Rules and guidelines for managing privileges for custom user roles
Consider the following rules and guidelines to manage privileges for custom user roles in your organization:
•You can't delete system-defined roles but you can delete custom roles.
•If you modify the permissions at the asset level in Administrator, the system automatically synchronizes the modifications on the Security page of Business 360 Console on an hourly basis.
•If you manually assign all the privileges of predefined user roles to custom user roles, the custom user roles can't perform all the tasks that the predefined user roles can perform.
To enable a user to perform a specific task, ensure that you assign the custom user role and other required user roles to the user along with the required privileges to perform the task. For example, to enable a user to perform file import, assign the custom user role and the Business360ProcessExecutor user role along with the required privileges on the Security page and Administrator.
For more information about the required user roles and privileges for a user to perform file import, see File Import.
•After you configure privileges for custom user roles on the Security page, ensure that you don't rename user roles in Administrator. If you rename user roles, MDM SaaS removes all the configured privileges.
•To perform actions in Business 360 Console, assign the user to the Admin or Designer and MDM Designer user roles.
•After you edit record and field privileges or data access rules for a business entity, users with custom user roles must wait at least 10 minutes before they perform the following actions:
- Search for records in the user interface or by using the Search REST API.
- View dashboards that include reports based on records of the business entity.
If users search for records or view dashboards immediately after the changes, business applications display inaccurate results.
•Ensure that you don't clone predefined user roles in Administrator and assign the cloned user roles to users in Business 360 Console. Users assigned to the cloned custom user roles can't perform all the tasks that a predefined user role can perform in your organization.
For example, users with Designer or MDM Designer user roles can configure business applications. However, if you clone the Designer or MDM Designer user role to create a custom user role, users assigned to the cloned custom user role can't configure business applications.
•Only users that are assigned to predefined user roles can run all jobs in Business 360 Console. For example, a user with an MDM Designer user role can run all jobs but a user with a custom user role can't run any jobs in Business 360 Console.
•Custom user role names are case-sensitive in MDM SaaS.
•If you don't have the license to a MDM SaaS business application and create a custom user role in Administrator with a name identical to any predefined user role of the business application, Business 360 Console doesn't display the custom user role on the Security page.
For more information about predefined user roles in MDM SaaS, see Predefined user roles