Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This article contains a table lists the default groups in the out-of-the-box system and describes the general permissions of each. To see more information about a group's permissions, you can print out or save to a file The process you can use to print or save the full details of that a group's permissionpermissions is described below the table. You can find information on how to actually configure group permissions in the Group Permissions Wizard article.

Groups

Type

General description of access permissions

Admin

Power User

The admin This group has full configuration and record access permission for the system. Admin users can see and do everything that is possible in the system. The number of admin users should be as small as possible. Admin users generally should not be deleted.

Admin ImportPower UserThis group is a copy of the Admin group that has additional create permissions specifically for importing. Admin Import users generally should not be deleted.
Adobe Sign UserPower UserThis group, along with the Admin and Business Admin groups, is the only group that can see and work with Adobe Sign elements, such as the Adobe Sign Envelope and Adobe Sign Recipient by default. This group can create, edit, delete, import, export, or copy records they own in any of the AdobeSign tables.

Anonymous

Power User

This group is used to enable sets up unregistered users with the ability to edit records. Unregistered users can click on an email a hyperlink sent in an outbound email in order to edit that record. It is used in conjunction with records if they are given the Anonymous user distinction. If all your users have user records in the system, you will do not need this group. As a power user group member, the Anonymous user uses an assigned or floating license. Anonymous users generally should not be deleted.

Approver

Power User

This group holds contains people who can approve either Contracts or , Change Requests, or both. Approvers will primarily interact with their own Approval records, but they can also view change requests for which they are an approveredit Approval records assigned to their team, and view related records. They can also view and edit Contracts and Change Requests for which they are an approver, and can view tables related to approving Contracts such as Approvals, Approval Templates, and Companies.

Base Service Desk

Power User

This group has uses the same base permissions that should apply to all more as the highly privileged groups dealing who work with the Service desk Desk tables. Users in those privileged groups should also be in the Base Service desk group. All IT Staff should belong to this group, as well as any additional groups for special permissions.

This group has full create /and edit access to all the records in the Support Case, Service Request, Incident, Problem, and Task tables, and create /and edit own access to Change Requests Request and Time Entries. It has Entry records that they own. These users have full view access to Assets, Services, Companies, and Employees and can edit its own employee record, but has no of the Asset, Service, Company, and Employee tables, can edit their own Employee records, but does not have any other create or edit access in those tables. It can create /edit end users (external customers)and edit End Users records. It cannot delete records.

Business AdminPower UserThis group is for business administrators who can view or edit all records in all tables. Business Admin users generally should not be deleted.

Change Manager

Power User

This group is responsible for management of Change Request records and has full privileges on the Change Request table. Members can create, edit, and delete records in this table and will are typically be users with Change Managers Manager or Change OwnersOwner roles. They can also create task and approval workflows for Change Requests, and can edit Change Request related services.

Configuration Manager

Power User

This group has full access to control over records in the Asset records and is responsible for creating, editing, and deleting those recordsand Model tables. People responsible for working on and configuring AssetsAsset records, managing Asset asset resources, and so on would typically be or other similar projects, are typically in this group. They might also be added to the Service Manager group if they are responsible for setting up change request workflows or services related to assets.

Contract Creator

End User

For This group is for internal employees who can request, edit, and create their own contracts, as well as view all contracts.

Contract Manager

Power User

This group has full access to control over records in the Contract table, Approvals tableApproval, Steps and Approval Workflow tables, and Companies tableCompany tables. They also have some access to End Users and Employees. They are responsible for creating, editing, and approving contracts for customers or the company.

Contract Owner

Power User

This group has a subset of the permissions that similar permissions to the Contract Managers havegroup. Its members Members are responsible for Contracts assigned to them, and have full permissions therepermission of Contracts where they are the Internal Contract Owner, but can only also view Contracts that they did not create or were not assigned to. They have all the other permissions necessary to allow them to use Contracts effectively

Contract RequesterPower UserThis group is for internal employees who can create and edit their own contracts. They can also view all contracts.

Customer

End User

Unused unless providing external customer support. Then this This group is used for end user customers, who can submit and view their own support cases. This group is generally only used when providing external customer support.

Customer Manager

Power User

Customer Manager – relevant if providing external customer support. Customer managers This group is used so Customer Managers can view all support cases for their own company. Similar to the Customer group, the Customer Manager group is generally only used for providing external customer support.

Document Creator

End User

Can create documents and edit their own – customer of document tableThis group can create, edit, and export their own Document records. However, they cannot view the Document records of others.

Document Manager

Power UserPeople who can approve and publish documents

This group has nearly full control of all records in the Documents table. However, they do not have the ability to modify the Status field of a Document record manually.

Document Reviewer

Power UserCan edit approvals for which they are the approver

This group can edit Approval records where they are the Approver. They can also view all records in the Document table.

DocuSign UserPower UserThis group, along with the Admin and Business Admin groups, is the only group that can see and work with DocuSign elements, such as the DocuSign Envelope and DocuSign Recipient tables, by default. This group can create, edit, delete, import, export, or copy records that they own in any of the DocuSign tables.

Guest

End User

This group may be used in hyperlinks to allow creation of new requests of any kind (is assigned to external users who can click on a hyperlink in an outbound email that allows them to create new requests, such as leads, users, Incidents) without seeing or incidents, in the system without needing to access the rest of the user interfaceEnd User Interface. Guest users generally should not be deleted. 

Internal customerCustomer

End User

Internal Customer in employee table, This group is for customers in the Employee table who can create Service Requests , and Purchase Requests, and report Incidents, as well as see their own Assets, Asset records. This group can also edit some of their profile information, and view other employee contact information. They , and may also have access to the Knowledge FAQsArticles table.

Marketing

Power User

This group is responsible for coordinating and recording information about marketing campaigns and providing quotes to prospective customers. They have full access to : the Campaign, Company, Lead, Opportunity, and Product tables. They also have some limited access to the Product Quoted, Quote, TasksTask, TeamsTeam, Time Entry, People: End External User, and People: Employee tables.

Procurement Group

Power User

This group is responsible for managing the Purchase Request, Item, and Item Requested tables. They can also view and edit all records in the Company Document table.

Project ManagerPower UserThis group has full control over Project, Task, and Task Template records that are related to their project. They can also create records and edit others' records in the Asset, Billing, and Billing.SR Time Entry tables.

Sales

Power User

This group is responsible for recording information regarding sales efforts to for specific companies, as well as Purchase Orders made. They the Purchase Order records that are created. This group can also create and update Support Case records for the companies they represent. They have full access to: control over records in the Company, Contract, Lead, Opportunity, and PO tables. Partial They also have partial access to records in the Campaign, Product, Product Quoted, Project, Quote, Support Case, TasksTask, TeamsTeam, Time Entry, People: End UsersUser tables.

Service Manager

Power User

For staff responsible for maintaining the Service Portfolio (Service table) and the Task Workflows/Templates table. Only Service Managers can create new Services.

...

This group has full control over records in the Service, Task, Task Step, Task Template, and Task Workflow tables. Besides Admins and Business Admins, Service Managers are the only group that can create new Services.

VendorEnd UserThis group is used to categorize vendor companies that can use the vendor portal. This group can create, edit, and view their own Company Document records, edit and view their own Company records, and view their own Contract records.

To access group permissions in the system, as well as how to print them:

  1. Go to Setup > Access > Manage Groups.
  2. Edit a group.
  3. Select the Tables tab.
  4. Sort by Click Access to sort the Access column so that tables the group can see are on top, where Access is Yes.with Yes at the top.
  5. Clickthe box to the left of Edit Check the box in the header row to select all tables, and click Select all found records.
  6. Hover over the printer icon and choose Print/Download Table View.

...

This produces a printout showing the ownership of records in the table and the basic Record permissions for each table for the selected group. Copy. You can copy/paste the page contents into a text editor in order to document the system permissions for each group, or group permissions for each system.