Features Pricing Docs Contact Sign In Get Started
Language

Roles and permissions

How a role is created, what each column of the permission grid grants, and the changes CommonLynk refuses so that you cannot lock your own workspace out.

A role is a named set of permissions, and it is the only thing that decides what a person can reach in your workspace. You manage roles from Settings, then Roles.

How permissions work

The list shows each role's name, its description, how many people hold it, whether it is active, and a link to edit its permissions. An Add role button sits at the top.

CommonLynk is deny by default. Nothing is granted until a box is ticked. Someone with no role, or whose role grants nothing for a module, is refused: if they are signed in they see a refusal page, and if they are not they are sent to the sign in page. Belonging to the workspace is never itself a permission.

Creating a role

Creating a role takes two steps rather than one.

  1. Give the role a name in each of your workspace's languages, add a description, and save.
  2. The role is created holding no permissions at all, and you are taken straight to its permission grid to grant them.

So a newly saved role is harmless until you tick something. If you leave the grid without granting anything, the role exists and gives nobody any access at all.

The permission grid

The grid puts the modules in rows and four columns across them, with a select all toggle on each row.

Column What ticking it allows
View Opening the module and reading its records, including downloading whatever it lets you export.
Add Creating a new record in that module, and attaching a file to one.
Edit Changing a record that already exists.
Delete Removing a record, and removing a file somebody else attached.

The modules are Registrations, Programs, Projects, Activities, Attendance, Reports, User Management, Roles and Permissions, Settings, Forms Builder, Form Data Review, Indicators and Backups.

The Backups row carries three extra boxes of its own:

  • Download, which allows a copy of everything to be taken away.
  • Manage settings, which allows the schedule and the destination to be changed.
  • Restore, which allows a copy to be written back.
There is no Export column, and people do look for one. The ability to download a file follows from the module's own view permission rather than from a separate box.

Saving rewrites the whole grid, so clearing a box takes that permission away as surely as ticking one grants it.

Screenshot: the permission grid for a role, with the Backups row and its three extra boxes.

Switching a role off

An inactive role grants nothing at all. Not reduced access, not view only: switching a role inactive removes every permission it carried, for every module, at once, until you switch it back. That is worth knowing before you use it as a temporary measure while a colleague is away.

Giving someone a role

A role is chosen when you add someone, and it can be changed later. A role is optional, so a person can exist with none: they can sign in and reach their own profile, and are refused everywhere else.

The changes CommonLynk refuses

CommonLynk refuses a save that would leave your workspace unable to administer itself. It refuses to take User Management and Roles away from the last role that holds both, to take Settings away from the last role that holds it, and to strip or deactivate the owner's role.

Each refusal is itself written to the activity log, so an attempt is visible afterwards.

User Management and Roles are two separate permissions. Being able to add people does not let you change what a role may do.