Course contents3 lessons
Course overview
  1. What is an Identity Template
  2. How to Apply and Manage Identity Templates
  3. 03How to Manage User Rights

Lesson 3 of 3

How to Manage User Rights

Manage an individual Hub user's workspace, application, and data permissions with explicit rules, then apply or revise those rights immediately.

2 min read

Control what an individual user can do inside a SpreadsheetWeb Hub workspace. Rights are divided into workspace, application, and data categories so access can be granted or restricted at the level required by the user's responsibilities.

Open the user's permissions

  1. Go to User List in the workspace.
  2. Find the user whose access needs to change.
  3. Select Edit.

The edit page displays the selected user and the rules currently assigned to the account.

Understand the permission categories

  • Workspace rights control workspace-level capabilities and administration.
  • Application rights control which applications the user can access or manage.
  • Data rights control the actions the user can take on saved application records.

Keeping these categories separate allows a user to perform one task without automatically receiving unrelated access. For example, a user can be allowed to save new records while remaining unable to browse existing saved data.

Add and review rules

Select Add Rule in the appropriate category and choose the permission to assign. Add all rules needed for the user's role, then review the complete combination for unintended access.

Prefer the smallest set of rights that supports the person's work. Pay particular attention to rules that apply to all applications or all application data because they affect a broader scope than application- or tag-specific rules.

Apply or revise the rights

Select Update User when the rule set is complete. The user's permissions are updated immediately.

To change access later, return to User List, edit the same user, and add or remove rules. Test a representative account after major permission changes to confirm that the intended applications and data actions are available while restricted areas remain inaccessible.