Changes for page Admin Visibility Rules
Last modified by karimpirani on 2014/07/03 15:48
Summary
Details
- Page properties
-
- Content
-
... ... @@ -1,12 +1,14 @@ 1 -Super Users, Domain Administrators and Organizational Unit Administrators all have different levels of visibility a nd authority as to what they can do in the Admin Console.Thispage outlines those rules.1 +Super Users, Domain Administrators and Organizational Unit Administrators all have different levels of visibility as to what they can do in the Admin Console. 2 2 3 +This page outlines those rules. 4 + 3 3 4 4 5 -= ===Super Users ====7 += Super Users = 6 6 7 7 Super users are unconstrained users. They can see and do everything in the system. 8 8 9 -In the system: 11 +In the SMR system: 10 10 11 11 * Only one role can contain the SUPER_USER permission; this role will be the SUPER_USER role, a system role. 12 12 * The SUPER_USER role cannot be modified (all system roles behave in this way). ... ... @@ -16,25 +16,25 @@ 16 16 17 17 18 18 19 -= ===Administrators ====21 += Administrators = 20 20 21 21 Administrators are users who have access to at least one administration screen. There are two administrative levels: domain and organizational unit. 22 22 23 23 24 24 25 -=== =Domain Administrator ====27 +=== Domain Administrator === 26 26 27 27 A domain administrator is governed by the permission DOMAIN_ADMINISTRATOR. Domain administrators will always see **all data** on any screen for which they have access. 28 28 29 29 30 30 31 -=== =Organizational Unit (OU) Administrator ====33 +=== Organizational Unit (OU) Administrator === 32 32 33 33 An OU administrator is governed by the permission OU_ADMINISTRATOR. OU admins will only see data for the OUs (and all child OUs) for which they are **responsible**. 34 34 35 35 36 36 37 -= ===Order of Precedence ====39 += Order of Precedence = 38 38 39 39 All users will be shown the greatest amount of data granted to them. A user can have as many of the admin permissions granted to them but the order of precedence is: 40 40 ... ... @@ -42,19 +42,19 @@ 42 42 43 43 44 44 45 -= ===Data Visibility in Modules ====47 += Data Visibility in Modules = 46 46 47 47 Here is the rule for data filtering on screens for each permission. Only the screen:sections below have specific rules regarding data visibility across the permission sets. 48 48 49 49 50 50 51 -=== =Admin Module ====53 +=== Admin Module === 52 52 53 53 The main idea behind these filters is that users are only allowed to modify users/relationships below their level. (e.g. Domain admins cannot modify each other). Also, OU admins are bound to whatever OUs for which they are responsible. 54 54 55 55 56 56 57 - __**The simple rule is**__: You//cannot//modify yourself, any of your roles, your responsibilities, or any users/roles at or above your level.59 +=== **//The simple rule is//**: You cannot modify yourself, any of your roles, your responsibilities, or any users/roles at or above your level. === 58 58 59 59 60 60