With application roles, you can set the end user access to modules, data views, pages, and applications more granularly. For example, you can grant access to an Approve Vacation module to a Manager role, and then assign end users to this Manager role to grant them access to the Approve Vacation module.
Overview
-
Create an application role on the Roles page of your application.
-
Select the respective environment.
Assigning is environment-specific, meaning, the same application role can have different end users or end user groups assigned for different environments. -
Assign end users or end user groups to this application role.
-
On the application’s Build page, set the end user access level to Application role and select the application roles you want to grant access to.
-
All end users assigned to that application role in a respective environment will automatically have access to the same modules, data views, pages, and applications that the application role has access to.
Create a new application role
In your application’s side navigation, click on Roles. Then,
- Select New role.
- Enter a name for the role.
- Optionally, enter a description to share more information about the role.
- Select Save role.
Assign end users to an application role
Once you have created at least one application role, you can assign specific end users to the role.
- In the dropdown on the top right, select the environment for which you want to assign end users to an application role. You need to assign separately for each environment.
- In the column Environment’s end users and groups, click Assign for the application role you want to assign end users to.
- In the modal, type in the email address of an existing user.
- Click Add user to add them to the list. Repeat step 3 and 4 to add more end users.
- Save changes.
Delete an application role
You can delete application roles that are no longer needed. However, you can only delete them if they are not used for giving access to a module, data view, page or the entire application.
To delete an application role, click the three dot icon next to the role’s name in the Application roles list. Then, select Delete and confirm deletion.
Unassign end users from application roles
- In the dropdown in the Environment’s end users and groups section, select the environment for which you want to unassign end users from an application role.
- Below, click Assign for the application role you want to unassign end users from.
- In the popup, click the trash icon next to the end user’s name.
- Save changes.
Related topics
- You also can create end users on client environments. Then, you can assign those end users to an application role in this client environment.
- If you are using SSO, you can automate the mapping of end user groups using features available to admins, as detailed in this documentation.