Collections and Permissions: Settings

This article explains the access management settings available on collections and permissions in eADM, and how to use the ruleset and message flow generator that ties them together. It is intended for administrators configuring application-level access control.

Collections and permissions

A collection is a container that groups related permissions together. It holds the shared configuration that applies to every permission inside it: how many permissions a user can hold per department or organization, how conflicting automatic permissions are resolved, and who is allowed to administer the collection.

A permission is an individual access right within a collection. Granting a permission to a user typically corresponds to membership of a specific system, licence, application, or group. Each permission has its own configuration for automatic granting, eligibility, department scope, and notifications.

Department-specific permissions

A permission can apply to one department only, instead of the whole organisation. This is controlled by the Department specific permission setting (see Permission settings below).

A department-specific permission grants access to the linked department only, not to the organisation as a whole. For example, a manager can hold a role in a target system for the departments they lead, without gaining access to the rest of the organisation.

Collection settings

These settings are configured on the Information tab of a collection.

Setting

Description

Multiple permissions per department

Determines whether a user can automatically hold more than one permission from this collection within the same department. Set to Yes to allow several permissions per department, or No to restrict the user to one.

Multiple permissions per organization

Determines whether a user can automatically hold more than one permission from this collection across the organization as a whole, regardless of department. Set to Yes to allow several permissions organization-wide, or No to restrict the user to one.

Prioritize permissions

Controls which permission applies when a user meets the automatic-allocation criteria for more than one permission in the collection. The permission with the highest priority (the highest numerical value) applies. A manually assigned permission always has the highest priority, regardless of its numerical value. Priority is set individually on each permission.

Remove manually assigned department-specific permissions

Removes a user's manually assigned department-specific permissions automatically when the user changes department. This must also be enabled on each relevant permission (see Department specific permission and Remove manually assigned department-specific permissions under Permission settings below).

Available to

Restricts who may grant, edit, or revoke permissions in this collection to the users covered by the linked ruleset.

System administrator

Sets the default recipient for automatic notifications about permissions in this collection.

Note: A manually assigned permission always overrides the Prioritize permissions ranking. Automatic allocation logic only decides between competing automatically granted permissions.

Permission settings

These settings are configured on the Permissions tab of a collection, for each individual permission.

Setting

Description

Name

Best practice is to use a human-friendly name, so administrators and managers can recognize the permission without needing to know the underlying system access it grants.

Join groups

The groups a user is added to when the permission is granted. The user is removed from these groups automatically when the permission is revoked.

Grant automatic permission

The ruleset that determines automatic granting of the permission. When a user no longer satisfies the ruleset, the permission is automatically revoked, together with any associated group memberships.

Can be granted permission

The ruleset that narrows down which users are eligible to be granted this permission, whether automatically or manually. Only an administrator can grant the permission to a user outside this ruleset.

Department specific permission

Marks the permission as tied to a specific department.

Remove manually assigned department-specific permissions

Works together with the collection-level setting of the same name. Enable this on each permission that should have its manually assigned instances removed automatically when a user changes department.

System owner

Sets the recipient for message flows about this specific permission, such as notifications about grants or revocations.

Description

Free-text field for extra information, for example to help managers understand when and to whom the permission should be granted.

Metadata

Free-text field used mainly for permissions granted directly to a system through the API.

Managing collections and permissions

An administrator can edit, delete, or move a permission.

It is only possible to move a permission to a collection with the same Multiple permissions per department and Multiple permissions per organization settings as the original.

An administrator can also edit or delete a collection.

Generating rulesets and message flows

Use Generate ruleset and message flow, available from a collection's Permissions tab, to create an automated notification either for all permissions in the collection or for one specific permission.

The wizard asks for:

  1. Trigger event: When a permission is granted, when a permission is revoked, or when a permission is edited.

  2. Recipient: Employee, Manager, System owner, or Custom. System owner uses the email address configured for a specific permission, while System Administrator is used when you create a message flow for all the permissions in a collection. Custom lets you enter a specific email address or expression.

For example, use this wizard to send an automated email to the system owner whenever a user is granted a specific permission.

Last updated: