Authorisation groups determine which features and menu items are available to users in the portal. By grouping rights, you can easily manage users' access level.
Requirements
- You need the Beheer_rechtengroepen right to configure authorisation groups.
Open authorisation groups
Go to Management > General management > Manage authorisation groups to open the overview of authorisation groups.
Create an authorisation group
- Click New authorisation group.
- Enter the following information:
| Field name | Description | Required |
|---|---|---|
| Name | The name of the authorisation group. | Yes |
| Description | A description of the authorisation group. | No |
| Type | The type of authorisation group (see the explanation below). | Yes |
| Code | The code of the authorisation group. | Yes |
- Click Save.
Authorisation group types
| Type | Purpose / Description |
|---|---|
| General | Administration rights and system-wide functions (portal settings, imports, SSO, translations, forms, etc.). Rights from all other types can be included here. |
| Assessor | Rights for assessing participants. |
| Trainer | Rights for trainers/instructors: participant lists, recording attendance, assessing participants and forms. |
| Owner | Rights for owners of trainings and schedules: managing sessions, registrations, costs and budgets. Only visible when the "Manage owners" right is enabled. |
| HRM | Rights for HR employees with broad access to HRM departments: user management, bulk assigning certificates, approvals and annual planning. Broader than Manager. |
| Supplier | Rights for external training providers: access to the training planner, training definitions, locations, materials and certificate definitions. |
| Managers | Rights for line managers: managing team members, approving/rejecting training requests, assigning certificates, delegating and team dashboards. Own team members only. |
| User | Rights for end users (= User): own profile, catalogue, trainings, certificates and registering for trainings. |
| Observer | Rights for merging data: users, authorisations, certificates, trainings, waiting rooms and CVs. |
| Practice supervisor | Rights for coaches supporting practical assignments: viewing participants, viewing/adding forms and accessing participant profile tabs. |
| Reporter | Rights for reporting: all reporting modules (users, trainings, certificates, Knowledge & Skills, digital content, forms and custom reports). The reporting departments can be configured through the Reports tab. |
| Team leader | Rights for managing projects/teams (= Project leader): My Projects, project details, roles, members, required certificates and Knowledge & Skills, and the project matrix. |
Good to know
-
The type is set when the authorisation group is created and cannot be changed afterwards.
-
Only the User, Managers, HRM, Trainer, Supplier and Reporter types support the Default option (new users are then automatically assigned to that group).
-
You can add rights from other types to an authorisation group — the type mainly determines the default available rights and role-specific functionality.
-
Do not assign too many authorisation groups to one user. Rights from all assigned groups are added together, which can give a user too many rights or conflicting roles unintentionally. This can lead to unexpected behaviour, for example when someone is both a Manager (own team only) and an HRM user (broad access). Keep the setup manageable and assign only the authorisation groups that are actually needed.
Assign rights
- Open the authorisation group.
- View the list of available rights, grouped by category.
- Select the rights that you want to assign to this group.
- Click Save.
The rights are divided into categories such as:
- Management — Access to management settings and configuration.
- Reports — Access to reports and overviews.
- Training — Rights for managing trainings and registrations.
- User — Rights for the user's own profile.
Assign an authorisation group to users
Authorisation groups are assigned through the user profile:
- Open the user profile via Actions > Actions > Search for user.
- Go to the Details tab.
- Click Authorisation group at the bottom of the page.
- Select the required authorisation group.
- Click Save.
Note: Changes to authorisation groups take effect when the user logs in again. Carefully check which rights you assign, especially management and reporting rights.
Two-factor authentication and authorisation groups
When the administrator has enabled the Enforce 2FA setting through the portal settings, it applies to all authorisation groups. When editing an authorisation group, you can see whether 2FA is enforced for users in this group.
Read more about 2FA in Set up two-factor authentication.
Frequently asked questions
Can a user have multiple authorisation groups?
Yes, a user can be linked to multiple authorisation groups. The rights are added together: the user receives all rights from all assigned groups.
What happens if I remove a right from a group?
Users who had that right only through this group lose access to the related feature. Users who also have the right through another group keep access.
Where can I find an overview of all available rights?
A complete overview of all rights and their descriptions is available in the article Rights overview.