Permissions reference
The levels, the resources, and the two roles that sit outside the group system.
The four levels
| Level | Means |
|---|---|
| None | The area is not available. |
| Read | Can open and read, cannot change anything. |
| Read & Write | Can create and edit. |
| Full access | Everything in Read & Write, plus settings for that resource. For a report that means report settings and its permissions. |
They are ordered. Anything that requires Read is also satisfied by Read & Write and Full access.
The resources
| Key | Controls |
|---|---|
| Report | Reports, topics, disclosures, data points, comments, attachments, history. |
| Files | The organisation file library. |
| Publication | Creating, editing and deleting publications. |
The administrator role
Organisation administrator sits outside the group system. It reaches Settings and can add users to the organisation, and it is not something you can hand out from inside the application: contact support to have a colleague made an administrator.
Defaults worth knowing
- A user in no group has full access to everything.
- A resource not mentioned by any of a user's groups falls back to full access.
- A report-level permission can raise a group's access for that report, never lower it.
What a user without access sees
An area a user has no permission for is simply absent from the navigation. Opening its URL directly shows an empty page rather than an explanation, so if a colleague reports "the page is blank", check their group membership first.
