Access Control
Details the configuration of access permissions for forms, covering general settings, advancing workflow, record readability at different workflow steps, and section-level access for user groups.
Access Control is the heart of your system's security and workflow management. It provides granular control over which user groups can perform specific actions—like creating, viewing, editing, and deleting records—on any given form. It also dictates how records move through your established workflows and which parts of a form are visible at each step.
This guide will walk you through the core concepts and configuration options.
Default Access Settings by Module
To provide a clear starting point, the tables below outline the default access permissions for the primary form in each module. Think of these as the standard templates; you can customise these settings to fit your organisation's specific needs using the controls described further down this page.
User Role Legend:
- A - Admin
- PU - Power User
- U - User
- IM - Injury Manager
- CO - Contractors
- DA - Drug and Alcohol Monitors
- HMM - Health Management Monitors
Module Access Control
Module | Create | View | Edit | Delete |
---|---|---|---|---|
Incident Reporting | A, PU, U | A, PU, U | A, PU, U | A |
Actions | A, PU, U | A, PU, U | A, PU, U | A |
Hazards | A, PU, U | A, PU, U | A, PU, U | A |
Injury Management | A, PU, U | A,, IM | A, IM | A, IM |
Risk Assessment | A, PU, U | A, PU, U | A, PU | A |
Documents | A, PU, U | A, PU, U | A, PU, U | A |
Inspections | A, PU, U | A, PU, U | A, PU, U | A |
Job Safety Observations | A, PU, U | A, PU, U | A, PU, U | A |
Corporate Risk Register | A, PU | A, PU | A, PU | A |
Training Records | A, PU | A, PU | A, PU | A |
Contractor Management | A, PU | A, PU, U, CO | A, PU, CO | A |
Field Observations | A, PU, U | A, PU, U | A, PU, U | A |
SWMS | A, PU, U | A, PU, U | A, PU, U | A |
Permit to Work | A, PU, U | A, PU, U | A, PU, U | A |
Non-Conformance | A, PU, U | A, PU, U | A, PU | A |
Quality | A, PU, U | A, PU, U | A, PU | A |
Alerts | A, PU | A, PU, U | A, PU | A |
Health Management | A, HMM | A, HMM | A, HMM | A |
Meetings | A, PU, U | A, PU, U | A, PU, U | A |
Work Hours | A | A | A | A |
Change Management | A, PU, U | A, PU, U | A, PU, U | A |
Diary | A, PU, U | A, PU, U | A, PU, U | A |
Registers Access Control
Module | Create | View | Edit | Delete |
---|---|---|---|---|
Equipment Maintenance | A, PU | A, PU, U | A, PU | A |
Waste Disposal | A, PU, U | A, PU, U | A, PU, U | A |
Asbestos Register | A, PU, U | A, PU, U | A, PU, U | A |
Chemical Register | A, PU, U | A, PU, U | A, PU, U | A |
Classified Equipment Register | A, PU, U | A, PU, U | A, PU, U | A |
Drills and Exercise Register | A, PU, U | A, PU, U | A, PU, U | A |
Drug and Alcohol Register | A, DA | A, DA | A, DA | A, DA |
Electrical Equipment Register | A, PU, U | A, PU, U | A, PU, U | A |
Fire Extinguisher Register | A, PU, U | A, PU, U | A, PU, U | A |
First Aid Register | A, PU, U | A, PU, U | A, PU, U | A |
Ladder Register | A, PU, U | A, PU, U | A, PU, U | A |
Lifting Equipment Register | A, PU, U | A, PU, U | A, PU, U | A |
PPE Register | A, PU, U | A, PU, U | A, PU | A |
Plant Equipment Register | A, PU, U | A, PU, U | A, PU | A |
Vehicle Register | A, PU, U | A, PU, U | A, PU, U | A |
Configuring Access: The Four Control Tabs
Access Control for a form is managed across four distinct tabs. Understanding how they work together is key to setting up your permissions correctly.
1. General Access Settings
This tab sets the high-level, form-wide permissions and visibility.
- Core Permissions: Assign groups that can:
- Create records from this form (none if blank).
- View records created from this form (none if blank).
- Edit records created from this form (none if blank).
- Delete records created from this form (none if blank).
- Import/Export records using this form (none if blank).
- Create records based on recurrence rules (none if blank).
- View Drafts: Select groups that can see all 'Draft' records. None if blank, but users can still see their own drafts.
- Inspect Audit Log of records created from this form (none if blank).
- Directly Create new records using the 'New Record' button (defaults to allow all Create groups if left blank). If restricted to specified groups, other groups given general Create access can still create via other means, e.g. through linked record creation.
- Hierarchy Access: You can select to Ignore hierarchy access to grant either internal user, external users, or all users access to records from this form, regardless of their hierarchy access restrictions.
- Manage Global Views: Select which groups can create, edit, and delete global (shared) views. Users not in a selected group can only manage their own personal views.
- Form Display Options: Control whether the form itself appears in the module record list page.
- Display: The form is visible in in the module record list.
- Do not display: The form is hidden in in the module record list.
- Restrict by group and hierarchy: Make the form visible only to specific user groups or hierarchy levels.
2. Advancing Form Workflow Permissions
This tab controls who can move a record from one workflow step to the next (e.g., from 'Draft' to 'Submitted').
- Select a Workflow step (e.g., Draft).
- From the list of available groups, select the group(s) that should be able to advance the form from this step.
- Use the arrow button to move them into the "permitted" list.
- Repeat for all other workflow steps and select OK.
3. Record Readable Permissions in Workflow
This tab defines which groups can view (read) a record when it is at a specific workflow step.
- Select a Workflow step (e.g., Submitted).
- Select the group(s) that should be able to read records that are currently at this step.
- Use the arrow button to move them into the "permitted" list.
- Repeat for all other workflow steps and select OK.
4. Section Access Permissions
This tab provides the most granular level of control, allowing you to set read and edit rights for specific sections within a form, based on the record's current workflow step.
- Select a Workflow step.
- Select one or more Form Sections.
- Assign Group(s) able to read the selected section(s) at this workflow step.
- Assign Group(s) able to edit the selected section(s) at this workflow step.
- Repeat for all necessary workflow steps and sections.
- Select OK.
Important Note: Putting It All Together
Permissions are layered. A user's ability to see or edit a field is determined by a combination of all four tabs. For example:
- A user might have general Edit rights from the
General
tab. - However, if the record is in a "Closed" workflow step, the
Record Readable
settings might restrict their access to Read-only. - Furthermore, even if they can edit the record, a specific "Manager Approval" section on the form might be locked via the
Section Access
tab.
Always consider the entire chain of permissions, from general access down to the specific section and workflow step, to ensure your configuration behaves as expected.
Version: 1
Mobile App Configuration
Covers the steps to enable a form for use in the mobile app and how to configure the specific record list display for mobile devices.
Version Control
Explains how to enable and configure record versioning, including automatic version creation rules and setting group permissions for deleting, editing, viewing, and creating record versions.