A User's role is defined when the User is setup.  The default role is Application User.  Roles can be changed on the Assign User Permissions/User Profile Tab.  Feature Access, and Admin Menu Access is also managed on the Assign User Permissions.


The different roles are also assigned different default security attributes for AutoSynch.  Please see Autosynch and Synch Orgunit Permissions article for more information.


Inactive

Inactive users cannot log-in.  Please see related article:  When Should I Delete a User Versus Making the User Inactive?


Application User

This is the default setting when setting up a new User and it intended for provide Users with standard functionality and therefore limited access to sensitive parts of Dynamic Budget.  Users can only be assigned access to the below menus on Assign User Permissions/User Profile tab.  Please note that while checkboxes for non-accessible menus may be checked, the users will still not be able to see the menus.


Because these Users cannot be provided access to the User Management menu they cannot make any changes to their own security setup or to those of other users.



Also if a specific menu item has been hidden but is viewable to Administrators (System, Restricted and Unrestricted) the Application User will not be able to see the menu item even if they have been given the above access. Please see related articles: How Do I Hide/Unhide Menu Items? and What Do I Do When An Application User is Setup with Payroll But Does Not See Payroll Menu Items?


Administrator - Restricted

This role was created to provide full security privileges to an Administrator within an assigned CompanyDB/s except for the ability to assign Payroll to either the User themselves or to other Users.


CompanyDB/s and User Management menu accesses must be completed by the System Manager.  A person with the Administrator - Unrestricted role does not have the authority to give themselves access to companies and when setting up new Users the person can only provide access to CompanyDB/s to which they themselves have access.


This role does also not allow the person to assign AutoSynch to themselves and other Users.


If the User has not been given User Management menu access they will not be able to view this menu and associated menu items and therefore will not be able to manage any security functionality.  If the User has not been given access to CompanyDB/s they will not be able to view any of its data including, as below, User data associated with the CompanyDB/s on the User Management screen.



The Administrator - Restricted can access and change all Feature and Admin Menus except for Payroll which is greyed-out.

Please note that in order to view Project Tracking, the Allocations menu needs to be checked.



Administrator - Unrestricted

This role was created to provide full security privileges to an Administrator within an assigned CompanyDB/s.  CompanyDB/s access and User Management Menu is granted by the System Manager. A person with the Administrator - Unrestricted role does not have the authority to give themselves access to CompanyDB/s and when setting up new Users the person can only provide access to CompanyDB/s to which they themselves have access.


This role does also not allow the person to assign AutoSynch to themselves and other Users.


The Administrator-Unrestricted can access and change all Features and Admin Menus.  If the User has not been given User Management menu access they will not be able to view this menu and associated menu items and therefore will not be able to manage any security functionality



Please note that  in order to view Project Tracking, the Allocations menu needs to be checked.



System Manager

The System Manager has all the security privileges as the Administrator - Unrestricted as well the ability to provide access to all CompanyDB/s and AutoSynch functionality.  The System Manager has access to all Features and Admin Menus, and can make any changes.