Creating and Managing User Groups

Last updated About 1 month ago

User group

This article describes how an Admin user can create and manage user groups. Additionally, it includes references to other valuable resources for efficient access management within the BI Book platform.

Create User Group

User group - Access to BI Book content can now be managed through user groups. You can assign a user group to BI Book content, and all members of that group will get the permission level defined by the User Group on the content.

  • (1) Admin users can create and manage User Groups by navigating to BI Book Company portal → Management → Groups → pressing “Add new group” button:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdGtDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--e325652ca76bc6a058bfa3813da8e30558dfae86/10.jpg
  • (2) Fill in “Group name” field (better to have a descriptive name that would reflect the purpose of the group) → Select user(s) that should belong to this User Group → Check or leave unchecked “Sensitive info included” * → press “Create”

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdG9DIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--124df988cd5c664052553c547c2ec2ca62456545/11.png

💡*Sensitive info included - the purpose of this setting is to mark a User Group that has privilege to access sensitive data, for example, payroll reporting, etc. Once checked, you will quickly see which user groups need extra care when adding users. This helps you avoid accidentally giving access to sensitive data through these groups.

Example of enabled "Sensitive info included" setting:

🟢In User group list view:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdHNDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--783eb79f67ed7b35f2bb8bb5c07b2129f0b298f4/12.png

🟢In User Group view:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdHdDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--3a74fbe46e168ca5abe481406c21dc2d7e44f90d/13.png
  • (3) Click on the user group name or the edit icon to configure the permissions (⚠️please check "Permissions for BI Book Content Objects" section at help.bibook.com/en/articles/bi-book-access-management for better understanding how the permissions work for different BI Book content objects) for the user group:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdDBDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--f5a4ea5a5300338dfebeb2e22a23ce048530d50c/14.png
  • (4) Remember to press “Save permissions” before navigating to the “Members” tab or “Show entities tree”:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdDRDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--2a91773db8025770cbbc031e8e52712d3e8eb6f5/15.png
  • (5) You can add more users to the user group by navigating to the “Members” tab → Add user:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdDhDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--8da0971d41978ea5213ee324437c29b15c5e145a/16.png
  • (6) Alternatively, you can add a user to the user group from Management → Groups → User Groups list view “+” icon next to the number of users:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdUFDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--e8b4dcb102a46a6f7b1d235a1ccf2d02fb03855b/17.png

💡User can belong to more than 1 User Group. In this case if there are overlapping permission to the same Content object, the higher permissions prevail.

Example Scenario - User belongs to 2 different User Groups:

🟢User Groups:

- User Group A: Read permission to Report C

- User Group B: Full access to Report C

🟢Outcome:

If a user belongs to both User Group A and User Group B, the user will have full access to Report C due to the higher permission level from User Group B.

  • (7) To learn how to grant a user group access to a BI Book Content object, please refer to the following resource: help.bibook.com/en/articles/granting-access-to-the-content-objects

  • (8) You can check what content objects a user group has access to from user group settings:

    a. Management → Groups → edit <user-group-name> → “Show entities tree” button:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdUVDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--a5a89369863eb36bb5da7a80efa8d12051a0f8fc/18.png

b. You can remove user group’s access to a content object from entities tree view by clicking on the delete icon:

/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdUlDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--bc2a076f65ed4ed7efc7769d0c00ea9d8547404e/19.png

Related articles