1b.app
Link copied -

When changing positions, the employee's access rights are not removed

When changing positions, the employee's access rights are not removed
Example:
Assign a position to a contact
and he has access rights
Now we delete the position and assign a new one
And in access rights, he still had the rights from the previous role
Although the new permissions do not have these permissions
https://crm.sportlife.ua/
And when we delete a position from an employee, then he retains access rights, although he was not given any rights in the card.
Original question is available on version: ru

Answers:

access rights are not assigned to the role as a whole
they only change when you change them in role
so everything worked correctly
19.09.2021, 20:00
Original comment available on version: ru

Strange logic. I understand that if the company has 10 employees, then you can go to the card and reset the rights.
But if the company has 400 employees and changes are constantly taking place, then you can’t keep track of it. + In addition, you need to train staff that when changing roles, extra rights may remain.
It is logical that if I assigned a role to an employee, he was assigned the rights of the role.
The role has deleted the rights rolled back to its original rights.
When changing roles, the rights of the new role should be assigned, and not some of the rights from the old position should remain.
I'll just give an example:
The company has several departments, their applications, orders are separated by rights. They should not see orders from other departments.
And so the employee was transferred from one department to another.
They changed his position in the card - and now he already sees the orders of both departments.
20.09.2021, 09:29
Original comment available on version: ru


Andrew
PM Digital Transformation
Client wrote:
Strange logic. I understand that if the company has 10 employees, then you can go to the card and reset the rights.
But if the company has 400 employees and changes are constantly taking place, then you can’t keep track of it. + In addition, you need to train staff that when changing roles, extra rights may remain.
It is logical that if I assigned a role to an employee, he was assigned the rights of the role.
The role has deleted the rights rolled back to its original rights.
When changing roles, the rights of the new role should be assigned, and not some of the rights from the old position should remain.
I'll just give an example:
The company has several departments, their applications, orders are separated by rights. They should not see orders from other departments.
And so the employee was transferred from one department to another.
They changed his position in the card - and now he already sees the orders of both departments.


Well everyone has their own logic.
1. If the user has 2 roles, then the rights are combined
2. If the user has the AAA role of BBB, then by my rights that are configured for BBB, I can go in and additionally add rights to the user and this is also convenient
so it depends which way you look
20.09.2021, 10:39
Original comment available on version: ru


Ustimenko Igor
OneBox production
Administrator
OneBox CTO wrote:

Andrew
PM Digital Transformation
Client wrote:
Strange logic. I understand that if the company has 10 employees, then you can go to the card and reset the rights.
But if the company has 400 employees and changes are constantly taking place, then you can’t keep track of it. + In addition, you need to train staff that when changing roles, extra rights may remain.
It is logical that if I assigned a role to an employee, he was assigned the rights of the role.
The role has deleted the rights rolled back to its original rights.
When changing roles, the rights of the new role should be assigned, and not some of the rights from the old position should remain.
I'll just give an example:
The company has several departments, their applications, orders are separated by rights. They should not see orders from other departments.
And so the employee was transferred from one department to another.
They changed his position in the card - and now he already sees the orders of both departments.


Well everyone has their own logic.
1. If the user has 2 roles, then the rights are combined
2. If the user has the AAA role of BBB, then by my rights that are configured for BBB, I can go in and additionally add rights to the user and this is also convenient
so it depends which way you look

Yes, but if personal and role rights were separated, everything would work the same way. That is, the rights of roles and personal are united. But when we delete a role, only personal ones remain.
Is it possible to make a revision so that when we delete a role, the rights added by this role are deleted? (but it is important to note that if an employee has several roles or has personal settings and does not intersect with the rights of the remote role, then these rights should remain)
And how many hours?
20.09.2021, 11:02
Original comment available on version: ru


Andrew
PM Digital Transformation wrote:
And how many hours?

6
29.09.2021, 02:15
Original comment available on version: ru

Please join the conversation. If you have something to say - please write a comment. You will need a mobile phone and an SMS code for identification to enter. Log in and comment