0 Helpful

How to Grant Access to a Specific Application or Permission

User
Related Applications

Definition

In the openstudio.one environment, access control is granular. You aren't just turning a feature "on" for a user; you are defining who can access it, where they can use it (e.g., specific departments), and for how long. This system allows for precise management of user rights, ensuring security and operational efficiency.

Permissions Control Center > Initial view
Permissions Control Center > Initial view

 

Accessing the Grant Tool

To assign a new permission, you must first select the application you want to authorize, then navigate to the specific permission view within the administration panel. The main permission that grants access to the application is identified with the MAIN badge.

INFO: If the application only has one permission, you will be directly redirected to the permission page and the definition of profiles is disabled.
Permissions List for an App
Permissions List for an App

 

Once inside the correct module, locate and click the Grant permission (New Authorization) button found in the top header area.

Permission header > Grant permission
Permission header > Grant permission

Selecting the User

The system requires you to positively identify the target user before defining their rights. You cannot grant permissions to a user who does not exist in the system registry.

Search & Identification

In the "User to Grant" section, you have two methods to find a user:

  • Direct ID Entry: If you know the user's Personal ID, you can type it directly into the input field.
  • Directory Search: Click the Search User button to open a searchable directory of internal staff.

Once a user is selected, the system displays a visual "User Chip." This element confirms the selection by showing their photo, full name, ID, and main department, ensuring you are granting rights to the correct person.

This action launches a dedicated modal window where you can configure every aspect of the user's access, from the specific rights they receive to the duration of their authorization.

Grant permission to a selected user
Grant permission to a selected user

From this modal you can:

  • Select the user to authorize
  • According to the permission type, define the value and parameters of the authorization
  • Define from when the permission is valid
  • Define until when the permission needs to be valid
    If left empty, the permission does not expire
Founder Restrictions (God Mode): If you attempt to select a user designated as a Founder, the system will prevent the action. Founders possess "God Mode" status, granting them permanent, full access to the entire system automatically. Manual grants are therefore unnecessary and disabled for these users.

Configuring Access Scope

Depending on the specific permission type, you may need to define the Structure / Scope of the access. This determines where the user is allowed to exercise their authority.

Global Access

If the permission applies system-wide (e.g., "Login Access" or "General Reporting"), the scope input may default to "Global" or be hidden entirely, as no specific target is required.

Specific Structure

For permissions tied to organizational units (e.g., "Manage Shifts" or "Approve Expenses"), a dropdown menu allows you to select a specific Department or Area. This limits the user's power strictly to that unit. For example, a user could be granted "Manager" rights for the "Marketing Department" but have no access to the "Finance Department".

[Screenshot: The 'Structure / Scope' dropdown menu showing department options]

Defining Permissions (Value)

The Value section determines exactly what the user can do within the defined scope. The interface adapts based on the technical complexity of the permission.

Standard Options

For simple access levels, you will see a list of radio buttons. Common examples include "Read Only," "Editor," or "Full Access". Only one option can be active at a time.

Complex Lists & Bulk Actions

For permissions involving multiple items—such as specific "Report Categories," "User Groups," or multiple "Structures"—a searchable list of checkboxes is provided.

To assist with managing large lists, the system provides several helper tools:

  • Live Search: Use the search bar to filter options by name. For example, typing "Finance" will instantly hide all non-finance groups.
  • Bulk Selection: Use the Select All, Select None, or Invert buttons to rapidly change multiple settings at once.
  • Area Grouping: If options are grouped by Area, you can use specific bulk selectors to toggle all items within that Area (e.g., "Select All in Area North").
Zero Value Warning: You must select at least one option. If you attempt to save without selecting any values, the system will warn you that having no options selected is effectively the same as having no permission.

Validity Settings (Time-Based Access)

Access can be scheduled or temporary, managed via the Validity Settings section. This feature is critical for maintaining security compliance and reducing manual cleanup.

Valid From

This field defaults to the current date. If left as is, the access activates immediately upon saving. If you select a future date, the permission will be saved in a Pending state, and the user will not have access until that specific date arrives.

Valid Until

This field is optional. Leaving it empty grants Unlimited Validity, meaning the access never expires. Setting a date ensures access automatically expires at the end of that day (23:59:59). This is highly recommended for temporary projects, audits, or contractor access.

Confirmation & System Checks

Before saving the new authorization, the system performs automatic validation to prevent data errors and conflicts.

Duplicate Check

The system verifies if the user already has a manual permission for the selected scope. If a duplicate exists, the system blocks the request to prevent database conflicts and ensures data integrity.

Profile Overlap

If the user already inherits this permission via a Permission Profile (e.g., "Audit controller"), a warning message will appear. You are allowed to proceed, but be aware that this manual grant will override the profile's settings for that specific scope. This is often used to grant extra rights that are not included in the standard profile.

Instant Activation: Upon clicking Confirm, the system instantly invalidates the user's cache. This ensures their new permissions are applied immediately without requiring them to log out and log back in.

Did you find this article helpful?
0 out of 0 found this helpful

divider

Related Articles

Sponsored
arrow-up icon
ESC