[[brix:en:users]]
====== ~ PERMISSIONS ~ ======
On this tab the administrator sets the user's access to companies and departments, their role, permissions for working on individual documents and DMS groups. The tab has three sections.
===== Company and department access =====
* //**{Company}**// — The [[brix:en:companies|company]] the user has access to.
* //**{Department}**// — The company [[brix:en:departments|department]] the user has access to. If no department is selected, the user has access to all departments of the company.
* //**{Role}**// — //admin// or //user//. An administrator has access to all company data and all programs from the modules the company subscribes to; for a user with the //user// role the programs are switched on individually in the **//[[brix:en:users:programs]]//** tab.
* //**{Partner}**//
Buttons: **SAVE** saves the access, **DELETE** removes the user's access to that company, and **CANCEL** discards unsaved changes.
===== Documents =====
Permissions apply only to documents and are entered separately for each user, per document type.
* //**{Document}**// — The document type the permissions apply to.
* //**{Permissions}**// — One or more permissions: //Delete//, //Update//, //Invoicing//, //Read//, //Void//, //Create// and //Approve//. Each permission has the same meaning in all documents.
The **SAVE** button saves the permissions and **CANCEL** discards them.
If no permission is entered for a document, the user is allowed everything on that document. As soon as any permission is entered for a document, the user may do on that document only what is explicitly permitted.
Not all documents have a built-in permission check. On documents without the check, entered permissions have no effect.
===== DMS groups =====
A list of all [[brix:en:dms_groups|DMS groups]] of the company is shown. The switch next to a group enables or disables the user's access to the documents of that group.
DMS groups control access to documents in the [[brix:en:dms]] system only partially. Detailed access control is set separately on each DMS document.