Manage User Roles and Privileges > Managing privileges for custom user roles > Segregation and validation of record and field privileges
  

Segregation and validation of record and field privileges

The privileges that you assign on the Records and Attributes tabs of the user role details page are independent of each other.
The privileges that you assign on the Records tab aren't automatically assigned to all fields on the Attributes tab. If you fine-tune the privileges on the Attributes tab, the changes aren't automatically updated on the Records tab.
To ensure that the privileges are valid and to minimize the validation messages, you need to manually assign the right combination of privileges on the Records and Attributes tabs.

Validation of privileges

If the record and field privileges that you configure for custom user roles on the user role details page aren't valid, validation messages appear.
Before you save the privileges, you need to fix the validation errors. These validation messages provide additional information about dependent privileges that enable you to configure a valid set of privileges.
The validation messages are grouped based on the record-level and attribute-level privileges that are missing and they appear separately within the Records and Attributes tabs. You can view the list of field groups that miss dependent privileges in the attribute-level validation messages. Clicking these field groups directs you to the missing privileges that are highlighted. Ensure that you assign these required privileges before you save the configuration of privileges. The validation messages disappear after you click Save or after you remove the assigned privileges that aren't valid.
For more information about assigning a valid set of privileges, see Guidelines to configure record and field privileges.

Guidelines to configure record and field privileges

When you assign privileges on the Records and Attributes tabs, you need to ensure that you assign a valid set of privileges.
Consider the following guidelines when you configure privileges on the Records and Attributes tabs:
For more information about assigning privileges for multiple business entities, see Configure privileges for multiple assets.
The following table contains the list of dependent privileges for record-level privileges:
Type of Privilege
Privilege
Requires
Record-level
Create or read
Create or read for attributes.
Record-level
Update
Create, update, or delete for attributes.
Record-level
Delete
Read privilege to records.
The following table contains the list of dependent privileges for attribute-level privileges:
Type of Privilege
Privilege
Requires
Attribute-level
Create
Create or update to records.
Attribute-level
Read or update
Read or update to records.
Attribute-level
Delete
Update to records.
Attribute-level
Read or update to child fields or nested field groups.
Read or update to parent field groups and to records.
Attribute-level
Create to child fields or nested field groups.
Create and update to parent field groups and records.
Note:
Update enables the users to edit a newly created child field's value.
Attribute-level
Delete to child fields or nested field groups.
Update to parent field groups and records.
Attribute-level
Read to a field group.
Read to at least one attribute in the field group and to records.
Attribute-level
Create to a field group.
Create to at least one attribute in the field group and create and update to records.
Note:
Update to records enables the users to update the value of a newly created field in the field group.
Attribute-level
Update to a field group.
Create, update, or delete to at least one attribute in the field group and update to record.
Attribute-level
Delete to a field group.
Update to record.
The following table contains the list of dependent privileges when you use bulk edit to assign privileges to multiple business entities:
Type of Privilege
Privilege
Requires
Record-level in bulk edit.
Read or create.
Read or create to attributes in bulk edit.
Record-level in bulk edit.
Update
Update to attributes and optionally create or delete to attributes in bulk edit.
Attribute-level in bulk edit.
Read or update.
Read or update to records in bulk edit.
Attribute-level in bulk edit.
Create
Create or update to records bulk edit.
Attribute-level in bulk edit.
Delete
Update to records in bulk edit.
Note:
If you assign a privilege to a field group, the privileges are automatically assigned to all fields within the field group. You can't fine-tune or disable the privileges assigned to these fields within the field groups. As a workaround, to disable a privilege assigned to fields within a field group, select the header-level checkbox for each privilege on the Attributes tab. This disables the privileges for all field groups and their fields.