User Permissions

The user permissions implemented by InfoAsset Manager are designed to prevent users from accidentally making changes to data they should not be editing.

A set of simple user access permissions can be applied at database level, group and individual action level.

With access permissions activated the following types of InfoAsset Manager user are available:

Note

Because permissions are assigned at group level and not to a specific software product, every role will be available for selection, even if it does not necessarily apply to your software product.

There are three other Live roles further restricting powers that users may have over Live Groups. These are:

Closed

Note

User roles for a Model Group are viewed in the Properties Dialog of the group. Note that the properties dialog will only display user roles that have been specifically appointed to that group and will not display user roles of parent groups. For example, if parent Model Group A with owner 'user1' has a sub Model Group B, 'user1' will only appear in the properties dialog for A although 'user1' will also have full edit powers over B.

Backwards Compatibility

If your database is an InfoNet v10.5 database that you have migrated to InfoAsset Manager, any list of users that was in the InfoNet v10.5 database will be migrated and merged with the list of users in the InfoAsset Manager database (if any).

For any particular user name, if the InfoAsset Manager database list already contains that user, the software checks that the Full Name and Administrator (Database Owner) settings are the same – if they are different, the settings already in InfoAsset Manager take precedence and a message is shown at the end of the import to warn that the settings were different for one or more users.

When an model group is migrated, the list of owners for that model group is also migrated.

The above happens regardless of whether Implement Permissions is currently switched on in the InfoNet v10.5 or InfoAsset Manager databases (the Implement Permissions setting itself is not migrated). This means that you can migrate data from an InfoNet v10.5 database that has permissions to an InfoAsset Manager database that does not, but if you then switch on permissions in the InfoAsset Manager database, you will see the users and owners that were migrated.

Tip

Note that this means that a user who is an Administrator (Database Owner) of the InfoNet v10.5 database will automatically become an Administrator of the InfoAsset Manager database, provided permissions are implemented and that user is not already listed in the InfoAsset Manager database.

For new databases created in InfoAsset Manager, you do not have to invoke access permissions. With the permissions option turned off, all users have Database Owner powers.

Network role-based write permissions

In addition to the user permissions described above, there is another type of permission that can be granted to asset network users by database owners. These permissions apply to the whole master database or to a specific asset network only. Such permissions are associated with network roles, allowing database owners to place restrictions on certain users. Users can be prevented from creating and deleting network objects, as well as from writing to particular fields.

Tip

Note that these network roles are applicable to asset network users only.

These permissions can only be implemented for databases where network roles have been enabled. This is achieved by enabling the Implement network roles for asset networks in this database option of the Users and Permissions Dialog. The assignment of one or more network roles per user is carried out by database owners in the Users and network roles Dialog, which is accessible via the Master database settings | Users and network roles... option of the File menu. Roles are configured in the Network roles and write permissions dialog that gets displayed when the Network roles... button is clicked in the Users and network roles dialog. All InfoAsset Manager data still remains visible to all users but with the use of these network roles, certain fields and the creation/deletion of network objects can be restricted.

Users and Permissions Dialog

Manage User Permissions Dialog

Edit Group Permissions Dialog

Users and network roles Dialog