Access rights to a unit group allow the user to see this group on different lists, run reports on it, add and remove units from it, delete this group, and so on. Access rights to the group apply to all the units belonging to it. This means that when the user gets access rights to the group, he or she can perform the allowed actions with all the units from it.
You can change access rights to a unit group in two ways: in the properties of this group or in the user properties. In the user properties, you should select Unit groups in the filter, mark the required group in the list and select the rights the user should have to this group. Read more about granting access rights here.
When granting unit group access rights, consider the following:
- A group can expand the access rights to a unit, but not limit them. If the user's rights to a unit and a group to which it belongs differ, a wider list of rights applies.
- The user's rights to the units included in the group don’t change when the group is created or when other users are granted access rights to it.
As in the case of other macro-objects, the rights to units are divided into standard and special ones.
Standard access rights
Most of the standard rights to a group apply both to the units belonging to it and to the group itself. For example, when getting the Change icon right, the user can change the icon for each unit of the group, as well as for the group itself.
Below are the standard access rights the users may have to unit groups.
View object and its basic properties
Allows seeing the group and its units on different lists and tabs, tracking the unit movement on the map in real time, and, if route access rights are granted, allows tracking the unit movement along the route.
If this access right is granted, the General tab is displayed in the unit group properties. The right also allows seeing data in the unit properties, unit tooltips and extended information.
The View object and its basic properties access right doesn’t allow editing the properties of the group and its units and performing other actions with them. Additional access rights are required for this purpose.
The View object and its basic properties access right is given by default when any other unit group access right is granted. To take this right away, you should deprive the user of all the access rights to the unit group.
View detailed object properties
Allows seeing the following information in the properties of each unit belonging to the group:
Manage access to this object
Allows seeing the Access tab in the properties of the group and its units and giving rights to them to other users, including by means of jobs and notifications.
Allows deleting the unit group from the system. Deleting the group doesn’t lead to the deletion of the units included in it. However, when given this right to the group, the user can delete its units from the system individually.
Allows editing the names of the group and the units included in it..
View custom fields
Allows seeing general custom fields (that is, the ones not marked as administrative) in the properties of the group and its units. Also, allows seeing the Profile tab in the unit properties.
Manage custom fields
Allows creating, deleting, changing general custom fields in the properties of the group and its units. Also, allows editing the content of the Profile tab in the unit properties. This access right works only in combination with the previous one
View admin fields
Allows seeing the custom fields marked as administrative ones in the properties of the group and its units.
Manage admin fields
Allows creating, deleting, editing custom fields marked as administrative in the properties of the group and its units. This access right works only in combination with the previous one
Edit not mentioned properties
Allows editing the following sections on the Advanced tab in the properties of each unit from the group:
Enables the Icon tab in the properties of the group and its units and allows selecting the icon for the group and for each of these units, respectively.
Request reports and messages
This access right allows:
To request messages of the Log type and run a tabular report of the same name, the Manage object log access right is required, and to run the Custom fields report, the View custom fields and/or View admin fields rights are required.
Edit ACL-propagated objects
Allows adding units to the group and removing them from it.
Manage object log
In combination with the Request reports and messages access right, allows requesting messages of the Log type and running a report of the same name on the group or unit. To delete messages of the Log type, the Delete messages right is also required.
In combination with the Manage events right, allows adding custom records to the unit log by registering events.
View and download files
Allows using a file server to view and download files for this group and its units.
Upload and delete files
Allows using a file server to upload and delete files for this group and its units.
Special access rights
The set of special access rights for unit groups is the same as for units. These rights determine the actions that the user can perform with the units of the group. For example, if the user has the Edit counters special right to the unit group, this means that he or she can edit counters in the properties of any unit from this group.
Read about special access rights to units here.