User Roles
Assigned user roles define which pages a user can access and for what tasks.
Each user is associated with a login company; by default that company is selected for management when that user logs in. The user can also be assigned access to child companies of the login company through the use of user roles. For example, a user may allowed to manage exemption certificates only for the login company, but have full access to configuring the login company's child companies.
User Administration
Only those who have the user administrator role, such as the ^dba user, can manage users and roles. Users can only manage (set or change) their own passwords as required; they cannot otherwise manage their user or role data or those of any other user.
Although the user administrator role enables you to manage users and roles, it does not allow you to add Configuration parameters that control aspects of user administration policy. To add Configuration parameters, you must also have the role Sabrix System DBA.
Security
Once you have the Sabrix System DBA role, you can add a number of Configuration parameters that govern password security at your implementation.
Password Parameters
On the Configuration page you can:
- Enable password validation, including minimum and maximum length and content requirements.
- Force password changes at set intervals.
Lockout Parameters
With the Sabrix System DBA role, you can also set parameters that control whether or not users are locked out after a certain number of failed login attempts. The lockout feature is turned off by default.
If you want to enable or modify other aspects of the lockout feature, review the following parameters in Configuration:
- LOGIN_MAXIMUM_ATTEMPTS_ENABLED
- LOGIN_MAXIMUM_ATTEMPTS
- LOGIN_MAXIMUM_ATTEMPTS_PERIOD
- LOGIN_LOCKOUT_PERIOD
User Tasks
Use the List Users page to display the list of currently configured users. Tasks include:
- Adding a new user.
- Deleting a user.
- Unlocking a user.
- Exporting a user or users.
- Selecting a user to open his or her Edit Users page.
Use the Edit Users page to displays user details. Tasks include:
- Deleting the current user.
- Adding a new user.
- Exporting a user or users.
- Defining a start and end date for the user.
- Selecting a company to which the user will be associated. This determines the default company that is selected when this user logs on. The Assigning User Roles page determines what Determination pages and companies the user can access.
- Entering or modifying basic contact information for the user, including his or her name, phone number and email address.
- Managing the user's password.
See Assigning User Roles for learn how to list and manage roles for the selected user on the User Roles page.
User roles define what the user has access to within Determination. Tasks include:
- Attaching one or more user roles to a user.
- Detaching a user role from a user.
- Setting start and end dates for a user's roles.
Use the Configuration page to modify password-specific configuration parameters.