Room Groups are used to manage User access and permissions at the Room level. A user cannot belong to different groups, he can only be a member of one group at a time but can be changed to a different group when needed.
Each Room, upon creation, inherits all Global groups and Environment groups from the environment the room belongs to.
The newly created room will also have specific room groups: Default, Shared Documents, Power User and Room Admin.
Generally, all users invited to the room are assigned to Default group, but this can be modified on "Invite Users Wizard" or later by changing the user's group.
When sharing documents, if users weren't previously added to the room and assigned to a different group, they will be automatically assigned to Shared Documents group. This can also be changed at a later time.
Who can create Room Groups?
Admins or Users having "Manage Users And Permissions" permission are able to create, edit and delete a room group. Power Users won't see this option unless they are Room Creators.
The Room Groups Management page can be reached from My Rooms page, by right clicking the room name and choosing "Groups & Folder Permissions" option (this is for Admins only). From within the Room, by clicking the Manage header button and choosing the "Groups & Folder Permissions" option.
Room Groups screen looks like the one below.
Each Group is formed by Group Users, Room Permissions and Folder Permissions. Next to the group name, a badge shows the number of Room Users assigned to this group.
Room Permissions grant or deny access to various Room features for that Group. Room Permissions are not specific to any folder or document, though some of them work in conjunction with Folder Permissions discussed further below.
Default: it's a System group identified by a pink globe icon with an "S". Cannot be deleted or renamed. Room Permissions and Folder Permissions can be changed.
Shared Documents: it's a System group identified by a pink globe icon with an "S". Cannot be deleted or renamed. Room Permissions can be changed. Folder Permissions are all disabled and unchecked by default and cannot be edited.
Power User: it's a System group identified by a pink globe icon with an "S". Cannot be deleted or renamed. Room Permissions can't be changed, they are all disabled and checked except "Manage Users And Permissions". Folder Permissions are all disabled and checked by default and cannot be edited.
Users belonging to this group, are pretty similar to Room Admins but cannot perform the following actions (unless they're Room Creator):
- Room Settings & Watermarks
- Room Users
- Room Groups and Permissions
- Save Room As Template
Room Admin: it's a System group identified by a pink globe icon with an "S". Cannot be deleted or renamed. Room Permissions can't be changed, they are all disabled and checked by default. Folder Permissions are all disabled and checked by default and cannot be edited.
Global Group: a green globe icon with a "G" identifies a Global group. It cannot be deleted at room level and Room Permissions cannot be edited either. Folder Permissions can be edited at room level.
Environment Group: a green globe icon with an "E" identifies an Environment group. It cannot be deleted at room level and Room Permissions cannot be edited either. Folder Permissions can be edited at room level.
Room Group: can be created by clicking on icon. Room Permissions and Folder Permissions can be edited and it can only be deleted if no users are assigned.
Another way of creating a group is by right clicking the group's name and selecting the "Copy Group" option. A window is opened to enter the Group Name. The new group is created with no Users but with the same Room and Folder Permissions as its source.
All groups can be copied except Power User and Room Admin.
This tab will display all users belonging to the selected group. Several actions can be performed by selecting the appropriate option under User Actions menu:
- Invite New Users
- Resend User Invitations
- Remove Selected Users From Room
- Change User Company
- Change User Group
- Change Expiration Date: Not enabled for Room Admins
- Change User Approver Status: Only shown when room requires 2nd Level Approval. Not enabled for Room Admins.
- Send an Email to Users
For more information on each user action, refer to Room Users Administration article.
Room Permissions grant or deny access to various Room features for that Group.
- Access Room Dashboard: group members can access the room's Dashboard. If the environment the room belongs to, does not Show Dashboard, this permission will be disabled.
- Manage Custom Fields: group members can add, delete and edit Custom Fields.
- Manage Personal Tags: group members can add, delete and edit Personal Tags.
- Manage Room Expedite Rules: group members can Manage (create, edit and delete) Expedite Rules on the room.
- Manage Room Work Lists: group members can Manage (create, edit and delete) Lists, List Fields and Pick List Field Choices.
- Manage Tags: group members can add, delete and edit Room Tags.
- Manage Users And Permissions: group members can Manage Room Users and Groups and Folder permissions.
- Notes: group members can see, search, create and edit Document Notes. Users can edit only Document Notes that they create.
- Request Documents: group members can create Document Requests and manage Requests they have created.
- See Activity Report: group members can access the Room's Activity Report.
- See Custom Fields: group members can room's Custom Fields in File Information and Advanced Search panels.
- See Room Work Lists: group members can see the room's lists and download all list items attachments.
- See Uploaded By Information for Documents: group members can see Uploaded By field on Documents grid and File Information panel.
- See Versions: group members can see previous versions and upload new versions of documents on folders where they have Manage Permission.
- Share Documents: group members can share documents with other users.
- Tag and Code Documents: group members can see the Coding Panel section on Document Details panel, Tag and Code documents and Search by Tags and/or Codes.
Room Permissions are not specific to any folder or document, though some of them work in conjunction with Folder Permissions discussed further below.
Room Folders are used to organize documents within a Room and provide the ability to allow or deny access to Group members. Additionally, Group members can be allowed or denied the following abilities on a folder level:
- Manage: allows group members full ability to upload, rename and delete folder and documents within the folder. Also allows other folders and documents to be copied or moved to this folder. Granting this permission will automatically grant all other folder permissions (except will deny ability to watermark the folder for this Group).
- Folder: allows group members to see the folder. This permission must be granted in order to grant any other folder permissions or to see folders contained within this folder.
- Documents: allows group members to see the documents contained in this folder. This permission must be granted in order to provide the ability to download documents.
- Download Native: allows group members to download the documents in the folder in their original format
- Download PDF: allows group members to download PDF renderings of the documents
- Watermarked: designates folder content to be watermarked for Group members. This setting will also prevent the "Download Native" option from being selected.
When the room has Apply Watermarks to All Folders setting on, note that Download Native and Watermarked columns are hidden
Inherited Folder Permissions
Folder Permissions provide the ability to manage folders flows downwards, while folder access flows upwards. This means that if a Group is granted the ability to Manage a folder, it is automatically, and required, to have Manage permission on all folders contained within that folder, and all their sub folders.
In the example below, a User Group is granted the ability to Manage Folder A. Once that permission is granted, the User Group will automatically have the ability to Manage Folder A1 and A2:
You will also see that in order for the User Group to have Manage permission to Folder A, it must also be given See Folder access to the top level folder "Folder Permissions Example" that contains Folder A.
Alternatively, in the following example, a User Group has permissions to the documents in Folder A2. If the "See Folder" permission is removed from A2's parent folder, Folder A, the Group will lose all permissions to Folder A1:
Refresh Logged-in Users' Permissions
This button will be enabled when any of the following changes occur:
- Change User Group
- Changes in Folder Permissions
When clicked, Folders and Documents panels are automatically refreshed for all users currently logged-in.
Some sections of the page are not automatically updated and require the user to manually refresh in order to show/hide the permissions and options currently available:
- Navigation bar
- Advanced Search
- Tools dropdown menu
- Document Details panel