Changes to Reserve's Roles & Rights were released on May 17, 2024.
Updates to this article are in red.
A pdf of this article is posted at the bottom.
Overview
Key points
Deviation from default role templates
Notable changes to existing rights
Working with custom roles and updating existing templates
Before you begin
Creating custom roles
Viewing role descriptions
Editing and deleting roles
Assigning roles in the web application
Assigning roles in the DMU
Personalized roles
Overview
Currently, there are four user role templates available in Reserve: Registered User, Community Manager, Manager, and Administrator. Each user must have one of the four roles, and customization is allowed for each user. Soon, changes to the structure and approach for Roles & Rights will increase flexibility and simplify the management of rights. When Custom Role Templates are released, Administrators may create additional templates. They'll also have the option to personalize rights for specific users who require a set of rights which differ from the templates.
When the changes to roles & rights are released on May 17, any user having rights which differ from the rights in their role template will automatically be given a Personalized Role. An Administrator can then assign them a new Custom Role once the desired Custom Roles have been created.
Key points
- Role templates are sets of user rights. Each user must be assigned a role; previously limited to Registered User, Community Manager, Manager, and Administrator. The names of these four default role templates cannot be changed or used as names for Custom Roles.
- Administrators can create unlimited additional role templates at Settings>General>Roles & Rights. These are Custom Roles. All changes to role templates are done in this screen. Administrators may select an existing role as a basis for a Custom Role, then check or uncheck various rights.
- The name of each Custom Role is a freeform text field. Reserve will not translate the text that you enter here.
- Each role has an optional description field, where administrators can add notes up to 256 characters.
- Once a Custom Role has been created, it can be associated to users via the DMU or at Settings>Users>User Role & Rights by a user who has the right to Manage User's Role. The DMU cannot create new roles dynamically.
- When an administrator makes changes to a role template by selecting or unselecting specific rights and saving, the changes are applied asynchronously to all users having that role. This will overwrite the current rights settings for users associated to that role. This will not apply to any users having a Personalized Role.
- The rights for the selected role are displayed as read-only in Settings>Users>User Role & Rights and My Profile: Role & Rights.
- If a user requires a set of rights which differ from the role templates, their rights can be personalized by a user who has the right to Manage User's Rights.
- By selecting Personalized for a given user in Settings>Users>User Role & Rights, the checkboxes for the rights become enabled. Any rights except those in the Account Rights section may be selected for that user. The Personalized setting should be used sparingly since it requires manual update anytime that user needs a right that has been added to the system. Personalized rights will not be updated when an administrator makes changes to a role template.
- Rights for users having a Personalized Role may only be updated by a user who has the right to Manage User's Rights and this must be done in the web application. That user may check or uncheck rights in Settings>Users>User Role & Rights.
- The DMU cannot be used to update individual rights or to assign a Personalized Role. It will only allow the assignment of a user role to a user.
- Users may need to log out and back in for changes in rights to take effect.
Role templates are managed in the screen shown below, which is Settings>General>Roles & Rights
A user's role may be assigned via the DMU or in the screen shown below, which is Settings>Users>User Role & Rights
Deviation from default role templates
Any users added to the system prior to May 17, 2024 could potentially have rights which differ from the role template assigned to them. This is nothing new, but these deviations are important to be aware of because when the changes to roles & rights are released on May 17, any user having deviated rights (rights which differ from the rights in their role template) will automatically be given a Personalized Role since deviations cannot be preserved or displayed in the system any other way.
- For example, when Susan Smith was added to the system in 2023, her user role was set to Registered User. At the time, the template for the Registered User role did not have the Manage Own Delegates right enabled. Susan needed the right to Manage Own Delegates so an administrator checked it off just for her. This caused Susan to have deviated rights (a set of rights that differed from the role template for Registered User), yet her role was still technically Registered User. Logic in the system at the time dictated that, if rights were changed in role templates, those changes only applied to users who were added to the system AFTER the template changes were saved. They didn't apply retroactively to users already having that role, which led to potentially many variations of each role.
- Prior to the release on May 17, Susan's role is Registered User.
- After the release on May 17, Susan's role is automatically set to Personalized so that she can keep Manage Own Delegates enabled (as well as any other customizations). A user must have the right to Manage Another User's Rights in order to check/uncheck rights for Susan.
- After the release on May 17, an Administrator can create a Custom Role that will meet Susan's (and potentially other users') needs and then assign that role to Susan instead of the Personalized Role. This will ensure that whenever new rights are added to the system, those new rights can easily be managed by an Administrator who will check or uncheck the rights in the role templates rather than having to go into each Personalized Role and check any new rights that need to be enabled.
- Administrators can go into Settings>Users and select Personalized in the User Role dropdown menu to see all of the users who have a Personalized Role. Or they can download the user file from the DMU (Data Management Utility).
- After May 17 it will no longer be possible to have a user with deviated rights assigned to a role template. When an administrator makes changes to a role template by selecting or unselecting specific rights and saving, the changes will now be applied asynchronously to all users having that role.
- Important notice regarding the four Account Rights in the upper left (Manage Instances, Manage General Account Settings, Manage System, and Visitor Administrator): These 4 rights require tighter control and are therefore DISABLED in the UI for Personalized Roles. They can only be enabled for Default/Custom Roles. Tighter still is the right to Manage General Account Settings, which is only enabled for the role of Administrator. There is one caveat to this: On May 17 when users who had deviated rights are switched to Personalized, if they had any of the the four Account Rights, those rights will still be enabled for them yet those rights will not be checked off in the UI. It is important for an Administrator to move such users into the appropriate Default/Custom Roles so that those Account Rights don't get overwritten when other changes are made within the Personalized Role for such users.
Notable changes to existing rights
- The right previously labeled Manage Another User's Role has changed to Manage User's Role. A user who has this right will be able to select user roles from the drop-down in the Settings>Users>User Role & Rights screen, but not create custom roles or personalized roles. They can select their own role.
- The right previously labeled Manage Another User's Rights has changed to Manage User's Rights. A user who has this right will be able to select user roles from the drop-down and create personalized roles in the Settings>Users>User Role & Rights screen. They can manage their own rights.
- Manage Own User Role and Manage Own User Rights have been removed from the system.
- After May 17, when changes are made to any of the four existing default role templates (Registered User, Community Manager, Manager, and Administrator), the current rights settings for users with that role will be overwritten. This is because of the new logic: When an administrator makes changes to a role template by selecting or unselecting specific rights and saving, the changes are applied asynchronously to all users having that role.
Working with custom roles and updating existing templates
The role of Administrator is intended to be the highest-level role. It is the only role allowed to have the Manage General Account Settings right. A user must have the right to Manage General Account Settings (and therefore, the role of Administrator) in order to create/modify custom role templates and to have the ability to assign the role of Administrator to another user. Administrator is one of the four default roles that cannot be removed and it should be associated to a very small number of users.
Before you begin
1. Perform an assessment
- Determine the kinds of roles your organization needs, considering the requirements at various locations. Within Reserve there is one list of roles and it is available across all locations.
- Review the rights which are currently enabled in the templates (see step 3 below and do not make changes yet).
- Note all users who have rights which differ from their assigned role and what those differences are. If you do this before the release on May 17 you'll be able to see the role assigned to that user. If you wait until after the release on May 17, all of these users will have a Personalized Role. To see all of the users who have a Personalized Role after May 17, download the user file from the DMU or go into Settings>Users and select Personalized in the User Role dropdown menu.
- Why does this matter? Consider the example of a user with deviated rights who will automatically be given a Personalized Role during the release on May 17. Be sure to read the last bullet in that section.
2. Decide whether you want to update any of the four default role templates now, after the release, or not anytime soon. These are Registered User, Community Manager, Manager, and Administrator. Keep in mind that these templates will be used as a starting point when you create Custom Roles.
- If you do this before the release on May 17 then only users created after you make your changes are guaranteed to have those exact rights. Existing users will be deviated from whatever you check/uncheck unless you also go separately into each user record and check/uncheck those same rights.
- If you do this after the release on May 17 then the changes in rights are applied asynchronously to all users having that role. These changes would not be applied to any users who were automatically given a Personalized Role on May 17.
- If your current role templates are fine as is, you do not need to update them anytime soon. Just be aware that when new rights are added to the system in the future, you will need to check them off in your templates to enable them for the desired users.
3. Update the default templates
3A. As an Administrator, in the Reserve Web Application go to Settings>General>Roles & Rights. If you do this before the release on May 17, the roles are listed in a dropdown menu. If you do this after the release on May 17, the roles are displayed as a list (see image in next section) and you will select the desired template by clicking on the radio button next to the template's name. Once you've selected a template, the rights for that template will be displayed. Enabled rights are checked and disabled rights are unchecked.
3B. Check or uncheck the appropriate rights, scroll to the bottom and press Save.
Creating custom roles
1. After the release on May 17, as an Administrator, in the Reserve Web Application go to Settings>General>Roles & Rights. Click on the to add a custom role.
The Custom Role window will open.
2. Enter a name for the role. The description field is optional, intended only to assist with role management. Select the existing role to use as a basis. Press Save.
*Note that custom roles cannot be named "Personalized" or "Personalised."
3. The role you created will now appear in the Role Templates column, in alphabetical order below the default roles. When the radio button next to that role's name is selected and the Rights tab is selected, that role's rights are displayed. Enabled rights are checked and disabled rights are unchecked. If the role has a description, it is displayed above the rights. Check or uncheck the appropriate rights, scroll to the bottom and press Save.
The roles that are shown in the Role Templates column are now available where roles are assigned to users, in Settings>Users>User Role & Rights, in alphabetical order below the default roles. See instructions for Assigning roles in the web application or Assigning roles in the DMU.
Viewing role descriptions
To view the Role Descriptions for all of the roles at once, select Role Descriptions in the right-hand column. Select Rights to view the list of rights.
Editing and deleting roles
To edit the name, description, or basis of a role, click on the icon. The names of the four default role templates cannot be changed. To delete a custom role, click on the
icon.
Assigning roles in the web application
When using the web application to assign roles, they must be assigned to one user at a time. See the next section for assigning roles in bulk via the DMU.
1. As an Administrator or a user with the right to Manage User's Role, in the Reserve Web Application go to Settings>Users and click on the name of the desired user.
2. On the left, select the User Role & Rights tab.
3. Note the user's current role setting shown at the top of the screen. When User Role is selected, the user's assigned role is shown in the drop-down menu. Alternatively, Personalized can be selected if a user requires a set of rights which differ from the role templates, but this setting should be used sparingly. See the Personalized roles section for details.
4. The User Role radio button should be selected. Click on the drop-down menu to see the list of available roles. If the role has a description, it will be shown when hovering over the role.
5. Click on the desired role. The rights for the selected role are displayed as read-only.
6. Scroll to the bottom and press Save.
Assigning roles in the DMU
1. As an Administrator or a user with the right to Manage User's Role, sign into the Data Management Utility.
2. Go to Users> Add New Users>Download New Users Template and download the user data
3. In the .csv file add rows for any new users.
4. In the User Role column, specify the appropriate role for each user.
*Users already having personalized roles will have "Personalized" in the User Role column. You cannot use the DMU to change a user's role from one of the default or custom roles to a Personalized role. This must be done in the web application so that specific rights can be checked/unchecked for that user.
5. Upload the user data.
Personalized roles
If a user requires a set of rights which differ from the role templates, their rights can be personalized within the web application by a user who has the right to Manage User's Rights. By selecting Personalized for a given user, the checkboxes for the rights become enabled and that user is no longer assigned to a role. The Personalized setting should be used sparingly since it requires manual update anytime that user needs a right that has been added to the system. Personalized roles cannot contain any of the four Account Rights that are in the upper left (Manage Instances, Manage General Account Settings, Manage System, and Visitor Administrator).
1. As an Administrator or a user with the right to Manage User's Rights, in the Reserve Web Application go to Settings>Users and click on the name of the desired user.
2. On the left, select the User Role & Rights tab.
3. Click on the Personalized radio button. The checkboxes for the rights become enabled.
4. Check/uncheck the appropriate rights. Any rights except those in the Account Rights section may be selected for that user.
5. Scroll to the bottom and press Save.
When new rights needed by this user are added to the system, the steps above must be repeated to enable those rights.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article