[{"data":1,"prerenderedAt":268},["ShallowReactive",2],{"guide:en:admin\u002Froles":3},{"id":4,"title":5,"body":6,"description":260,"extension":261,"meta":262,"navigation":263,"path":264,"seo":265,"stem":266,"__hash__":267},"guide_en\u002Fen\u002Fuser\u002Fadmin\u002Froles.md","Roles",{"type":7,"value":8,"toc":252},"minimark",[9,13,17,22,29,76,94,98,112,118,122,129,135,138,144,205,211,215,218,242],[10,11,5],"h1",{"id":12},"roles",[14,15,16],"p",{},"A role is a set of restrictions. Everyone given the role is blocked from the actions its restrictions name, on the records its restrictions match. A role is also a team: the people who hold it are the people it describes.",[18,19,21],"h2",{"id":20},"the-roles-window","The Roles window",[14,23,24,28],{},[25,26,27],"strong",{},"Admin › People › Roles"," opens the Roles window. The roles are listed on the left and the one you select is on the right.",[30,31,32,43,57,73],"ul",{},[33,34,35,38,39,42],"li",{},[25,36,37],{},"Search"," and ",[25,40,41],{},"Filters"," above the list narrow it by name, by who holds the role, by what its restrictions cover, and by deleted roles. Each applied filter shows as a chip.",[33,44,45,48,49,52,53,56],{},[25,46,47],{},"Add role"," starts a new role. The list's ",[25,50,51],{},"⋯"," holds ",[25,54,55],{},"Import roles"," and the exports to CSV and Excel.",[33,58,59,60,52,62,65,66,38,69,72],{},"A role's row ",[25,61,51],{},[25,63,64],{},"Clone",", ",[25,67,68],{},"Delete",[25,70,71],{},"Restore",".",[33,74,75],{},"Tick roles to change them together.",[14,77,78,79,82,83,86,87,38,90,93],{},"Edits wait in the window, and the upload button above the list counts them. ",[25,80,81],{},"Save"," writes the role on screen, and ",[25,84,85],{},"Save all"," writes every changed role. Moving to another role keeps your edits to the one you left. ",[25,88,89],{},"Undo",[25,91,92],{},"Redo"," step through them.",[18,95,97],{"id":96},"a-roles-form","A role's form",[14,99,100,101,104,105,38,108,111],{},"A role has a ",[25,102,103],{},"Name",", an ",[25,106,107],{},"Owner",[25,109,110],{},"Tags",". People given the role can apply its tags to the work they touch.",[14,113,114,115,72],{},"You give a person a role from their record in ",[25,116,117],{},"People",[18,119,121],{"id":120},"restrictions-as-sentences","Restrictions, as sentences",[14,123,124,125,128],{},"The ",[25,126,127],{},"Restrictions"," section reads as plain language:",[130,131,132],"blockquote",{},[14,133,134],{},"Members of the Field Technician role can do everything except:\n• Delete Work Order records where name is \"freckle\".\n• Create & Edit Work Order records where status is any of \"completed\", \"in-progress\".",[14,136,137],{},"Each line is one restriction. A red dot marks a restriction that blocks something. A grey dot marks one that blocks nothing yet, because no action is chosen.",[14,139,140,141,143],{},"A line's ",[25,142,51],{}," opens the restriction's form:",[30,145,146,152,158,164,181,199],{},[33,147,148,151],{},[25,149,150],{},"Model",": the kind of record, such as Work Order, Site or Feature. Feature also covers assets.",[33,153,154,157],{},[25,155,156],{},"Field",": the field on that record to test. The list offers the model's fields and the properties its records commonly carry. You can also type one.",[33,159,160,163],{},[25,161,162],{},"Comparison",": is, is not, is greater than, is at least, is less than, is at most, contains, is any of, is none of, or is between.",[33,165,166,169,170,38,174,177,178,72],{},[25,167,168],{},"Value",": one value, a list for ",[171,172,173],"em",{},"is any of",[171,175,176],{},"is none of",", or two bounds for ",[171,179,180],{},"is between",[33,182,183,186,187,65,190,65,193,38,196,198],{},[25,184,185],{},"Blocked actions",": ",[25,188,189],{},"Create",[25,191,192],{},"Read",[25,194,195],{},"Edit",[25,197,68],{},". A chosen action turns red.",[33,200,201,204],{},[25,202,203],{},"Remove"," deletes the restriction.",[14,206,207,210],{},[25,208,209],{},"Add restriction"," adds a line and opens its form. Closing a form you never filled in removes the line.",[18,212,214],{"id":213},"limiting-a-role-to-some-records","Limiting a role to some records",[14,216,217],{},"To give a group authority over some records and not others:",[219,220,221,228],"ol",{},[33,222,223,224,72],{},"Tag those records, for example ",[225,226,227],"code",{},"north",[33,229,230,231,234,235,238,239,241],{},"Give the group's role a restriction on the ",[25,232,233],{},"tags"," field, with the comparison ",[25,236,237],{},"is not"," and the value ",[225,240,227],{},", blocking the actions you want kept to those records.",[14,243,244,245,248,249,251],{},"The line under the sentence then reads the other way round: ",[171,246,247],{},"So members can read only Feature records where tags is north."," Each role a person holds narrows further. Two such roles leave only the records carrying both tags. To cover two areas with one role, use ",[25,250,176],{}," with both tags.",{"title":253,"searchDepth":254,"depth":254,"links":255},"",2,[256,257,258,259],{"id":20,"depth":254,"text":21},{"id":96,"depth":254,"text":97},{"id":120,"depth":254,"text":121},{"id":213,"depth":254,"text":214},"The Roles window, reading a role's restrictions as sentences, building a restriction, and limiting a role to some records with a tag.","md",{},true,"\u002Fen\u002Fuser\u002Fadmin\u002Froles",{"title":5,"description":260},"en\u002Fuser\u002Fadmin\u002Froles","STqk7uhehwFI3bIySG-BaiSVNRukCvLGmQbO-wP6tEs",1790080291543]