You can add roles to an existing custom Access Group Profile or create a new profile with the required roles.
Roles are added to an Access Group Profile. The profile is then assigned to a user through the user's Access rights.
Important: You cannot add a role directly to a user's Access rights. To give a user an additional role, add the role to an Access Group Profile and assign that profile to the user.
Add a Role to an Existing Custom Profile
If the required role needs to be added to an existing custom Access Group Profile, you can edit the profile and select the required role.
- Go to Administration → Master Data → Access Group Profiles.
- Open the required custom Access Group Profile.
- Open the Access Groups tab.
- In the Allowed Actions (Roles) area, find the required role.
Find a Role in the List
The Selected Roles Only option controls which roles are displayed in the list.
When Selected Roles Only is enabled, the system displays only the roles that are already selected in the profile.
If you want to add a new role, clear the Selected Roles Only option first.
After clearing the option:
- Use the Search field to find the required role.
- Select the checkbox next to the role.
- Save the profile.
Screenshot: Show the Allowed Actions (Roles) area with Selected Roles Only enabled and then disabled, highlighting that additional roles become available after the option is cleared.
Important: If Selected Roles Only is enabled, a role that is not yet included in the profile will not appear in the list. Clear Selected Roles Only before searching for a role that you want to add.
The selected role is now included in the existing custom Access Group Profile.
Note: If the profile is already assigned to users, adding a role to that profile adds the role to the permissions provided by the profile. The affected users must log out and log in again before checking the updated access rights.
Create a New Access Group Profile with Roles
If you do not want to modify an existing custom profile, you can create a new Access Group Profile containing the required roles.
- Go to Administration → Master Data → Access Group Profiles.
- Select Create.
- Enter a name for the new profile.
- Open the Access Groups tab.
- In the Allowed Actions (Roles) area, make sure Selected Roles Only is cleared.
- Use the Search field to find the required role.
- Select the checkbox next to the role.
- Repeat the search and selection for each additional role that needs to be included.
- Select Save and close.
The new Access Group Profile now contains the selected roles.
Screenshot: Show a newly created Access Group Profile on the Access Groups tab with Selected Roles Only cleared and several required roles selected.
Important: Creating a new Access Group Profile does not automatically assign it to any user.
Assign a New Profile to a User
After creating a new Access Group Profile, assign it to the user who needs the roles included in the profile.
- Go to Administration → Master Data → Users.
- Open the required user.
- Open the user's Access rights.
- Find the newly created Access Group Profile.
- Select the checkbox next to the profile.
- Save the changes.
The user now receives the roles included in the assigned Access Group Profile.
Screenshot: Show the user's Access rights with the newly created Access Group Profile selected.
Note: You do not need to assign the profile again when you add a role to an existing profile that is already assigned to the user. The updated role is included in the permissions provided by that profile.
Log Out and Log In Again
After adding a role to a profile or assigning a new profile to a user, the affected user must log out and log in again.
Always perform a new login before checking whether the updated access rights are available.
Important: Do not check the updated permissions in the user's existing session. Log out and log in again first.
Standard System Profiles
Standard system Access Group Profiles cannot be modified by the user.
If the required role cannot be added because the profile is a standard system profile, create a new Access Group Profile containing the required roles instead.
Screenshot: Show a standard system profile where the roles cannot be edited.
Important Notes
- Roles are added to Access Group Profiles, not directly to users.
- You can add roles to an existing custom Access Group Profile if it is available for editing.
- To add a role that is not currently included in a profile, clear Selected Roles Only before searching for the role.
- Selected Roles Only displays only roles that are already selected in the current profile.
- A new Access Group Profile can contain one or multiple required roles.
- A newly created profile must be assigned to the required user through Users → Access rights.
- If a role is added to an existing profile that is already assigned to a user, the profile does not need to be assigned again.
- After changing access rights, the affected user must log out and log in again before checking the result.
Thank you for being FirstBIT Customer!