Skip to main content

Manage Roles and Permissions

The Roles and Permissions infeature OPSCOM provideprovides granular control over what administrative users can access and do within the system. ThisIts featureprimary allowspurpose is to allow administrators to define specific responsibilities, enhance security, and ensurestreamline thatoperations eachby userensuring hasusers only have appropriate access levels,levels. streamliningThis operationsarticle is intended for OPS-COM administrators responsible for managing backend system security and maintainingadministrative data integrity.access.

Using

Setup thisand Feature

Configuration

    This

  1. Clickfeature Systemdictates Configuration,backend thenaccess and requires a high-level administrator to set it up initially.

    Admin Management,Side: andAdministrators clickmust Manage Roles.

Creating and Managing Roles

Roles are central tohave the permissionspre-defined system, acting as templates for sets of permissions.

  1. The Manage Administrator Roles page will display. The System Administrator (Primary) rolerole, isor pre-definedequivalent andhigh-level allows youpermissions, to create new roles and assign them to other adminstaff users.members.

    Using this Feature

    Administrators can use the following instructions to create new role templates, edit existing ones, assign granular permissions, and apply these roles to administrative staff.

    Creating a New Role

    1. Click System Configuration, then Admin Management, and click Manage Roles.

    2. To create a new role, click

      Click the Add New Role button at the bottom of the page.

    3. Enter a descriptive name in the Role Name field and provide a detailed summary in the Description for that role.

      • The description will appear as a rollover tooltip when you mouse over the Edit Role button for that role.
      field.

    4. Click the Save Role button to save yourthe new role.

      FVUimage.pngrole template.

    Editing an Existing Roles

    You can modify the name and description of any role (except the System Administrator role).

    Role
    1. On the Manage Administrator Roles screen, click

      Click the Edit Role button next to the specific role you wish to update.update on the Manage Administrator Roles screen.

    2. Make yourthe desired changes to the Role Name and/orand Description. fields.

    3. Click the Save Role button to save your edits.

    Assigning Permissions to a Role

    Once a role is created, you'll define what actions users assigned to that role can perform by setting its permissions. 

    1. On the Manage Administrator Roles screen, click

      Click the Permissions button next to the role you want to configure.configure Theto open the Editing Permissions screenscreen.

      will display.
    2. The top bar displays various icons, mirroring the OPSCOM menu structure. The number next to each icon indicates how many permissions within that category have been selected for the current role.
    3. Click ana specific module icon (e.g., aPermit, "Permit"Violations) icon,from athe "Violations"top icon)bar to display the specific permissions available within that category.

    4. To grant a permission, enable

      Enable the checkbox next to thata permission's name.name to grant that specific access level to the role.

    5. Once

      Click the Save Permissions button once you have navigated through each icon and selected all the necessary permissionspermissions.

      for the role, click Save Permissions. The role, with its defined permissions, is now created and ready for assignment.

    Assigning Roles to Admin Users

    After roles are defined, you can assign them to your administrative users.

    1. Click System Configuration,Configuration, then Admin Management,Management, and click Edit Admin Users. Theto open the Manage Active Administrators pagepage.

      will display.
    2. Select an existing user you wish to modify, or choose to create a new user.

    3. On

      Add or confirm the details in the User Information section on the left side of the screen,screen.

      add
    4. Select the specific role or confirm the User Information (e.g., name, email).

    5. On the right side, select the role(s)roles you wish to apply to thatthe user from the available options.options on the right side.

    6. You can also add a Comment for

      Enter any relevant notes about the user's role or status.status in the Comment field.

    7. Click the Update User button to finalize the changes.

    On the Editing Permissions screen, the top bar displays various icons mirroring the system menu structure. The number next to each icon indicates exactly how many permissions within that category have been selected for the current role. Additionally, the role description will appear as a helpful rollover tooltip when you havemouse finishedover makingthe yourEdit changes.Role button.

    Available Actions and Buttons

    • Add New Role: Click this button at the bottom of the management page to create a new, blank role template.

  • Edit Role: Click this button next to an existing role to modify its name or description. Note that the primary System Administrator role cannot be edited.

  • Permissions: Click this button next to a role to open the granular matrix where individual system actions are enabled or disabled.

  • Save Permissions: Click this button to finalize the selected access levels for a given role.

  • Update User: Click this button to save any changes made to a specific administrator's profile, including their newly assigned roles.


  • Best Practices &and Considerations

    • Principle of Least Privilege: Always adhereAdhere to the principle of least privilege.privilege: GrantAlways grant users only the permissions absolutely necessary for them to perform their job functions. This minimizes security risks and reduces the potential for accidental system errors.

    • Role-Based Access Control: Utilize rolesrole-based toaccess managecontrol: permissions efficiently. Instead of assigning individual permissions to each user,user manually, create template roles (e.g., "Enforcement Officer," "Permit Manager," "Finance Admin") and assign users to those roles.templates. This significantly simplifies onboarding, offboarding, and security auditing.

    • ClearMaintain Roleclear Descriptionsrole descriptions:: Use the role description field to clearly state the purpose of the role and the types of permissions it encompasses. This helps other administrators quickly understand what each role is intended for.for without having to open the complex permissions matrix.

    • RegularConduct Reviewregular access reviews:: Periodically review your defined roles and user assignments to ensure they remain appropriateappropriate. Adjust roles as job responsibilities change or as staff join/members join or leave your organization.

    • Test Newnew Rolesroles before deployment:: BeforeAlways deployingtest a new role to active users, test it with a testdummy administrator account before deploying it to confirmactive users. This confirms that the assigned permissions function exactly as expected and do not inadvertently grant too much or too little backend access.