User permissions for the FM Portal are managed through the permissions management system. The central component of rights management is rights groups. These groups define which types of rights (e.g., read rights or edit rights) assigned users should have for which areas of the FM Portal. Individual users can then be assigned to a rights group either directly or indirectly via a user group.
When assigning roles and permissions in the portal, a distinction must be made between “permission groups” and “workflow roles.”
Permission groups are used to assign access rights to the functional areas of the portal, i.e., to menu items, tables, data forms, and information sections within forms. For each individual access right within the permission group, it can be specified in what form the access right is granted, e.g., read-only, edit, ...
If a form is integrated into a workflow, different people are typically involved in processing the workflow steps, each performing tasks only at specific steps (e.g., applicants create the ticket, or approvers approve or reject it). Simply assigning access rights to the data form via the permission groups is not sufficient here, since access to the data form must not be granted in general, but only for a specific workflow step.
Workflow roles are therefore used to determine, regardless of the settings of the permission groups, which workflow step is assigned to which role, and which role is authorized to perform specific actions in that step. These workflow roles are in turn filled by individual persons or permission groups.
The rights assigned in the workflow roles thus override the rights assigned globally via the rights groups.
Your eTASK.FM portal offers a range of so-called automatic groups. These are predefined groups that are automatically created during installation and automatically updated with every update. You therefore have three options for managing user rights:
You use the existing automatic groups as they are
You use the automatic groups but adapt them to your needs. 📄 Automatikgruppen anpassen IC2634
You do not use the automatic groups and create completely new permission groups. 📄 Rechtegruppen anlegen IC1067
Regardless of which option you choose, you then assign users to the permission groups either directly or indirectly via user groups.
You can find information about the exact settings available in a permission group (whether it’s an automatic group or a custom-created permission group) here:
Overview of the different types of permissions you can assign: 📄 Rechteübersicht FM-Portal IC2626
Assigning permissions from a permission group to the menu: 📄 Rechte auf Menü, Infobereiche und API-Pfade vergeben IC1065
Assign permissions of a permission group to form information fields: 📄 Rechte auf Menü, Infobereiche und API-Pfade vergeben IC1065
Set permissions for a rights group on entries in the Property Explorer and thus on the objects in the corresponding properties: 📄 Rechte auf Liegenschafts-/Objektexplorer vergeben IC2004
📄 Einem Benutzer Rechte über seinen Mitarbeiterdatensatz zuordnen IC1061