To grant a user individual permissions for selected records or categories:
1. Right-click on a record or category and select Properties from the shortcut menu. The Properties window appears.
2. Click the Permissions tab. Users/roles that have already individual permissions are initially displayed in the users list.
Now, you can either grant individual permissions to selected users or roles one by one, or you can employ a Permissions Template.
Granting Permissions One by One
To grant individual permissions to selected users or roles:
1. If the desired user is not already shown, click Add Users. The Add User window is displayed.
2. Search for respective users. Click OK to add them to the list in the Permissions section. OR If the desired role is not already shown, click Add Role and select a role to add it to the list in the Permissions section.
3. Select a user or role from that list and activate the permissions you want to assign, or deactivate previously granted individual permissions to revoke them.
4. Click Apply to save your changes and continue to assign individual permissions to further users. OR Click OK to save all changes and close the Properties window.
Granting Permissions Employing Templates
To employ a Permissions Template:
1. Click Use Template and select the template you want to use.
2. Click Apply to save your changes and continue to assign individual permissions to further users. OR Click OK to save all changes and close the Properties window.
NOTE: With Permission Templates, both the permissions to be granted and the respective users are specified in the template itself. You can not assign a Permissions Template to a user selected from the user list on the Permissions tab. For more information on Permissions Templates, see “Overview: Permissions Templates” .)
SPECIAL TECH INFO: Configuring Authenticators’ User Search Criteria
With the Cumulus Built-in authenticator you can search for the login names as well as for first, middle or last names. With LDAP authenticators, a search for login names is performed by default. The default search criteria for the LDAP authenticator can be changed in the LDAP.xml file (located in the conf folder inside the Cumulus Server installation folder.)
Additional Information on Category Permissions
• Categories Representing Catalogs The Properties Window for a category representing a catalog (a “root” category) does not provide a Permissions tab. Because such a category is on the highest hierarchical category level, only child permissions can be defined for it. (For details on child permissions, see “For Subcategories” .)
• Moving Categories To move a category, the user needs the permission Modify Category for the category to be moved and the permission Create Category for the ‘absorbing’ category (the category which will house the moved category). A moved category maintains its permissions.