Understanding object permissions
Who is this article for?
All Users needing to understand object permissions
Overview - View Only
By default, all users should be able to see / view only all objects created within your Healthcare Guardian application; unless these have been changed on a object-by-object basis. Objects are usually created to underpinning a questionnaire record / instance (i.e. LFPSE Incident, Policy, Feedback etc.). However permissions can be updated on creation through triggers that can be set up in the Questionnaire Template.
Once default permissions are amended, only Model Administrator and the Object Owner will always have full permissions on the objects which cannot be changed.
Overview - Value Entry and View Only
By default, only the Object Owner and users with a Model Administrator standard role (licence) can add performance assessments (values) to performance metrics created within your Healthcare Guardian application; unless these have been changed on a Object : Measure (O:M) basis. Please note that if permissions to allow value entry (sometimes called "data entry) are set at measure level, those permissions will also need to reflected at the object level too.
However, this is permission grouping is typically no longer in the Healthcare Guardian application, unless customers have the "Oversight" (Sometime called "Performance") module, please see below, or continue to use Object : Measure (O:M) reporting.
Please be aware that users with these permissions will be able to add view the object (or the measures they have specifically been given permission to value entry against).
Overview - Edit, Value Entry and View Only
In respect of edit rights [of a object] (rather the value entry or viewing), the default setting is that users can only perform this on objects are the Object Owner, or a Model Administrator standard role (licence) holder, unless these have been changed on a object-by-object basis. Permissions can be updated on at any time through the workflow and/or triggers that can be set up in the Questionnaire Template. Please see example below.
Please refer to guidance around triggers in Question Manager for further information on this. If users wish to edit the associated questionnaire record / instance they must have edit permissions set in the underpinning object.
Please be aware that users with these permissions will be able to add performance assessments (values) if applicable, and view the questionnaire record / instance.
Overview - Authoring, Edit, Value Entry and View Only
The main advantage an object author has over a object editor, is the ability to delete the object.
This should not be done unless you are 100% sure this is what is required as their no recovery functionality available.
By default, only the Object Owner and users with a Model Administrator standard role (licence) can author objects within your Healthcare Guardian application; unless these have been changed on a object-by object basis.
Please be aware that users with these permissions will be able to add edit, update performance assessments (values) and view the object(s) questionnaire record / instance. However permissions can be updated on at any time through the workflow and/or triggers that can be set up in the Questionnaire Template. Please see example below.
Please refer to guidance around triggers in Question Manager for further information on this.
1. Author, Edit, Value Entry & View Only
Any user (or groups of users) in the Author, Edit, Value Entry & View Only have full authoring permissions on the object, or questionnaire record / instance.
2. Edit, Value Entry & View Only
Any user (or groups of users) in the Edit, Value Entry & View Only have full editing permissions on the object, or questionnaire record / instance.
However, if users are able to edit the object, or questionnaire record / instance, they are able to:
- All questions on the questionnaire
- Update / amend the object name
- Set the priority and stage
- Update / amend the start date, due date or end date
- Update / amend owner
- Update / amend the object description
- Update / amend the org unit, coordinates, org unit and requestor
... and any object custom fields
It is important ant NOT to update any of these if they are being populated through a questionnaire workflow or trigger ands should be updated via the questionnaire record / instance only.