nService3 Authorization

nService authorization (i.e. access control) is based on groups. Each service in the service tree has three groups defined: user group, technician group and administrator group. Services that don’t have these three groups defined inherit them from their ancestors. If a service inherits the groups, it must inherit all three groups.

1. Services, service requests, service routing and notification rules, service statuses, service priorities, products, knowledge base, question & answer wizards, knowledge articles

Module

Action Right

Module User Group

Module Technician Group

Module Admin Group

System Admin Group

Service

Submit service requests on this service.

Yes

Yes

Yes

Yes

Add, edit, respond to, assign, close service requests of this service. Run query;

No

Yes

Yes

Yes

Delete service requests of this service;

Edit, move and delete the service;

Add, edit, delete the request routing and notification rules, statuses and priorities of this service.

No

No

Yes

Yes

Product

Can select the product in service requests.

Yes

Yes

Yes

Yes

Add, edit, delete, move products and sub-categories.

No

No

Yes

Yes

Knowledge

View knowledge articles and question & answer wizards.

Yes

Yes

Yes

Yes

Add and edit knowledge articles and question & answer wizards.

No

Yes

Yes

Yes

Delete and move knowledge articles and question & answer wizards;

Add, edit, delete, move knowledge folders.

No

No

Yes

Yes

 

2. Tasks in the calendar

Service workers can add tasks to calendar. System administrators and the owner of the tasks can delete them. Service workers are users who are in the technician group or administrator group of any service.

3. Organizations and sites, organizational units, users, groups and assets

Action Right

Users

Service Workers

System Admin Group

Add and edit organizations and sites

No

Yes

Yes

Delete organizations and sites

No

No

Yes

4. Organizational units, users, groups and assets

Action Right

Users

Service Workers

Organizational Unit Admin Group

System Admin Group

Browse organizational unit tree

Employees

Yes

Yes

Yes

Add, edit, delete and move organizational units

No

No

No

Yes

Add, edit users, groups and assets in an organizational unit

Edit Self

No

Yes

Yes

Delete users, groups and assets in an organizational unit

No

No

Yes

Yes

 

Action Right

Users

Organization Admin Users

Service Workers

System Admin Group

Add, edit users not in any organizational unit

No

Yes, within his organization

Yes

Yes

Delete users, groups and assets not in any organizational unit

No

Yes, within his organization

No

Yes

 

Organization admin users are designed for organizations other than the website owner. They don’t have any meaning in the organization that owns the website. It is designed to let the companies that you serve to manage their own users.

5. Email, event log, service zone, system settings

Only users in the system administrator group are allowed to perform any actions on these modules.

 

Copyright© 2007 Avensoft.