About User Roles and Security Groups

A person’s usability within FlowWorks is determined by two things:

  1. The role(s) they have been assigned.
  2. The Security Group(s) to which they belong.

You can assign one or more user roles and security groups to each user in your client base. The proper mix of capabilities and access can permit a user to perform his/her assigned functions.

Please read this article carefully before creating new users, to ensure the security of your entire user network is well maintained!

Definitions

Client: An organization subscribed to FlowWorks' software services.

User: An individual working under a client, who logs-in to FlowWorks using their own login credentials.

Role: A user’s assigned function(s) and responsibilities in FlowWorks. Roles are useful for limiting or extending a user’s accessibility to tools (such as F.A.C.E and Alarming) and administrative functions (such as creating and managing user accounts).

Security Group: A set of permissions that dictate the visibility & accessibility of sites & channels, and custom-made resources (including GIS layers, custom apps and custom screens).

Overall structure

user_role_and_security_group.png

A client of FlowWorks can have from one to many individual users. The flowchart shown above demonstrates that a single user must be assigned a role and be part of a security group, although each user can be assigned more than one of each. Every role-type dictates the tools and administrative privilege a user has access to; a security group determines the scope of a user’s visibility of (and accessibility to) sites, channels, and custom resources.

User roles

User roles determine the permissions that are appended to a user account. A single user can have more than one role.

Important notes about user roles

  1. A role does not ‘inherit’ the privileges of the roles below it. For example, the attributes of the ‘User’ role do not carry over to that of ‘Group Administrator’. For a Group Administrator to be fully capable of using any of the tools in FlowWorks, he/she must also be given the additional role of User. This characteristic allows greater flexibility for security and access.
  2. With that said, it is possible to create a user with a ‘Group Administrator’ role-type only. Without having the ‘User’ role-type as well, he/she can only create and manage other accounts and cannot fully use the features and functions offered in FlowWorks.

To find out how to check and modify the roles assigned to a user, see, Modify / Check User Roles.

User role types

The chart below describes the different types of roles that can be assigned to FlowWorks users. Remember, a user can be assigned more than one of these roles for greater access to features and control.

user-roles.jpg

Security Groups

Security Groups give Group Administrator(s) the power to maintain granular control over their network of sites, channels, and custom resources.

SecGrpStrctr_451x270.jpg

By default, each Client has a parent security group and each new user is automatically placed in this group. The parent security group entails the widest network of sites, channels, tools to which a user is permitted access. Note that all user role settings remain active in security groups.

Group Administrators can modify the settings of each security group and organize users accordingly – this is useful for sub-dividing accessibility to certain tools and visibility of sites, channels and custom resources. Parent security groups can have numerous 1st level sub-groups; and sub-groups can have numerous 2nd level sub-groups, which can have 3rd level sub-groups, and so on.

Important notes about security groups

  1. If a user is assigned to multiple Security Groups or sub-groups, the permissions granted by those groups are combined. Security Groups grant access and do not deny or remove access granted by another group.
  2. It is possible to build a security structure that becomes cumbersome to manage and maintain. It is recommended that the Group Administrator(s) invest some time in planning the necessity of permitting/restricting access to sites, channels, and tools prior to creating security groups and assigning users thereto.

To find out how to create and edit Security Groups, please see article Manage Security Groups.

 

FAQ: Security Groups and Roles

1. Should top-level administrators be included in each Security Group (Parent/Root + Subgroups) ?

Users are [normally] automatically placed in the client’s Parent Security Group when their account is created. There is no requirement to explicitly add an administrator to every sub-group unless your intent is to limit their site/channel access.
 
The Parent Group represents the broadest scope of sites and channels available to that user. Therefore, if an administrator needs access to the complete dataset, keeping them at the Parent Group level is appropriate. Users can also be assigned to specific sub-groups when their access needs to be limited to particular sites or channels.

2. What happens if a user belongs to multiple Security Groups with different channel permissions?

Security Groups grant access; they do not deny or remove access granted by another Security Group. For example, if one Security Group gives a user visibility to all channels at a particular site, and another Security Group has some of those channels hidden, the user will still have access to the channels granted by the first group. An allow wins over a deny as a result when it comes to security group site/channel visibility
 
Therefore, assigning a user to multiple groups does not create a conflict where a restrictive group removes access granted by another group. The user's available access is based on the permissions granted across their applicable Security Groups.

3. What is the recommended approach for managing Security Groups?

The Parent or 'root' Group can represent the overall dataset where all sites/channels reside, while sub-groups can be used to separate contractors, departments, locations, or staff who require access to specific site groupings. This is the most common way to structure your security groups.

Within each group, you can further control which sites and channels are visible and which users have access to these groups. Security Groups can also be nested into additional sub-groups when more granular access is required.
 
For example -- a sample hierarchical structure for security group set up is shown:

  • Parent Group – Complete dataset / broad access
    • Contractors – Sites and channels relevant to external users
    • Operations – Sites relevant to operations staff
    • Engineering – Engineering-related sites
      • internal
      • external
    • Regional/Location Groups – Further site-specific access as required

We recommend keeping the hierarchy as simple as practical and using sub-groups where there is a specific access requirement. This makes the structure easier to maintain as users, sites, and responsibilities change. The FlowWorks documentation also recommends planning the required access structure before creating groups and assigning users.
 
Finally, Security Groups control the scope of sites, channels, and other resources, while User Roles control the tools and administrative functions available to the user. These are separate, so users can be assigned the appropriate combination of roles and Security Groups based on their responsibilities.

Have more questions? Submit a request

0 Comments

Article is closed for comments.