Skip to content
English
  • There are no suggestions because the search field is empty.

Custom User Roles for Data Access

A custom user role decides which features people can use. To go further and decide which records they can see, combine the role with user groups and labels. Each group is allowed a set of labels, and the role's data access is set to Controlled by Label, so members see only the records that carry one of their group's labels.

This article builds on the Basic User role from Custom User Roles for Feature Access. We'll create two groups, GRC Users and Risk Users, give each a label, and limit Basic Users to the controls labeled for their group.

Before you begin

  • You must be an Admin to manage user groups and roles.
  • Create the labels you want to use first. This example uses GRC Team and Risk Team.

Step 1: Create the user groups

Open Users and select the User Groups tab. A user group gives a set of users access to the same labeled records.01-user-groups-tab-empty

Click Add User Group. Enter a Name (here, GRC Users) and an optional Description, then choose the Members. In this example, John Doe is added to GRC Users.02-create-grc-users-group

Under Labels, click Select Label and choose the label this group can access. For GRC Users, choose GRC Team.03-select-access-label

Leave Access set to Allow. You can also choose Deny to keep the group away from records with that label. Click + Add Label if the group needs more than one.04-label-access-allow-deny

Hover the info icon next to Labels for a reminder of how this works: an allow label lets the group act on records carrying it, and a deny label blocks them even when another of the group's labels allows them. Click Submit to create the group.05-labels-tooltip

Repeat for Risk Users: add Jane Doe as a member and allow the Risk Team label.06-create-risk-users-group

Both groups now appear on the User Groups tab, along with their labels.07-user-groups-list

On the Users tab, the Groups column shows each person's groups: Jane Doe is in Risk Users and John Doe is in GRC Users. Both are assigned the Basic User role.08-users-groups-column

Step 2: Set the role's Controls access to Controlled by Label

Open User Roles, click Basic User, and expand Controls. By default, Control Record Visibility is set to Allow, so members see every control.09-controls-visibility-default

Select Controlled by Label. The change saves right away, and the Controls row shows an override. Members of this role now see only the controls that carry a label one of their groups allows.10-controls-controlled-by-label

Step 3: Label your controls

Go to Controls. The Labels column shows how many labels each control has. In this example, AU01 already carries Risk Team and BC01 carries GRC Team, while AU02 and BC03 have no labels yet.11-controls-list-before

Open a control and click Labels in its header. Select the label and click Update. Here, AU02 gets Risk Team. Repeat for BC03 with GRC Team.12-au02-add-risk-team-label

All four controls now carry a label. As an Admin, you still see every control.13-controls-list-labeled

Step 4: Preview what each group sees

Return to the Basic User role and click Preview. Under User Groups, select Risk Users, then click Preview.14-preview-select-risk-users

In the preview tab, open Controls. With Risk Users applied, only AU01 and AU02, the Risk Team controls, are listed. This is what Jane Doe sees. The banner at the top shows the role and group being previewed.15-preview-risk-users-controls

Click Exit Preview, then start a new preview with GRC Users selected.16-preview-select-grc-users

Now only BC01 and BC03 are listed. This is what John Doe sees. Someone in both groups would see the controls allowed by either group.17-preview-grc-users-controls