Customizing the access rights for groups of users and individual users to work with the application. Access rights are defined at a user group level as each user can belong to more than one group and the rights of different groups are combined. The rights are set at several levels
- Modules – rights can be forbidden for whole modules
- Submodules
- Objects and extensions
- Actions to objects – a group may be allowed to edit the records of an object but not to add new ones, or to view the records with no rights to change anything.
A separate group of rights is personalized and is declared at user level. It allows setting filters by objects. In this way for example a certain user can only see the clients which are legal persons. Filters are created through a user interface, which enables the introduction of complex filters, the use of logical operators, combinations etc. Users are organized in groups that define and limit what a user can see. There is a password to each user, which is encrypted when saved. Users can also be limited by the IP address they use to enter the system. The system is closely integrated with the status system, which also allows personalization of rights.