Only a user with administrator rights can create Access Group Profiles, add roles to profiles, or assign Access Group Profiles to users.
Access Group Profiles are managed in Administration → Master Data → Access Group Profiles. Profiles are assigned to users through Administration → Master Data → Users → Access rights.
Users You can add roles to an existing custom custom Access Group Profile or create a new profile with the required roles.
Roles are added to an Access Group Profile. The profile is then assigned to a user through the user's Access rights.
Important: You user cannot add a role directly to a user's Access rights. To give a user an additional role, add the role to an Access Group Profile and assign that profile to the user.
...
If the required role needs to be added to an existing custom Access Group Profile, you an administrator can edit the profile and select the required role.
- Go to Administration → Master Data → Access Group Profiles.
- Open the required custom Access Group Profile.
- Open the Access Groups tab.
- In the Allowed Actions (Roles) area, find the required role.
Find a Role in the List
The Selected Roles Only option controls which roles are displayed in the list.
When Selected Roles Only is enabled, the system displays only the roles that are already selected in the current profile. It does not display all roles available in the system.
If you want to add a new role, clear the :
- Clear Selected Roles Only
...
- .
...
- Use the Search field to find the required role.
- Select the checkbox next to the role.
- Save the profile.
Screenshot: Show the Allowed Actions (Roles) area with After clearing Selected Roles Only enabled and then disabled, highlighting that additional roles become available after the option is cleared., the list displays the roles available in the system, including roles that are not yet selected in the profile.
Important: If Selected Roles Only is enabled, a role that is not yet included in the profile will not appear in the list. Clear Selected Roles Only before searching for a role that you want to add.
...
Create a New Access Group Profile with Roles
If you user do not want to modify an existing custom profile, you an administrator can create a new Access Group Profile containing the required roles.
- Go to Administration → Master Data → Access Group Profiles.
- Select Create.
- Enter a name for the new profile.
- Open the Access Groups tab.
- In the Allowed Actions (Roles) area, make sure Selected Roles Only is cleared.
- Use the Search field to find the required role.
- Select the checkbox next to the role.
- Repeat the search and selection for each additional role that needs to be included.
- Select Save and close.
The new Access Group Profile now contains the selected roles.Screenshot: Show a newly created Access Group Profile on the Access Groups tab with Selected Roles Only cleared and several required roles selected.
Important: Creating a new Access Group Profile does not automatically assign it to any user.
...
After creating a new Access Group Profile, an administrator must assign it to the user who needs the roles included in the profile.
- Go to Administration → Master Data → Users.
- Open the required user.
- Open the user's Access rights.
- Find the newly created Access Group Profile.
- Select the checkbox next to the profile.
- Save the changes.
The user now receives the roles included in the assigned Access Group Profile.Screenshot: Show the user's Access rights with the newly created Access Group Profile selected.
Note: You do not need to assign the profile again when you add a role to an existing profile that is already assigned to the user. The updated role is included in the permissions provided by that profile.
...
Standard system Access Group Profiles cannot be modified by the user.
If the required role cannot be added because the profile is a standard system profile, an administrator must create a new custom Access Group Profile containing the required roles instead.
Screenshot: Show a standard system profile where the roles cannot be edited.
Important Notes
- Only users with administrator rights can create Access Group Profiles, add roles to profiles, or assign profiles to users.
- Roles are added to Access Group Profiles, not directly to users.
- You can add roles to an existing custom Access Group Profile if it is available for editing.
- To add a role that is not currently included in a profile, clear Selected Roles Only before searching for the role.
- Selected Roles Only displays only roles that are already selected in the current profile, not all roles available in the system.
- A new Access Group Profile can contain one or multiple required roles.
- A newly created profile must be assigned to the required user through Users → Access rights.
- If a role is added to an existing profile that is already assigned to a user, the profile does not need to be assigned again.
- After changing access rights, the affected user must log out and log in again before checking the result.
Thank you for being FirstBIT Customer!






