Centralized User Role Management with Tenant-Level Permissions
IGCM supports tenant level permissions for easier role management across multiple enterprises. Users can configure permissions at the tenant level and use it across different enterprises. Previously, all permissions, including permission groups, permission levels, roles, and user roles, were managed at the enterprise level only and separate permissions had to be created for each enterprise within a tenant.
With this enhancement, if a user has access to three enterprises, a role can be created at the tenant level and assigned to the user in all three enterprises instead of creating the role thrice (once in each enterprise).
Example Scenario:
Consider a tenant that already has three enterprises. Since these enterprises were created before this functionality was introduced, they will continue to use enterprise-level permissions. Roles for these enterprises must be managed individually.
If two additional enterprises are added to the same tenant after the introduction of this functionality, users will have the option to enable tenant-level permissions during the setup of these new enterprises. Once enabled, permissions for these enterprises can be managed centrally at the tenant level. This setting is permanent and cannot be changed after the enterprise is created.
This functionality is not applicable for existing enterprises. For new enterprises, the functionality will be disabled by default and can be enabled during creation. Once enabled, it cannot be modified.
To support this, the Use Tenant Permissions checkbox in the Basic Details submenu of the Enterprise menu must be enabled.
-
When enabled, the enterprise will only use Tenant Level Permissions. Users accessing this enterprise will be assigned to Global (Tenant) user roles, regardless of which enterprise they are logged into.
-
The following new menus will replace the usual enterprise-level permission menus:
-
Tenant Permission Group
-
Tenant Permission Level
-
Tenant User Role
-
Tenant Role
-
-
These menus help manage permissions centrally for all enterprises under the tenant.
-
When disabled, the enterprise will continue to use the enterprise-level permissions.
A new system default permission group, System POS All Permission, has been introduced and automatically assigned to the default user role of POS Administrator. This permission group cannot be modified or deleted.