Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Fixed Sys role description

...

Table of Contents
minLevel1
maxLevel2

...

Concept

The primedocs authorization concept pursues the following goals:

...

A primedocs group can contain groups or users - this can be defined statically or made dynamic by a configuration. For dynamic groups, a configuration is stored which automatically assigns or removes a user from a group based on user information.

...

Permissions

Permission / Role

Sys admin

Org admin

User admin

Template admin

Campaign admin

Snippet admin

User

Manage organizations

Manage logo

Manage templates

Modify templates and their permissions

1

Manage users

Manage shared snippets

2

Create template snippets

Manage fields

Manage campaigns

Manage signatures

  1. Provided that the template administrator has an explicit modification right on the template.

  2. Provided that the user has an explicit modification right on the snippet.

The following roles permissions are provided in primedocs:

System administrator

Highest authorization. System administrators can assign roles for users and groups. In addition, they can edit all templates (including those to which the user does not have explicit modification rights) and manage organizations, snippets, users and fields.

Organization administrator

...

User

"User" controls whether the respective user can log in to primedocs or not. This authorization is initially set by default.

Dev

"Dev" enables functions for developers that regular users don't need.

System administrator

This permission includes all other permissions from here to the right (i.e. "Org", "User", etc.). The system administrator can set permissions for users and user groups in primedocs desktop. Furthermore, they can manage all templates as well as organizations, snippets and users and their profiles in primedocs.

Organization administrator

This permission allows the administration of organizational units (OUs). If the user has this permission, they will see the "Organizational units" entry in the "Organization" tab in primedocs desktop and can create new OUs, modify existing ones (change logos, change addresses, etc.) and delete them.

User administrator

Permission to administrate all This permission allows the user to manage users and their profiles: this is useful for all those who provide support for the OneOffixx environment. If the user has this permission, they will see the "User / profile administration" entry in the "Organization" tab in primedocs desktop. There they can manage users and their profiles; create, edit and delete users/profiles as well as share profiles in the name of other users.

Template administrator

Permission to edit and create templates: Template administrators see This permission enables the maintenance of templates:

  • The template administrator sees all templates and their permissions.

  • However,

...

  • a user can only

...

  • edit templates and their authorizations if they have the explicit right to make changes to the template.

  • The template administrator can also edit all

...

  • designer snippets and create new ones. They have

...

  • the right to

...

  • make changes to the global document functions, the global configurations and translations

...

  • and to all tags.

Campaign administrator

Permission to Campaign administrators can create, edit and create delete email campaigns.

Snippet administrator

Permission to edit and create shared snippets: snippet administrators do not need explicit modification rights on the snippets. They This authorization enables the administration of all shared text modules ("snippet"). In contrast to the template administrator, the snippet administrator does not require explicit editing rights to a snippet or snippet category: they can always edit all snippets.

...

Read access and Write access is only granted the corresponding user. System and snippet administrators do not have access for privacy reasons.

...

Assigning permissions in the dashboard

Open the Admin Dashboard in the browser.

Go to the Security tab.

Authorize individual users

Select the user to be authorized or search using the Search Query text field.

Alternatively, you can also create primedocs groups or assign the authorizations to a Windows group that is available to you. With the latter, the authorized users can be regulated via your internal authorization concepts instead of via primedocs.

You can find a screenshot of this below under Alternative: Authorize Windows groups.

(1) Place a tick in the row of the user and the column of the correct permission(s).

(2) Click on save in the corresponding line.

...

Alternative: Authorize Windows Groups

Select the windows groups tab.

(1) Search for an existing AD group in the "New User Group" field and add it by clicking on +Create User Group.

(2) Assign the required authorizations to the added Windows group.

(3) Click on save in the corresponding line.

...