Roles Overview
Roles are the functional groupings of permissions to create an operational function for users of the SafeZone system. There are two types of role:
System Roles
System Roles are pre-configured system defined roles for common use cases for example a Notification Administrator would have permission to perform all functions around Mass Comms from Creating Templates to sending Ad hoc customized communications.
System Roles apply globally to a permission, in so much as they cannot be limited by variables scopes such as Item Categories / Types, User Scopes, etc.
A system role would not for example be used to grant a user the ability to send Notifications to a specific group of people, that would be done by Custom Roles.
System Roles are summarized at the bottom of the page (here)
Custom Roles
Custom Roles, as implied by their name, grant organizations more flexibility in the permissions structure. They allow specific scopes to be included in the general permissions, so that a user may be allowed to send notification templates, however only to specific types of message to defined groups.
Example:
A custom role could be setup to allow the sending of notifications which are in the Travel Comms category, to users who are in a Travel user group.
Navigating the Roles Screen
The Roles Screen allows you to easily view, search and filter your list of roles in addition to creating new and editing existing Custom Roles.
Search roles field: Allows you to type in the name of a role and filter the list
Custom roles / System roles buttons: Allow you to filter the list and show only custom or system roles as required
Create New Role button: Used to create new Custom Roles (see below for more information)
Roles Information: You can view information on a role by clicking its name from the list
Creating a Custom Role
The most common action in the Roles screen is the creation of Custom Roles as System Roles cannot be edited. To create a custom role:
- Go to Admin - Access Control - Roles
- Click "Create New Role"
- Give the Role a Unique name when prompted and press "Save"
- You will then see the information page for the role which can be setup as required (see below for more information)
Setting up permissions in a Custom Role
Custom roles can be setup as soon as they are created and also edited later as required. The process is the same whether doing a first setup or editing.
- Go to the role information page by either
- Creating the role with the steps above, or;
- Going to Admin - Access Control - Roles and clicking on the role you would like to setup
- Click on View / Edit Permissions at the bottom of the page
- You will then see the permissions screen for that role with items grouped by category
- Select the section you would like to setup permissions, in this example I want a role for viewing Mental Health tips only and so will select "Tip Reporting"
- A summary of what is already setup will be displayed. To make changes, click "Edit" and then use the switch to turn on the permission and customize its scope
- For the Mental Health Tip manager I can allow people with the role to View, Resolve and Reopen tips and then limit that permission by the scope of "Mental Health" tips as shown below.
- Turning on a permission shows the available scope limitations. For tip reporting this can be the type of tip and region group the tip was raised.
- Once complete, click "Save" to confirm or "Cancel" to return to the role's information page without saving.
Note: Roles can stack together so you don't need to put all permissions for an individual in a specific role.
- If the user is a SafeZone user they will already be able to raise tips and so that permission does not need to be selected for a custom role
- You can also link multiple custom roles together in a Security Group which can be applied to a number of users with the same access rights and scopes.
Editing the Role's Name
If you want to change the name of a role, jus select it by:
- Going to Admin - Access Control - Roles and clicking on the role you would like to edit
- Click "Edit Name"
- Enter a new unique Name
- Click "Save" to confirm or "Cancel" if you change your mind
Deleting a Role
If you want to delete a role:
- Go to Admin - Access Control - Roles and clicking on the role you would like to delete
- Click the Delete Role button
- You will see a pop-up confirmation message asking you to check whether users or groups are assigned this role.
- Click "Delete" to confirm or "Cancel" to go back
Summary of System Roles
Custom roles can be created at any time, however the system comes with a number of roles pre-packaged and are summarized below:
NOTE: The system roles do not have any limiting scopes (e.g. View User records but only from specific groups; Send templates but only from specific categories; View Check-ins but only from your team).
These can be created as Custom Roles
Role Name | Description | Application(s) effected |
Acknowledge Alerts | Can Acknowledge Alerts raised from the SafeZone App or Drag dispatch | OmniGuard and Command |
Alert Administrator | Can Drag Dispatch Alerts from the Command screen | Command |
Alert History | Can view alerts which have been resolved | OmniGuard and Command |
Asset Administrator | Can view heatmaps from OmniGuard responders | Command |
Asset History | Can run Asset History Playback from the History page | OmniGuard and Command |
Check-in Administrator | Can view heatmaps from SafeZone Check-ins | Command |
Check-in History | Can run check-in history reports from the History page | OmniGuard and Command |
Message Administrator | Can manage responder chats and create chat sessions | SafeZone, Command and OmniGuard |
Message History | Can see historical chats (required for Responder and Wellbeing Chats) | SafeZone, Command and OmniGuard |
Notification Administrator | Can create and fully Manage Notification Templates (Edit, Enable, Disable, Delete) | Command |
Raise Alerts | Can raise alerts in the system. Recommended for all users | SafeZone, Command and OmniGuard |
Raise Check-Ins |
Allows users to use the Check-in function Recommended for all users |
SafeZone |
Resolve Alerts | Can resolve alerts raised in the SafeZone system | OmniGuard and Command |
Restore Alerts | Can restore recently closed alerts from the Alert History | OmniGuard and Command |
SafeZone Administrator | Full system administration super-user access. | OmniGuard and Command |
Send adhoc messages and templates | Can send Custom messages from the Notify screen or geotargeted messages to check-ins and/or responders through the live screen (Map capture or clicking on a specific user) | Command |
Send templates only | Can only send templated notifications | Command |
View alerts | Can view alerts raised in the system (but not acknowledge, or resolve them) | OmniGuard and Command |
View assets | Can view live locations of OmniGuard responders or SafeTrans vehicles | OmniGuard and Command |
View check-ins | Can view live check-ins of SafeZone app users | OmniGuard and Command |
View notification history | Can review notifications which have been sent from SafeZone Command through the History page | Command |
View user records | Can view and search through User Records | OmniGuard and Command |
Comments
0 comments
Article is closed for comments.