Understanding the Manage users permission

Language: English

This article explains what the "Manage users" permission allows, and how you decide which Roles a user with this permission can assign to other users.

What the Manage users permission allows

A user whose Role includes the "Manage users" permission is called a user manager in this article. A user manager can do the following in the User management section of the Database settings:

  • Invite new users to the Database and assign them a Role
  • Change the Role of an existing user
  • Choose the optional Forms and Folders, and the Parameter values, that apply to a user's Role
  • Revoke a user's access to the Database

You turn on "Manage users" for a Role in the Role's permissions dialog, under "Permitted operations" and "User management". "Manage users" is a Role-level permission, like "Manage roles" and "Security contact". A user manager can only include optional Forms and Folders in a user's Role if they have access to these Forms and Folders themselves.

Which Roles a user manager can assign

Each Role states which other Roles its users can assign. You choose these Roles in the "Assignable roles" section of the Role's permissions dialog:

  • "Any role". When checked, users with this Role can assign every Role in the Database, including Roles that you add later. Use this for administrators.
  • One checkbox for each Role in the Database, including the Role you are editing. When checked, users with this Role can assign that Role, even if it includes permissions that their own Role does not have. When "Any role" is checked, these checkboxes cannot be changed.

A user manager can assign exactly the Roles that are checked, and no others. When a user manager invites a user or changes a user's Role, they only see the Roles that they can assign. If none are allowed, the list is replaced by the message "Your role does not allow you to assign any role. Ask a database administrator."

The Role that a user manager checks is the Role being assigned:

  • Inviting a user: the user manager must be allowed to assign the Role they choose.
  • Changing a user's Role: the user manager must be allowed to assign the new Role. They do not need to be allowed to assign the user's current Role.
  • Revoking a user's access: the user manager must be allowed to assign the user's current Role. For example, a user manager who cannot assign the "Administrator" Role cannot revoke the access of an administrator.

If "Manage users" is checked but no Role is, a warning reminds you that users with this Role cannot assign any Role.

Example

Your Database has an "IT" Role and a "Finance Director" Role. Only the Finance Director can approve budgets, so the "IT" Role does not have all the permissions of the "Finance Director" Role. You still want the IT team to invite new finance directors, but not to appoint administrators.

In the "IT" Role, check "Manage users". Then, under "Assignable roles", check "Finance Director" and leave "Any role" unchecked. Users with the "IT" Role can now invite finance directors, move existing users to the "Finance Director" Role, and revoke the access of finance directors. They cannot assign any other Role, and they still cannot approve budgets themselves.

Administrators

In the "Administrator" Role, check "Manage users" and, under "Assignable roles", check "Any role". Administrators can then assign every Role, and you do not need to update the "Administrator" Role when you add a Role.

How to choose the Roles a user manager can assign

  1. On the Database List page, click on the Database.
  2. Click on "Database settings" and then on "Roles".
  3. Click on the Role of the user managers to open it in the side panel.
  4. Under "Permissions", click on "Edit permissions".
  5. In the "Permitted operations" section, under "User management", check "Manage users".
  6. Click on "Assignable roles" in the left pane of the dialog.
  7. Check "Any role", or check each Role that users with this Role may assign.
  8. Click on "Save".

The side panel of the Role summarizes your choice, for example "Manage users in all roles" or "Manage users in 3 roles".

Adding a Role

When you add a Role, for example "Data entry", ActivityInfo asks "Which roles may assign users to the “Data entry” role?". The question lists the Roles that have "Manage users" but not "Any role". Check the Roles that should be able to assign the new Role, and click on "Save". To decide later, click on "Skip". Roles with "Any role" can assign the new Role without any change.

If you delete a Role, ActivityInfo removes it from the "Assignable roles" of every other Role.

Manage users and Manage roles

The "Manage users" permission does not allow a user to change what a Role can do. To add, edit or delete Roles, a user needs the "Manage roles" permission.

Permissions granted to an individual user

"Assignable roles" only applies to Roles. When you grant permissions to an individual user for a specific Form or Folder, you can only grant permissions that you have yourself. To give a user permissions that you do not have, assign them a Role that you are allowed to assign.

Legacy Roles

Legacy Roles, which define permissions without Grants, do not have the "Assignable roles" section. Users with a legacy Role that includes "Manage users" can assign Roles whose permissions are equal to or fewer than their own. To choose the Roles explicitly, click on "Duplicate and migrate as updated role" in the side panel of the legacy Role.

Related articles:

Next item
Add your first role