Definition
In the openstudio.one environment, access control is granular. You aren't just turning a feature "on" for a user; you are defining who can access it, where they can use it (e.g., specific departments), and for how long. This system allows for precise management of user rights, ensuring security and operational efficiency.
Accessing the Grant Tool
To assign a new permission, you must first select the application you want to authorize, then navigate to the specific permission view within the administration panel. The main permission that grants access to the application is identified with the MAIN badge.
Once inside the correct module, locate and click the Grant permission (New Authorization) button found in the top header area.
Selecting the User
The system requires you to positively identify the target user before defining their rights. You cannot grant permissions to a user who does not exist in the system registry.
Search & Identification
In the "User to Grant" section, you have two methods to find a user:
- Direct ID Entry: If you know the user's Personal ID, you can type it directly into the input field.
- Directory Search: Click the Search User button to open a searchable directory of internal staff.
Once a user is selected, the system displays a visual "User Chip." This element confirms the selection by showing their photo, full name, ID, and main department, ensuring you are granting rights to the correct person.
This action launches a dedicated modal window where you can configure every aspect of the user's access, from the specific rights they receive to the duration of their authorization.
From this modal you can:
- Select the user to authorize
- According to the permission type, define the value and parameters of the authorization
- Define from when the permission is valid
- Define until when the permission needs to be valid
If left empty, the permission does not expire
Configuring Access Scope
Depending on the specific permission type, you may need to define the Structure / Scope of the access. This determines where the user is allowed to exercise their authority.
Global Access
If the permission applies system-wide (e.g., "Login Access" or "General Reporting"), the scope input may default to "Global" or be hidden entirely, as no specific target is required.
Specific Structure
For permissions tied to organizational units (e.g., "Manage Shifts" or "Approve Expenses"), a dropdown menu allows you to select a specific Department or Area. This limits the user's power strictly to that unit. For example, a user could be granted "Manager" rights for the "Marketing Department" but have no access to the "Finance Department".
[Screenshot: The 'Structure / Scope' dropdown menu showing department options]
Defining Permissions (Value)
The Value section determines exactly what the user can do within the defined scope. The interface adapts based on the technical complexity of the permission.
Standard Options
For simple access levels, you will see a list of radio buttons. Common examples include "Read Only," "Editor," or "Full Access". Only one option can be active at a time.
Complex Lists & Bulk Actions
For permissions involving multiple items—such as specific "Report Categories," "User Groups," or multiple "Structures"—a searchable list of checkboxes is provided.
To assist with managing large lists, the system provides several helper tools:
- Live Search: Use the search bar to filter options by name. For example, typing "Finance" will instantly hide all non-finance groups.
- Bulk Selection: Use the Select All, Select None, or Invert buttons to rapidly change multiple settings at once.
- Area Grouping: If options are grouped by Area, you can use specific bulk selectors to toggle all items within that Area (e.g., "Select All in Area North").
Validity Settings (Time-Based Access)
Access can be scheduled or temporary, managed via the Validity Settings section. This feature is critical for maintaining security compliance and reducing manual cleanup.
Valid From
This field defaults to the current date. If left as is, the access activates immediately upon saving. If you select a future date, the permission will be saved in a Pending state, and the user will not have access until that specific date arrives.
Valid Until
This field is optional. Leaving it empty grants Unlimited Validity, meaning the access never expires. Setting a date ensures access automatically expires at the end of that day (23:59:59). This is highly recommended for temporary projects, audits, or contractor access.
Confirmation & System Checks
Before saving the new authorization, the system performs automatic validation to prevent data errors and conflicts.
Duplicate Check
The system verifies if the user already has a manual permission for the selected scope. If a duplicate exists, the system blocks the request to prevent database conflicts and ensures data integrity.
Profile Overlap
If the user already inherits this permission via a Permission Profile (e.g., "Audit controller"), a warning message will appear. You are allowed to proceed, but be aware that this manual grant will override the profile's settings for that specific scope. This is often used to grant extra rights that are not included in the standard profile.