Permissions
Permissions decide what a user can do in Weissr Capex. You assign them to user groups, and every member of a group inherits them. This page explains how the permission model works, where in Administration you manage it, and lists every permission in the three application areas: Common, Capex Management and Capex Strategy.
It is written for administrators and superusers setting up or reviewing access in your organization.
How permissions work
Four rules cover almost everything:
Permissions are assigned to user groups, never to individual users. A user gets a permission by belonging to a group that has it.
A group can hold a permission only once. A group can have many permissions, but you cannot assign the same one to it twice.
A permission is either on or off, or it has a level. On or off permissions are a single checkbox. Level based permissions have three: Create, Edit and Read.
Most permissions apply system-wide, but some are granted per node in the Organizational Structure. Both Capex Management and Capex Strategy have permissions of this kind.
Permission levels: Read, Edit and Create
Level based permissions are marked Is CRUD in the Administration pages, and Read, Edit, Create in the reference tables further down. Each level includes the ones below it, so you only ever tick the highest level a group needs.
Level | What the group can do | Includes |
|---|---|---|
Read | View the object. No changes. | Nothing below it. |
Edit | View and change the object. | Read |
Create | View, change, create and delete the object. | Read and Edit |
📌 Note: There is no separate delete checkbox. Create is what allows a group to delete objects, so treat it as the highest level of trust.
📌 Note: Read cannot be switched off. Once a level based permission is assigned to a group, Read is always on and the checkbox is greyed out. In the same way, Edit is locked once Create is ticked, because the higher level already includes it.
What happens when a user belongs to several groups
Weissr merges the permissions of all the groups a user belongs to into one list. Each permission appears once in that list, at the highest level granted by any of the groups. A user who has Read through one group and Create through another ends up with Create.
Permissions are only ever added this way. A group cannot take away something another group has granted.
Permissions tied to the Organizational Structure
Not every permission is granted system-wide. Some are granted per node, so a group can hold them in one part of the organization and not in another. Both applications have permissions of this kind, and they are managed in different places.
Application | Permissions granted per node | Where you grant them |
|---|---|---|
Capex Management | Project (CM), Request creation and Approval. | Administration → Capex Management → Organizational structure. One structure for the whole application. |
Capex Strategy | A larger set: Asset blocks to nodes, Asset ledger, Asset mapping, Asset scope, Base alternative, External Data, Investment map, Model, Model input audit log, Node audit log, Report chart, Report table, Strategic alternative, Strategic building block and View Node And Sub Nodes. | Administration → Capex Strategy → Nodes. This structure is per project, so select the project first. The page title calls it Organizational structure, the menu item calls it Nodes. |
Three ways to tell a node permission from a system-wide one:
The Scope column in the reference tables below reads Node or Division instead of Global.
On the Permissions page, a node permission offers a Node assignments... button where a global permission offers Assignments....
Node permissions never appear in the Permission matrix. The matrix lists global permissions only.
📌 Note: Division is a narrower kind of node permission. A Division permission can only be placed on a node whose type is Division or Group, not on any node in the tree. Two Capex Strategy permissions work this way: Base alternative and Strategic alternative.
👉 Assigning Permissions in the Organizational Structure
Where to manage permissions
Global permissions are managed under Administration → Security. You need the Administrator or Superuser permission to open it.
Give one group its permissions
Location: Administration → Security → User groups
Find the group in the list and open its Action menu.
Choose Permissions. The dialog Edit permissions for user group opens.
Pick a permission in Add permission. It is assigned straight away.
For a level based permission, tick Create or Edit in the row. Read is already on.
To take a permission away, use the remove button at the end of its row.
Assigned permissions are grouped into one card per application area, so you can see at a glance what the group can do in Common, Capex Management and Capex Strategy.
Give one permission to several groups at once
Location: Administration → Security → Permissions
Find the permission in the list and click Assignments....
In User groups, select every group that should have it. Each change is saved immediately.
The Users card below the selector lists everyone who now inherits the permission, so you can check the result before closing the dialog.
💡 Tip: This dialog assigns the permission at Read level. To grant Edit or Create, go to the Permission matrix or the group's own Permissions dialog afterwards.
Set many permissions at once with the Permission matrix
Location: Administration → Security → Permissions → Permission matrix
The matrix is the fastest way to set up a new environment or review an existing one. Permissions run across the columns, user groups down the rows, and you tick the intersection.
The matrix is split into three tabs: Common, Capex Strategy and Capex Management.
Level based permissions show three checkboxes, Create, Edit and Read. On or off permissions show one.
Only global permissions appear here. Node and Division permissions are granted in the Organizational Structure instead.
🔒 Two cells are deliberately locked. You cannot grant Superuser unless you are a superuser yourself, and you cannot change the permissions of a group you belong to. Ask a colleague to make that change.
Grant a permission on part of the organization
Location: Administration → Capex Management → Organizational structure, or Administration → Capex Strategy → Nodes
Node and Division permissions are granted on the node itself. Select the node in the tree, then assign the permission to a user group or user on the right. For Capex Strategy, select the project first, because each project has its own structure.
📌 Note: The CS node permissions and CM node permissions items in the Users and User groups action menus are read-only views. They show what a user or group already holds, node by node. To change anything, go to the Organizational structure.
See what a single user can do
Location: Administration → Security → Users
Open the user's Actions menu and choose Permissions. The dialog lists every global permission the user has inherited from their groups, with the application area and the Create, Edit and Read levels. This view is read-only. To change what the user can do, change their group membership or the permissions of their groups. For node permissions, use CS node permissions or CM node permissions in the same menu.
See who holds a given permission
Location: Administration → Security → Permissions
Click Assignments... on the permission, or Node assignments... if it is a node permission. The dialog lists the user groups that hold it and the users who inherit it. This is the quickest answer to "who can approve requests" or "who has Superuser".
⚠️ Superuser and Administrator give full access
Superuser grants access to the whole system, including the Administration page. Administrator grants full access to the Administration page. Both bypass the permission model for everything they cover, so review the members of any group holding them before you assign anything else.
Superuser also carries every Capex Management node permission implicitly, with one exception: Approval. A superuser is not a decision maker until the Approval permission is granted on the relevant node.
Permission change log
Every permission change is recorded: the group, the permission, the action taken, the user who made the change and the time. Assignment, un-assignment and changes to the Create, Edit and Read levels are all tracked.
To see changes for | Go to |
|---|---|
One permission | Administration → Security → Permissions → Action → Audit log |
One user group | Administration → Security → User groups → Action → Audit log |
One user | Administration → Security → Users → Actions → Audit log. The tabs As recorded user and As affected user separate changes the user made from changes made to them. |
Everything | Administration → Audit logs → Security / Permissions |
📌 Note: Log entries identify a permission by its ID number, not its name. Use the ID column in the tables below to look it up.
Permission reference
The three tables below list the permissions in each application area.
ID is the number used in the change log.
Level is On/off for a single checkbox, or Read, Edit, Create for a permission with levels.
Scope is Global for a permission granted system-wide in Administration → Security, or Node or Division for one granted per node in the Organizational Structure.
Common permissions
ID | Permission | Level | Scope | What it allows |
|---|---|---|---|---|
77 | Administrator | On/off | Global | Full access to the Administration page. |
70 | Currency rate | Read, Edit, Create | Global | Open and manage currency exchange rates from the Capex Management and Capex Strategy navigation. |
1 | Superuser | On/off | Global | Full access to the system, including the Administration page. Acting as a decision maker still requires the Approval permission. |
80 | Tag management | On/off | Global | Create, update and delete tags for Capex Strategy alternatives and Capex Management documents. |
Capex Management permissions
Capital Budgeting permissions are part of Capex Management and are marked in the descriptions below.
ID | Permission | Level | Scope | What it allows |
|---|---|---|---|---|
82 | Additional request creation | On/off | Global | Create additional funding requests inside a project, even without create rights on the node. Requires Edit through the Project (CM) node permission, or Edit granted by an invitation to the project. See Managing Overspend and Additional Funding. |
85 | Approval | On/off | Node | Take part in the approval process and act as a decision maker on requests. It allows the user to change the state of a request in the approval workflow. It does not give visibility of every request in the node. See Assigning Permissions in the Organizational Structure. |
5 | Budget Alternative | Read, Edit, Create | Global | Capital Budgeting. View, edit, create, duplicate and delete Capital Budgets. |
76 | Capex Management configuration | On/off | Global | Full access to the Capex Management sections of the Administration page. |
84 | Child request creation | On/off | Global | Create child requests and sub-requests, even without create rights on the node. Requires Edit through the Project (CM) node permission. |
10 | Decision permission (budget alternatives) | On/off | Global | Capital Budgeting. Approve and disapprove Capital Budgets, and mark them as preliminary. |
87 | Delete approved requests | On/off | Global | Permanently delete requests that are approved, completed or rejected. Without it, only draft and active requests can be deleted. Can be given to superusers and to general users. |
86 | Funds reallocation | On/off | Global | Reallocate funds within Capex Management. Requires create rights on the node, or Edit through the Project (CM) node permission or an invitation to the project. Use it together with Additional request creation. See Managing Overspend and Additional Funding. |
29 | Import/export capex request data to/from ERP systems | On/off | Global | Open the Import/Export page and transfer data to and from ERP systems. |
4 | Project (CM) | Read, Edit, Create | Node | Access and manage projects in Capex Management. What the user can do follows the level granted on each node. See Assigning Permissions in the Organizational Structure. |
30 | Request creation | On/off | Node | Create requests in a node. The user sees only the requests they created or were invited to, not the other requests in that node. See Assigning Permissions in the Organizational Structure. |
15 | Secret project | On/off | Global | Make capex requests private or public, and see other users' private requests. |
24 | Selector of suggested decision maker | On/off | Global | Assign decision makers in the decision steps of a request. |
81 | Send individual capex rows | On/off | Global | Send selected capex rows to external ERP systems. |
28 | Setting/editing Capex request approval step planned date | On/off | Global | Set planned dates for the approval steps in a request workflow. |
Capex Strategy permissions
📌 Note: Base alternative, Strategic alternative and Strategic building block work as one family. Which of the three is checked depends on the type of the alternative being opened, and the check runs against the alternative's own node and the nodes above it. On top of that, a user needs View Node And Sub Nodes on at least one node in the alternative's structure, unless they hold Administrator.
ID | Permission | Level | Scope | What it allows |
|---|---|---|---|---|
39 | Alternative delta report/ TA sheet | On/off | Global | View the Alternative delta report in presentations. |
61 | Asset blocks to nodes | Read, Edit, Create | Node | Assign asset blocks to project nodes. |
59 | Asset ledger | Read, Edit, Create | Node | Manage asset ledgers within nodes. A legacy permission, kept for existing configurations. |
58 | Asset mapping | Read, Edit, Create | Node | Map assets to project structures. |
60 | Asset scope | Read, Edit, Create | Node | Define the scope of assets at node level. |
71 | Base alternative | Read, Edit, Create | Division | Manage base alternatives within strategic projects. Can only be assigned on a node of type Division or Group. |
65 | Can be selected as responsible for asset data | On/off | Global | The user can be picked as responsible for asset data in alternative overviews. |
31 | Can be selected as responsible for base alternative | On/off | Global | The user can be picked as responsible for base alternatives. |
26 | Can be selected as responsible for external data | On/off | Global | The user can be picked as responsible for external data in alternatives. |
66 | Can be selected as responsible for investment plan | On/off | Global | The user can be picked as responsible for investment plans. |
32 | Can be selected as responsible for strategic alternative | On/off | Global | The user can be picked as responsible for strategic alternatives. |
33 | Can be selected as responsible for strategic building block | On/off | Global | The user can be picked as responsible for strategic building blocks. |
74 | Can select responsible user for alternative part | On/off | Global | Assign other users as responsible for parts of an alternative. |
75 | External Data | Read, Edit, Create | Node | Manage external data at node level. |
47 | Investment map | On/off | Node | Assign investment maps to nodes. |
78 | Manage Alternative States | On/off | Global | Activate and deactivate project alternatives to control memory use. Also opens the activation and deactivation log. |
34 | Manage Current Strategy | On/off | Global | Mark a group strategy as the current strategy so it can be used in Capex Management. |
50 | Manage Documents | Read, Edit, Create | Global | Manage documents inside alternatives: upload, replace and delete, depending on the level granted. Also opens the document audit log. |
49 | Model | Read, Edit, Create | Node | Manage models at node level. |
48 | Model Assumptions | Read, Edit, Create | Global | Open and manage the cash flow settings (assumptions) of base alternatives. |
44 | Model input audit log | On/off | Node | Open the log of model input changes. |
45 | Node audit log | On/off | Node | Open the log of node changes. Required to see changes in Asset mapping. |
37 | Project (CS) | Read, Edit, Create | Global | Access and manage projects in Capex Strategy. |
68 | Project lock | On/off | Global | Lock project versions so they cannot be changed. |
72 | Report chart | Read, Edit, Create | Node | Manage chart assignments at node level. |
38 | Report chart folder | Read, Edit, Create | Global | Create, rename and delete chart folders. |
43 | Report table | Read, Edit, Create | Node | Assign report tables to project nodes. |
63 | Scope level node audit log | On/off | Global | Open the audit log for scope changes in alternatives. |
40 | Sensitivity data/parameters | Read, Edit, Create | Global | Manage sensitivity settings in projects. |
41 | Sensitivity summary report | On/off | Global | View the Sensitivity Summary report in presentations. |
18 | Strategic alternative | Read, Edit, Create | Division | View, edit and create strategic alternatives on the node. Can only be assigned on a node of type Division or Group. |
19 | Strategic building block | Read, Edit, Create | Node | View, edit and create strategic building blocks on the node. |
3 | View Node And Sub Nodes | On/off | Node | See the node and its sub-nodes in the Capex Strategy scope. It is also a prerequisite for opening an alternative: the user needs it on at least one node in the alternative's structure, unless they hold Administrator. |