Configuring advanced access control via access roles
Who is this article for?Administrators responsible for managing permits.
Administrator role and Permits module access are required.
Access roles allow you to control which users can view, create, edit, and approve specific permit types based on filters such as department, facility, or location.
1. Configuring access roles
To configure an access role, follow these steps:
- Navigate to Access Roles in Data Manager.
- Select Create New Role.
- Enter a name and description for the role.
- Set the status to Active, Inactive, or Archived.
- Select Permit Module from the Site Module dropdown.
- Assign the relevant permit types (for example, Biosafety, Hot Work, or Confined Space).
- Set the required permissions: View, Create, Edit, Comment, or Approve.
- Add access filters such as Room, Department, Facility, Organization, or Location.
- Navigate to Edit Forms.
- Mark the form field that defines the access scope (for example, Department).
- Navigate to Edit Permit Type.
- Pair the access role with the corresponding form field.
Important: Filters only work when they are set in both the access role and the permit form field.
2. Layering with user tags
User tags allow further refinement of access control, particularly for delegated workflows.
Scenario A: User tags only
A user tagged as Permit Coordinator can submit or amend permits for a linked principal investigator.
Scenario B: Access role combined with user tag
This approach combines role-based permissions with delegated submission rights, ensuring visibility remains limited to authorized permit types.
3. Setting up roles effectively
Follow these tips to manage access roles efficiently:
- Start broad, then narrow – Begin with default roles and add filters and tags as your requirements grow
- Test role behavior – Use a non-administrator test account to confirm users see only the correct permits
- Document custom roles – Maintain a reference document for onboarding new administrators and troubleshooting access issues
- Review annually – Remove unused roles and update committee memberships to keep your system current