Permissions

Permissions decide what a user can do in Weissr Capex. You assign them to user groups, and every member of a group inherits them. This page explains how the permission model works, where in Administration you manage it, and lists every permission in the three application areas: Common, Capex Management and Capex Strategy.

It is written for administrators and superusers setting up or reviewing access in your organization.



How permissions work

Four rules cover almost everything:

  • Permissions are assigned to user groups, never to individual users. A user gets a permission by belonging to a group that has it.

  • A group can hold a permission only once. A group can have many permissions, but you cannot assign the same one to it twice.

  • A permission is either on or off, or it has a level. On or off permissions are a single checkbox. Level based permissions have three: Create, Edit and Read.

  • Most permissions apply system-wide, but some are granted per node in the Organizational Structure. Both Capex Management and Capex Strategy have permissions of this kind.

Permission levels: Read, Edit and Create

Level based permissions are marked Is CRUD in the Administration pages, and Read, Edit, Create in the reference tables further down. Each level includes the ones below it, so you only ever tick the highest level a group needs.

Level

What the group can do

Includes

Read

View the object. No changes.

Nothing below it.

Edit

View and change the object.

Read

Create

View, change, create and delete the object.

Read and Edit

📌 Note: There is no separate delete checkbox. Create is what allows a group to delete objects, so treat it as the highest level of trust.

📌 Note: Read cannot be switched off. Once a level based permission is assigned to a group, Read is always on and the checkbox is greyed out. In the same way, Edit is locked once Create is ticked, because the higher level already includes it.

What happens when a user belongs to several groups

Weissr merges the permissions of all the groups a user belongs to into one list. Each permission appears once in that list, at the highest level granted by any of the groups. A user who has Read through one group and Create through another ends up with Create.

Permissions are only ever added this way. A group cannot take away something another group has granted.

Permissions tied to the Organizational Structure

Not every permission is granted system-wide. Some are granted per node, so a group can hold them in one part of the organization and not in another. Both applications have permissions of this kind, and they are managed in different places.

Application

Permissions granted per node

Where you grant them

Capex Management

Project (CM), Request creation and Approval.

Administration → Capex Management → Organizational structure. One structure for the whole application.

Capex Strategy

A larger set: Asset blocks to nodes, Asset ledger, Asset mapping, Asset scope, Base alternative, External Data, Investment map, Model, Model input audit log, Node audit log, Report chart, Report table, Strategic alternative, Strategic building block and View Node And Sub Nodes.

Administration → Capex Strategy → Nodes. This structure is per project, so select the project first. The page title calls it Organizational structure, the menu item calls it Nodes.

Three ways to tell a node permission from a system-wide one:

  • The Scope column in the reference tables below reads Node or Division instead of Global.

  • On the Permissions page, a node permission offers a Node assignments... button where a global permission offers Assignments....

  • Node permissions never appear in the Permission matrix. The matrix lists global permissions only.

📌 Note: Division is a narrower kind of node permission. A Division permission can only be placed on a node whose type is Division or Group, not on any node in the tree. Two Capex Strategy permissions work this way: Base alternative and Strategic alternative.

👉 Assigning Permissions in the Organizational Structure


Where to manage permissions

Global permissions are managed under Administration → Security. You need the Administrator or Superuser permission to open it.

Give one group its permissions

Location: Administration → Security → User groups

  1. Find the group in the list and open its Action menu.

  2. Choose Permissions. The dialog Edit permissions for user group opens.

  3. Pick a permission in Add permission. It is assigned straight away.

  4. For a level based permission, tick Create or Edit in the row. Read is already on.

  5. To take a permission away, use the remove button at the end of its row.

Assigned permissions are grouped into one card per application area, so you can see at a glance what the group can do in Common, Capex Management and Capex Strategy.

Give one permission to several groups at once

Location: Administration → Security → Permissions

  1. Find the permission in the list and click Assignments....

  2. In User groups, select every group that should have it. Each change is saved immediately.

  3. The Users card below the selector lists everyone who now inherits the permission, so you can check the result before closing the dialog.

💡 Tip: This dialog assigns the permission at Read level. To grant Edit or Create, go to the Permission matrix or the group's own Permissions dialog afterwards.

Set many permissions at once with the Permission matrix

Location: Administration → Security → Permissions → Permission matrix

The matrix is the fastest way to set up a new environment or review an existing one. Permissions run across the columns, user groups down the rows, and you tick the intersection.

  • The matrix is split into three tabs: Common, Capex Strategy and Capex Management.

  • Level based permissions show three checkboxes, Create, Edit and Read. On or off permissions show one.

  • Only global permissions appear here. Node and Division permissions are granted in the Organizational Structure instead.

🔒 Two cells are deliberately locked. You cannot grant Superuser unless you are a superuser yourself, and you cannot change the permissions of a group you belong to. Ask a colleague to make that change.

Grant a permission on part of the organization

Location: Administration → Capex Management → Organizational structure, or Administration → Capex Strategy → Nodes

Node and Division permissions are granted on the node itself. Select the node in the tree, then assign the permission to a user group or user on the right. For Capex Strategy, select the project first, because each project has its own structure.

📌 Note: The CS node permissions and CM node permissions items in the Users and User groups action menus are read-only views. They show what a user or group already holds, node by node. To change anything, go to the Organizational structure.

See what a single user can do

Location: Administration → Security → Users

Open the user's Actions menu and choose Permissions. The dialog lists every global permission the user has inherited from their groups, with the application area and the Create, Edit and Read levels. This view is read-only. To change what the user can do, change their group membership or the permissions of their groups. For node permissions, use CS node permissions or CM node permissions in the same menu.

See who holds a given permission

Location: Administration → Security → Permissions

Click Assignments... on the permission, or Node assignments... if it is a node permission. The dialog lists the user groups that hold it and the users who inherit it. This is the quickest answer to "who can approve requests" or "who has Superuser".

⚠️ Superuser and Administrator give full access

Superuser grants access to the whole system, including the Administration page. Administrator grants full access to the Administration page. Both bypass the permission model for everything they cover, so review the members of any group holding them before you assign anything else.

Superuser also carries every Capex Management node permission implicitly, with one exception: Approval. A superuser is not a decision maker until the Approval permission is granted on the relevant node.


Permission change log

Every permission change is recorded: the group, the permission, the action taken, the user who made the change and the time. Assignment, un-assignment and changes to the Create, Edit and Read levels are all tracked.

To see changes for

Go to

One permission

Administration → Security → Permissions → Action → Audit log

One user group

Administration → Security → User groups → Action → Audit log

One user

Administration → Security → Users → Actions → Audit log. The tabs As recorded user and As affected user separate changes the user made from changes made to them.

Everything

Administration → Audit logs → Security / Permissions

📌 Note: Log entries identify a permission by its ID number, not its name. Use the ID column in the tables below to look it up.


Permission reference

The three tables below list the permissions in each application area.

  • ID is the number used in the change log.

  • Level is On/off for a single checkbox, or Read, Edit, Create for a permission with levels.

  • Scope is Global for a permission granted system-wide in Administration → Security, or Node or Division for one granted per node in the Organizational Structure.

Common permissions

ID

Permission

Level

Scope

What it allows

77

Administrator

On/off

Global

Full access to the Administration page.

70

Currency rate

Read, Edit, Create

Global

Open and manage currency exchange rates from the Capex Management and Capex Strategy navigation.

1

Superuser

On/off

Global

Full access to the system, including the Administration page. Acting as a decision maker still requires the Approval permission.

80

Tag management

On/off

Global

Create, update and delete tags for Capex Strategy alternatives and Capex Management documents.

Capex Management permissions

Capital Budgeting permissions are part of Capex Management and are marked in the descriptions below.

ID

Permission

Level

Scope

What it allows

82

Additional request creation

On/off

Global

Create additional funding requests inside a project, even without create rights on the node. Requires Edit through the Project (CM) node permission, or Edit granted by an invitation to the project. See Managing Overspend and Additional Funding.

85

Approval

On/off

Node

Take part in the approval process and act as a decision maker on requests. It allows the user to change the state of a request in the approval workflow. It does not give visibility of every request in the node. See Assigning Permissions in the Organizational Structure.

5

Budget Alternative

Read, Edit, Create

Global

Capital Budgeting. View, edit, create, duplicate and delete Capital Budgets.

76

Capex Management configuration

On/off

Global

Full access to the Capex Management sections of the Administration page.

84

Child request creation

On/off

Global

Create child requests and sub-requests, even without create rights on the node. Requires Edit through the Project (CM) node permission.

10

Decision permission (budget alternatives)

On/off

Global

Capital Budgeting. Approve and disapprove Capital Budgets, and mark them as preliminary.

87

Delete approved requests

On/off

Global

Permanently delete requests that are approved, completed or rejected. Without it, only draft and active requests can be deleted. Can be given to superusers and to general users.

86

Funds reallocation

On/off

Global

Reallocate funds within Capex Management. Requires create rights on the node, or Edit through the Project (CM) node permission or an invitation to the project. Use it together with Additional request creation. See Managing Overspend and Additional Funding.

29

Import/export capex request data to/from ERP systems

On/off

Global

Open the Import/Export page and transfer data to and from ERP systems.

4

Project (CM)

Read, Edit, Create

Node

Access and manage projects in Capex Management. What the user can do follows the level granted on each node. See Assigning Permissions in the Organizational Structure.

30

Request creation

On/off

Node

Create requests in a node. The user sees only the requests they created or were invited to, not the other requests in that node. See Assigning Permissions in the Organizational Structure.

15

Secret project

On/off

Global

Make capex requests private or public, and see other users' private requests.

24

Selector of suggested decision maker

On/off

Global

Assign decision makers in the decision steps of a request.

81

Send individual capex rows

On/off

Global

Send selected capex rows to external ERP systems.

28

Setting/editing Capex request approval step planned date

On/off

Global

Set planned dates for the approval steps in a request workflow.

Capex Strategy permissions

📌 Note: Base alternative, Strategic alternative and Strategic building block work as one family. Which of the three is checked depends on the type of the alternative being opened, and the check runs against the alternative's own node and the nodes above it. On top of that, a user needs View Node And Sub Nodes on at least one node in the alternative's structure, unless they hold Administrator.

ID

Permission

Level

Scope

What it allows

39

Alternative delta report/ TA sheet

On/off

Global

View the Alternative delta report in presentations.

61

Asset blocks to nodes

Read, Edit, Create

Node

Assign asset blocks to project nodes.

59

Asset ledger

Read, Edit, Create

Node

Manage asset ledgers within nodes. A legacy permission, kept for existing configurations.

58

Asset mapping

Read, Edit, Create

Node

Map assets to project structures.

60

Asset scope

Read, Edit, Create

Node

Define the scope of assets at node level.

71

Base alternative

Read, Edit, Create

Division

Manage base alternatives within strategic projects. Can only be assigned on a node of type Division or Group.

65

Can be selected as responsible for asset data

On/off

Global

The user can be picked as responsible for asset data in alternative overviews.

31

Can be selected as responsible for base alternative

On/off

Global

The user can be picked as responsible for base alternatives.

26

Can be selected as responsible for external data

On/off

Global

The user can be picked as responsible for external data in alternatives.

66

Can be selected as responsible for investment plan

On/off

Global

The user can be picked as responsible for investment plans.

32

Can be selected as responsible for strategic alternative

On/off

Global

The user can be picked as responsible for strategic alternatives.

33

Can be selected as responsible for strategic building block

On/off

Global

The user can be picked as responsible for strategic building blocks.

74

Can select responsible user for alternative part

On/off

Global

Assign other users as responsible for parts of an alternative.

75

External Data

Read, Edit, Create

Node

Manage external data at node level.

47

Investment map

On/off

Node

Assign investment maps to nodes.

78

Manage Alternative States

On/off

Global

Activate and deactivate project alternatives to control memory use. Also opens the activation and deactivation log.

34

Manage Current Strategy

On/off

Global

Mark a group strategy as the current strategy so it can be used in Capex Management.

50

Manage Documents

Read, Edit, Create

Global

Manage documents inside alternatives: upload, replace and delete, depending on the level granted. Also opens the document audit log.

49

Model

Read, Edit, Create

Node

Manage models at node level.

48

Model Assumptions

Read, Edit, Create

Global

Open and manage the cash flow settings (assumptions) of base alternatives.

44

Model input audit log

On/off

Node

Open the log of model input changes.

45

Node audit log

On/off

Node

Open the log of node changes. Required to see changes in Asset mapping.

37

Project (CS)

Read, Edit, Create

Global

Access and manage projects in Capex Strategy.

68

Project lock

On/off

Global

Lock project versions so they cannot be changed.

72

Report chart

Read, Edit, Create

Node

Manage chart assignments at node level.

38

Report chart folder

Read, Edit, Create

Global

Create, rename and delete chart folders.

43

Report table

Read, Edit, Create

Node

Assign report tables to project nodes.

63

Scope level node audit log

On/off

Global

Open the audit log for scope changes in alternatives.

40

Sensitivity data/parameters

Read, Edit, Create

Global

Manage sensitivity settings in projects.

41

Sensitivity summary report

On/off

Global

View the Sensitivity Summary report in presentations.

18

Strategic alternative

Read, Edit, Create

Division

View, edit and create strategic alternatives on the node. Can only be assigned on a node of type Division or Group.

19

Strategic building block

Read, Edit, Create

Node

View, edit and create strategic building blocks on the node.

3

View Node And Sub Nodes

On/off

Node

See the node and its sub-nodes in the Capex Strategy scope. It is also a prerequisite for opening an alternative: the user needs it on at least one node in the alternative's structure, unless they hold Administrator.