Skip to main content

Object roles: setup and assignment

This guide shows you how to create object roles and assign them to employees and objects. With object roles, you can give employees extra permissions within specific objects or object groups, without changing their main permissions.

What is an object role?

An object role gives an employee extra permissions that apply only within the selected object(s), for example a specific construction site or service location.

Important: An object role adds permissions for the selected objects, but it never limits the employee's main permissions. If the employee's main permissions already let them view or edit data across the whole company, they keep that right after an object role is assigned. An object role can never take away or narrow anyone's existing permissions.

Requirements

  • Your company must be using the Objects module.

  • Only employees with the Administrator permission level can create or change object roles, meaning decide what a role allows. No other permission level can do this, however many other permissions it has.

  • More people can assign an existing object role to someone. This includes an employee who has edit rights on that object and already has at least the same level of access. For example, they already have that role, or their own permissions cover everything the role would give. An Administrator can always assign anything.

Step 1: Create an object role

Go to Configure → Permissions → Object roles:

  • Give the role a name (e.g. "Site manager").

  • For each data set (e.g. working time, documents), choose whether the role gives No rights, Can view or Can edit. This is one ranked choice, not two separate checkboxes. If you choose Can edit, you automatically get view rights too.

  • If needed, allow the role to use the timer when adding working times (see below).

Picture guide

Step 2: Assign the object role to an employee and an object

You can link a role from either side:

  • On the employee's profile page (the Object roles panel): choose the object role and one or more objects or object groups it applies to.

  • On the object's page: the other way round. Assign the role to several employees on the same object at once.

Picture guide

Employee Profile:

In the selected object view:

You can also set a validity period:

  • If you leave the start date empty, the role is valid straight away.

  • If you leave the end date empty, the role has no end date.

  • If you set an end date, the role is valid up to and including that date. Access ends automatically from the next day, so you don't need to delete anything by hand.

Step 3: Check the permissions

After assigning the role, it's a good idea to check the employee's profile to see which objects and roles apply to them.

Permission to add working times with the timer

This permission only lets the employee start and stop the working time timer (the start and end time of their work) on the selected object. It doesn't let them view or edit working time entries. That needs its own separate permission.

Example

Need

Solution

A site manager needs extra permissions to manage their own object's data

An object role linked to that specific object

An employee should be able to clock in and out with the timer on one object only

An object role that only allows adding working time with the timer

Good to know

  • An object role only adds permissions. It never takes anything away.

  • Changes (assigning or removing a role) take effect straight away. The user doesn't need to log out and back in.

  • When you deactivate an employee, you can choose whether to also remove all object roles linked to that employee.

  • You can't give anyone an object role that would give them more permissions than you have yourself.

Did this answer your question?