User Tools

Site Tools


en:diary:userpermissions

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
en:diary:userpermissions [2024/10/07 14:25] Lada Svobodováen:diary:userpermissions [2026/09/07 15:11] (current) Milan
Line 1: Line 1:
-====== Users permissions ======+====== User Permissions ======
  
-The Buildary user permission system is designed to allow very straightforward work on smaller projects with a few members project team. At the same time, it is flexible enough to meet the demands of large corporate customers and project teams of the largest construction sites.+{{youtube>akZLFxBlluo}} 
 +\\ 
 +The user permission system in **Buildary.online (hereinafter referred to as "Buildary")** is designed to allow straightforward work on smaller projects with small project teams. At the same time, it is flexible enough to meet the requirements of large corporate customers and project teams, even on the largest construction projects.
  
-The Buildary user permission system can be viewed as three-level system.+The user permission system in Buildary can be viewed as having three levels.
  
-** The first level of permissions is at the domain level ** and controls if the user can create new projects and diaries in that domain. The user'permissions are set by the domain administrator. For users working in their personal domain, this level is irrelevantbecausein the personal domain, the user always has all the permissions.+**The first level of permissions is at the domain level** and determines whether a user can administer the domain, create and manage new projects and diaries within that domain. These permissions are assigned to users by the domain administrator. 
 +For users working in their personal domain, this level is irrelevant because they always have full permissions in their personal domain.
  
-** The second level of permissions is at the project level ** where company roles and member roles, as well as their permissions on the project site, can be defined for the entire project team.+**The second level of permissions is at the project level**where company roles and member roles and their permissions for the project can be defined for the entire project team.
  
 +**The third level is the Project Diary and its records.** For each Project Diary, authorized persons from the project team and their roles are defined. Users' permissions within the diary are determined by these roles. The Authorized Persons section of the diary contains predefined roles from the project team, but the role can be changed at the diary level, allowing an authorized person to have a different role in each diary if required. This is the level that every diary administrator must understand and use correctly.
  
-** The third level is the construction diary and its entries**. For each construction diary, authorised persons and their roles are listed. The role defines the user's permissions in the diary. This is a level that every diary administrator needs to understand and use properly. 
  
 +===== Domain Users =====
  
-====== Domain users ======+Users who only work on projects to which they have been invited, as well as users who only work in their personal domain, do not need to manage domain permissions.
  
-On the other hand, it is very important for a company domain administrator to correctly understand and set domain-level permissions +For a corporate domain administrator, however, it is important to correctly understand and configure permissions at the domain level. The domain user list should contain only employees of the company, not external usersExternal users are added as **Project Team Members** on specific projects.
-Only the employees of your company are added to the domain user list +
-The external users are added only as project team members of a specific project. Not to the domain user list.+
  
-{{:en:diary:domain_users_list.png?600|}}+The following permission areas can be assigned to domain users:
  
-**Domain users can be granted the following permissions:**+  * **Domain Administration** – allows the user to edit domain information and settings, add domain users including configuring their permissions, and delete the domain. It also allows the user to view all projects in the domain, but does not grant permission to edit them. The domain administrator can create **Template Projects** and modify their settings, including the default code lists.
  
-**Domain Administration** - This permission allows the user to edit domain settings, insert domain users including their permission settings, delete the domain.+  * **Project Creation** – allows the user to create new projects within the domain.
  
-**Create New Project** - This permission allows the user to create new projects in a given domain.+  * **Project Management** – allows the user, on projects where they are a project team member, to edit project information, add companies and Project Team Members to the project, and create new Project Diaries.
  
-**Administrate Project** - This permission allows the user to edit project information, insert new companies, and team members to the projectcreate new project diaries but always only on the projects where he is a team member.+  * **Administrator of All Projects and Diaries in the Domain** – allows the user to manage all projects in the domainregardless of who created them. This includes adding organizations and team members, modifying role code lists, creating and configuring diaries, and editing the cover sheet and Authorized Persons in the Identification Details. Assigning this role gives the user read-only access to Daily Records. This role does not grant permission to enter Daily Records or add Basic Documents, Project Documentation, Inspections and Tests, or other documents.
  
-**All Projects Administration** - This role allows for the configuration of all projects within the domain (regardless of who created them)such as adding organizations, team members, modifying role dictionaries, as well as creating and configuring diariesediting cover pages, and managing authorized persons from identification details. Assigning this role grants the user read-only access to the daily records. This role does not grant the ability to make daily entries or add supplementary documents, such as basic documentsproject documents, inspections, and other paperwork.+  * **Reader of All Projects** – allows access to all diaries in the domain without the ability to make any changes to them
 +  
 +When a domain is createdits creator is automatically added to the domain users as an administrator. In addition, the user who created the domain and thereby became its owner has the same permissions as the domain administrator by virtue of being the owner. Thereforedeleting the domain user or changing their permissions cannot restrict the domain owner's permissions.
  
-- **All Projects Reader** -Allows access to all diaries within the domain, without the ability to make any modifications.+After a user is added to domain, an invitation is sent to their email address asking them to create an account. The user account and the user in the domain are linked based on the email address, regardless of which one was created first.
  
  
  
-The user is automatically written to domain users as an administrator after he/she creates the domain. In addition, he/she becomes the owner of the domain which grants him/her the same permission as a domain administrator. Therefore, deleting user from domain user list or changing his/her domain permissions can not restrict the domain owner in his/her permissions.+\\  
 +===== Project Users ===== 
 + 
 +If you have created a project and want to give other users access to it, you must first add them as **Project Team Members**. This is done in the project settings under **Project Team**. 
 + 
 +After a user is added as a project team member, an invitation is sent to their email address. 
 + 
 +Adding a user as a project team member gives them access to the project, but does not by itself grant them any permissions to work with the Project Diary. These must be defined by selecting the appropriate role based on the user's actual role on the project when adding or editing the project team member. The roles assigned to project members determine what permissions the user has in the Project Diary. 
 + 
 + 
 + ==== Authorized Persons in the Diary ==== 
 + 
 + 
 +**Permission Area - Project Diary:** 
 + 
 +  * **Diary Administration** – allows the user to edit the diary's Identification Details, add Authorized Persons, and delete the diary (only if it does not contain signed and locked Daily Reports). It also allows the user to perform all diary configurations available under **Diary Settings**. 
 + 
 +  * **Regular Entries** – allows the user to add, edit, and delete records in the Weather, Persons, Machinery, Materials, and Performed Works sections. However, only their own records can be edited or deleted, and only until the day is locked. 
 + 
 +  * **Other Entries** – allows the user to add, edit, and delete records in the Additional Records section. However, only their own records can be edited or deleted, and only until the record is locked. 
 + 
 +  * **Project Documents** – allows the user to add, edit, and delete records in the Documents section of the Project Diary's Identification Details, i.e. Basic Documents, Project Documentation, Inspections and Tests, and Other Documents. 
 + 
 +When a diary is created, its creator is automatically added to the Authorized Persons as an administrator. In addition, the user who created the diary and thereby became its owner has the same permissions as the diary administrator by virtue of being the owner. Therefore, deleting the user or changing their role cannot restrict the diary owner's permissions. 
 + 
 +**Permission Area - Project:** 
 + 
 +  * **Project Administration** – allows the user to expand the project's project team and modify project settings, including code lists and drawings for the Project Diary. Some permissions within this area can be assigned separately through sub-areas: 
 +    * **Project Team Administration** – allows the user to add a new project team member, create a new company on the project, and add an Authorized Person to the Project Diary. 
 +    * **Project Completion** – allows the user to close the project. 
 +    * **New Diary by Copy** – allows the user to create a new diary by copying an existing diary. 
 + 
 + 
 + 
 +\\  
 +===== Diary Users ===== 
 + 
 +If a user is to have access to a diary, they must be added to the diary's list of **Authorized Persons**. This is done in the diary's **Identification Details**. The user is also assigned a role inherited from **Project Team Members**, which can be changed as needed for each diary. Their permissions to work in the diary are then determined by this role. 
 + 
 + 
 +<WRAP info> 
 +If a user is listed as an Authorized Person in a diary, they have access to the entire Project Diary for viewing, regardless of their role. This right is established by law, and the Buildary system respects it. 
 +</WRAP>
  
en/diary/userpermissions.1728303948.txt.gz · Last modified: 2024/10/07 14:25 by Lada Svobodová

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki