group. For each combination of function profile and authorization filter(s) a user group is required (for example Security Region North, Security Region South). |
For more information on creating function profiles, refer to
Creating function profiles. For more information on creating authorization filters and linking them to a user group, refer to
Creating authorization filters.
The following actions are subject to security logging:
◦ Adding, changing and deleting user groups
◦ Linking or unlinking users to user groups
◦ Updating function profiles that are linked to the user group
| For more information about this topic, Security logging ( Administrator’s Guide). |
| System reports available in Authorization provide an overview of authorization per business object/user group. For more information, see . |
For more information on linking user groups to
Self-Service web definitions or
Planon Live mobile web definitions, see
Linking user groups to web definitions and
Linking user groups to web definitions / granting access to modules respectively.