Quick StartThe ReportMagic MenuReport StudioFilesSchedulesBatch JobsReport JobsDashboardsProfileAdminAccount DetailsGetting StartedAbout ReportMagicRegistering and Logging InReport LibrarySearching ReportMagicConnections and AgentsWriting ReportsStarting Out With Report StudioCreating Report TemplatesRMScriptMacro ShorthandReporting on Different Periods of TimeSetting Macro Parameter DefaultsStoring Input and Output FilesReport VariablesUsing Variable ParametersSpecifying How Graphs LookStep-by-Step LogicMonitor Graph ExamplesStep-by-Step Jira Graph ExamplesSpecifying How Tables LookChanging Fonts and ColorsUsing Macros in PowerPoint TemplatesRestricted MacrosGenerating Reports Using SchedulesUsing HTML Forms in SchedulesSeeing How Reports RanViewing ReportsCached ValuesUsing AggregationsAdvanced Report StudioAdvanced [Object.Graph:] MacroAPI AccessREST APIREST API - FilesAdvancedRole-Based Access Control (RBAC)SecurityMiscellaneousBadgesCertificationsTips, Tricks and Shortcut KeysMacrosAgentAgent.ConnectionAgent.ExecuteAgent.MonitorMagicNodeListAgent.MonitorMagicNodeMeasurementListAgent.MonitorMagicNodeMeasurementSummaryAgent.MonitorMagicNodePropertyListAgent.MonitorMagicNodeTypeListAgent.PropertyAgent.SqlAnalysisAgent.SqlGraphAgent.SqlListAgent.SqlTableAgent.SqlValueAgent.SqlValuesAgent.WebQueryAlertMagicAlertMagic.MetricsGraphAlertMagic.MetricsListAlertMagic.StatisticsAutoTaskAutoTask.AccountListAutoTask.AccountPropertyAutoTask.ConnectionAutoTask.CountAutoTask.FieldListAutoTask.FieldPropertyAutoTask.ListAutoTask.PropertyAutoTask.SummaryValueAutoTask.TicketListAutoTask.TicketPropertyAzureAzure.ConnectionAzure.LogAnalyticsGraphAzure.LogAnalyticsQueryAzure.LogAnalyticsScalarAzure.LogAnalyticsTableAzure.ResourceGroupListAzure.ResourceListAzure.ResourcePropertiesAzure.SentinelAlertRuleListAzure.SentinelConnectorListAzure.SentinelIncidentListAzure.SentinelThreatIndicatorListAzure.SentinelThreatIndicatorMetricListAzure.SubscriptionListBloggerBlogger.BlogPropertyBlogger.ConnectionBlogger.PageBlogger.PageListBlogger.PagePropertyBlogger.PostBlogger.PostListBlogger.PostPropertyCacheCache.ExpiresCache.GetCache.IsSetCache.SetCache.UnsetCertifyCertify.ConnectionCertify.DepartmentListCertify.DepartmentPropertyCherwellCherwell.BusinessObjectDefinitionListCherwell.BusinessObjectListCherwell.BusinessObjectSchemaCherwell.BusinessObjectSummaryCherwell.ConnectionCiscoCisco.ConnectionCisco.FirmwareVersionPropertyCisco.SecurityAdvisoryListCisco.SerialNumberPropertyCisco.SoftwareSuggestionListCiscoDnaCenterCiscoDnaCenter.ConnectionCiscoDnaCenter.SiteListCiscoDnaCenter.SitePropertyCloudHealthCloudHealth.AssetDetailsCloudHealth.AssetListCloudHealth.AvailableReportDimensionsCloudHealth.AvailableReportOptionsCloudHealth.AvailableReportsListCloudHealth.AwsAccountDetailsCloudHealth.AwsAccountsListCloudHealth.ConnectionCloudHealth.CustomerDetailsCloudHealth.CustomerListCloudHealth.CustomerReportDetailsCloudHealth.CustomerStatementDetailsCloudHealth.OrganisationAccountsListCloudHealth.OrganisationListCloudHealth.QueryCodacyCodacy.ConnectionCodacy.ListConnectWiseManageConnectWiseManage.ConnectionConnectWiseManage.CountConnectWiseManage.DictionaryConnectWiseManage.ListConnectWiseManage.PropertyCoreArrayArray.CountBreakBreakpointCalculateColorCommentContinueConvertDeleteDeleteRowDocumentBookmarkDocumentBreakDocumentInsertSectionDocumentSectionEmailEmailFileEmailReportExecuteForEachFormatTableCellFormatTableRowIfIgnoreIncInsertTableCellImageIsSetLinearRegressionLinkMapObjectRandomRegexRepeatRowSearchAndReplaceSectionSettingsSleepStopStopwatchStringStringIndexSubstringSwitchThrowExceptionUnsetWarningWhileDatabaseDatabase.ConnectionDatabase.GraphDatabase.ListDatabase.TableDatabase.ValueDatabase.ValuesDataMagicDataMagic.SyncDictionaryDictionary.ItemDictionary.KeysDictionary.ValuesDocumentDocument.SetPropertiesDropBoxSignDropBoxSign.ConnectionFileFile.CopyFile.CopyOutputFilesFile.Csv.CellFile.Csv.RowFile.Csv.RowCountFile.Csv.TableFile.EmbedFile.ExecuteFile.ExistsFile.ImageFile.InsertFile.ListFile.LoadListFile.LoadObjectFile.LoadStringFile.LoadVariablesFile.SaveObjectFile.Xlsx.CellFile.Xlsx.RowFile.Xlsx.RowCountFile.Xlsx.TableFunctionFunction.CallFunction.DefineGoogleGoogle.ConnectionGoogle.TableGraphGraph.AddDataGraph.DeleteDataGraph.RenameDataGraph.UpdateGravatarGravatar.ImageHaloPsaHaloPsa.ConnectionHaloPsa.ListHighlightHighlight.BearerSummaryHighlight.BroadbandSummaryHighlight.CellularSummaryHighlight.ConnectionHighlight.FolderListHighlight.HttpServerPerformanceSummaryHighlight.IcmpTcpUdpPerformanceSummaryHighlight.MosPerformanceSummaryHighlight.PrecisionPerformanceSummaryHighlight.TunnelSummaryHighlight.WatchNodeListHighlight.WirelessAccessPointSummaryHubSpotHubSpot.ListHubSpot.PropertyHubSpot.QueryJarrayJarray.TableJiraJira.AttachmentImageJira.AttachmentListJira.AttachmentPropertyJira.ConnectionJira.GraphJira.InsertMarkupJira.IssueAnalysisJira.IssueCommentListJira.IssueCommentPropertyJira.IssueLastCommentPropertyJira.IssueListJira.IssuePropertyJira.IssueResponseTimeJira.LastImageJira.StatusListJira.TableJira.TimeInStateJira.UserListJira.UserPropertyJsonJson.ItemJson.ListKrokiKroki.ImageListList.AddList.AnalysisList.ComplementList.CountList.DequeueList.DuplicatesList.FirstList.GraphList.GroupByList.IndicesOfList.IntersectionList.ItemList.RangeList.SelectList.SelectColumnsList.SortList.SummaryValueList.TableList.UnionList.WhereLogicMonitorLogicMonitor.AccountPropertyLogicMonitor.AlertAnalysisLogicMonitor.AlertCalendarLogicMonitor.AlertCountLogicMonitor.AlertListLogicMonitor.AlertMapLogicMonitor.AlertPropertyLogicMonitor.AlertRuleListLogicMonitor.AlertRulePropertyLogicMonitor.AlertStatusLogicMonitor.AlertTableLogicMonitor.AppliesToFunctionListLogicMonitor.AppliesToFunctionPropertyLogicMonitor.AppliesToListLogicMonitor.AuditEventAnalysisLogicMonitor.BigNumberWidgetValuesLogicMonitor.ClearCacheLogicMonitor.CollectorExecuteLogicMonitor.CollectorGroupListLogicMonitor.CollectorGroupPropertyLogicMonitor.CollectorListLogicMonitor.CollectorPropertyLogicMonitor.CollectorVersionListLogicMonitor.CollectorVersionPropertyLogicMonitor.ConfigCheckListLogicMonitor.ConfigCheckPropertyLogicMonitor.ConfigSourceGroupListLogicMonitor.ConfigSourceListLogicMonitor.ConfigSourcePropertyLogicMonitor.ConfigSourceXmlLogicMonitor.ConnectionLogicMonitor.ConnectionApiTokenLogicMonitor.ConvertToLiveWidgetLogicMonitor.DashboardLogicMonitor.DashboardGroupListLogicMonitor.DashboardGroupPropertyLogicMonitor.DashboardListLogicMonitor.DashboardPropertyLogicMonitor.DashboardWidgetListLogicMonitor.DatamartSyncLogicMonitor.DataPointListLogicMonitor.DataPointPropertyLogicMonitor.DataSourceGraphListLogicMonitor.DataSourceGraphPropertyLogicMonitor.DataSourceGroupListLogicMonitor.DataSourceListLogicMonitor.DataSourcePropertyLogicMonitor.DataSourceXmlLogicMonitor.DeviceConfigSourceFileLogicMonitor.DeviceConfigSourceInstanceListLogicMonitor.DeviceConfigSourceListLogicMonitor.DeviceConfigSourcePropertyLogicMonitor.DeviceCountLogicMonitor.DeviceDataSourceListLogicMonitor.DeviceDataSourcePropertyLogicMonitor.DeviceGroupListLogicMonitor.DeviceGroupPropertyLogicMonitor.DeviceListLogicMonitor.DevicePropertyLogicMonitor.DeviceSlaWidgetPropertyLogicMonitor.DeviceTableLogicMonitor.EscalationChainDestinationListLogicMonitor.EscalationChainDestinationPropertyLogicMonitor.EscalationChainListLogicMonitor.EscalationChainPropertyLogicMonitor.EventSourceFilterListLogicMonitor.EventSourceFilterPropertyLogicMonitor.EventSourceGroupListLogicMonitor.EventSourceListLogicMonitor.EventSourcePropertyLogicMonitor.EventSourceXmlLogicMonitor.FinancialInformationLogicMonitor.ForecastLogicMonitor.GraphLogicMonitor.GraphSpecificationLogicMonitor.HistoricSdtListLogicMonitor.ImageLogicMonitor.InstanceAnalysisLogicMonitor.InstanceCountLogicMonitor.InstanceDetailsTableLogicMonitor.InstanceGroupCountLogicMonitor.InstanceGroupListLogicMonitor.InstanceListLogicMonitor.InstancePropertyLogicMonitor.IntegrationListLogicMonitor.IntegrationPropertyLogicMonitor.JobMonitorListLogicMonitor.JobMonitorPropertyLogicMonitor.LastMeasurementLogicMonitor.LogAnalysisLogicMonitor.LogicModuleMetadataPropertyLogicMonitor.LogicModuleUpdateListLogicMonitor.LogicModuleUpdatePropertyLogicMonitor.LogItemListLogicMonitor.NetscanGroupListLogicMonitor.NetscanGroupPropertyLogicMonitor.NetscanListLogicMonitor.NetscanPropertyLogicMonitor.NewUserMessagePropertyLogicMonitor.PaymentInformationLogicMonitor.PercentageAvailabilityLogicMonitor.PortalVersionLogicMonitor.PropertySourceGroupListLogicMonitor.PropertySourceJsonLogicMonitor.PropertySourceListLogicMonitor.PropertySourcePropertyLogicMonitor.QueryLogicMonitor.RecipientGroupListLogicMonitor.RecipientGroupPropertyLogicMonitor.RecycleBinItemListLogicMonitor.RecycleBinItemPropertyLogicMonitor.ReportGroupListLogicMonitor.ReportGroupPropertyLogicMonitor.ReportListLogicMonitor.ReportPropertyLogicMonitor.ResourceAnalysisLogicMonitor.ResourceGroupAnalysisLogicMonitor.RoleListLogicMonitor.RolePropertyLogicMonitor.SdtListLogicMonitor.SdtPercentageLogicMonitor.SdtPropertyLogicMonitor.SingleSignOnPropertyLogicMonitor.SlaWidgetValuesLogicMonitor.SnmpSysOidMapListLogicMonitor.SnmpSysOidMapPropertyLogicMonitor.SummaryValueLogicMonitor.SummaryValueListLogicMonitor.ThresholdLogicMonitor.TrafficTableLogicMonitor.UnmonitoredDeviceListLogicMonitor.UnmonitoredDevicePropertyLogicMonitor.UserApiTokenListLogicMonitor.UserApiTokenPropertyLogicMonitor.UserListLogicMonitor.UserPropertyLogicMonitor.WebsiteCheckpointDataListLogicMonitor.WebsiteCountLogicMonitor.WebsiteGroupAnalysisLogicMonitor.WebsiteGroupCountLogicMonitor.WebsiteGroupListLogicMonitor.WebsiteGroupPropertyLogicMonitor.WebsiteListLogicMonitor.WebsitePropertyLogicMonitor.WidgetStatusMagicSuiteMagicSuite.ApplyBrandMagicSuite.BadgeListMagicSuite.ConnectionMagicSuite.ConnectionListMagicSuite.ConnectionPropertyMagicSuite.ConnectionStatusPropertyMagicSuite.FeedbackListMagicSuite.FeedbackPropertyMagicSuite.GlobalSettingPropertyMagicSuite.MacroGroupListMagicSuite.MacroHelpMagicSuite.MacroListMagicSuite.ReportBatchJobCountMagicSuite.ReportBatchJobListMagicSuite.ReportBatchJobPropertyMagicSuite.ReportConnectionSummaryMagicSuite.ReportJobCountMagicSuite.ReportJobListMagicSuite.ReportJobPropertyMagicSuite.ReportMacroCountMagicSuite.ReportPropertyMagicSuite.ReportScheduleCountMagicSuite.ReportScheduleListMagicSuite.ReportSchedulePropertyMagicSuite.SetReportPropertyMagicSuite.SubscriptionListMagicSuite.SystemPropertyMagicSuite.TenantImageMagicSuite.TopicHelpMagicSuite.VersionMerakiMeraki.CameraImageMeraki.ConfigurationChangeListMeraki.ConnectionMeraki.DevicePropertyMeraki.DeviceUplinkPropertyMeraki.EndOfLifeMeraki.NetworkClientListMeraki.NetworkDeviceListMeraki.NetworkEventListMeraki.NetworkListMeraki.NetworkPropertyMeraki.NetworkSwitchPortsListMeraki.NetworkSwitchStackListMeraki.OrganizationAdminsListMeraki.OrganizationDeviceLicenseListMeraki.OrganizationDeviceLicensePropertyMeraki.OrganizationDeviceListMeraki.OrganizationDeviceListStatusPropertyMeraki.OrganizationInventoryListMeraki.OrganizationLicenseStatePropertyMeraki.OrganizationListMeraki.OrganizationPropertyMeraki.OrganizationUplinkUsageMeraki.QueryMeraki.WirelessNetworkClientConnectionStatsPropertyMeraki.WirelessNetworkClientLatencyListMeraki.WirelessNetworkClientsConnectionStatsListMeraki.WirelessNetworkClientsLatencyListMeraki.WirelessNetworkConnectionStatsPropertyMeraki.WirelessNetworkDeviceConnectionStatsPropertyMeraki.WirelessNetworkDeviceLatencyListMeraki.WirelessNetworkDevicesConnectionStatsListMeraki.WirelessNetworkDevicesLatencyListMeraki.WirelessNetworkLatencyListMicrosoftDataverseMicrosoftDataverse.ConnectionMicrosoftDataverse.CountMicrosoftDataverse.EntityDefinitionsListMicrosoftDataverse.EntityListMicrosoftDataverse.EntityPropertyListMicrosoftDataverse.ListMicrosoftDataverse.PropertyMicrosoftGraphMicrosoftGraph.ConnectionMicrosoftGraph.QueryObjectObject.ArrayCountObject.GraphObject.PropertyObject.TypeObject.UnpackObject.UnpackVariablesOpenAiOpenAi.AnswerOpenAi.CompleteOpenAi.ConnectionOpenAi.ImageQuickBooksQuickBooks.ConnectionQuickBooks.PropertyReportMagicReportMagic.ApplyBrandReportMagic.ReportPropertyReportMagic.SetReportPropertyReportMagic.TenantImageSalesforceSalesforce.ConnectionSalesforce.ListSalesforce.PropertyServiceNowServiceNow.ConnectionServiceNow.CountServiceNow.CreateServiceNow.DeleteServiceNow.DictionaryServiceNow.ListServiceNow.PropertyServiceNow.UpdateShapeShape.AddShape.CloneShape.DeleteShape.FormatShape.HideShape.SetPropertyShape.SetTextSideroLabsOmniSideroLabsOmni.ConnectionSideroLabsOmni.ListSideroLabsOmni.ObjectSlackSlack.ConnectionSlack.MessageSlideSlide.DeleteSlide.DeleteSectionSlide.LinkSlide.MoveToSlide.RepeatSmtpSmtp.ConnectionSnmpSnmp.EnterprisePropertySolarWindsSolarWinds.ConnectionSolarWinds.SqlListSolarWinds.SqlTableSolarWindsServiceDeskSolarWindsServiceDesk.ConnectionSolarWindsServiceDesk.ListSolarWindsServiceDesk.PropertySqlSql.AnalysisTableTable.ColumnCountTable.DeleteTable.FormatTable.GraphTable.MergeCellsTable.MergeRowsTable.RowCountTable.SaveTable.SortTable.WorldMapTimeCalendarCronHumanReadableCronRunDateDateRangeDateTimeDateTime.IsInWorkHoursDateTime.WorkHoursDurationTimeSpanTogglToggl.ClientListToggl.ClientPropertyToggl.ConnectionToggl.ProjectListToggl.ProjectPropertyToggl.ProjectReportPropertyToggl.TimeEntryListToggl.TimeEntryPropertyToggl.UserListToggl.UserPropertyToggl.WorkspaceListToggl.WorkspacePropertyTwilioTwilio.ConnectionTwilio.SmsUkParliamentUkParliament.PetitionCountUkParliament.PetitionListUkParliament.PetitionPropertyVariableVariable.ImageVariable.ListVariable.PropertyWebWeb.ConnectionWeb.HtmlWeb.ImageWeb.QueryWeb.ScreenshotWeb.TableWeb.TextXlsxXlsx.AddAnalysisXlsx.EmbedZendeskZendesk.ConnectionZendesk.ListZendesk.PropertyZoho.DeskZoho.Desk.ZohoListZoho.Desk.ZohoProperty

Access Control

When A New User Registers

When a new person in your email domain registers for ReportMagic, as Tenant Admin, you'll get an email notifying you of this. The new account will not have access until you have approved them. To approve a user:

  1. From the Admin menu, click Users to see the new account and the fact that it is not yet approved.
  2. Either:
    • In the Users table, double-click to select the user, and select the Approved check box
    • Click the link in the email
  3. After this:
    • The account is shown with a green check mark in the Approved column
    • The user is notified by email that their account is approved
    • The user is given the default role as defined in Admin > Access Control > Roles

Using Role-Based Access Control (RBAC)

Role Based Access Control allows you, as a Tenant Admin, to customize the levels of access for your regular users to the different parts of ReportMagic. Tenant Admin users will always have access to all parts of the system.

All regular users on the system, or created in future, are assigned roles designated as Default role(s). There is one Default role out-of-the-box. If you left the permissions for this Default role unchanged, users assigned the role would have unrestricted access to all regular (non-Tenant Admin) menus and features associated with the role:

However, Tenant Admins can modify (or not use) the Default role and can also create multiple new default roles, for example, default Report Writer, default Schedule Creator and so on to restrict or allow access to different functionality.

Tenant Admins can also set up multiple non-default roles with customized permissions and then assign users to these roles.

To view the existing roles, memberships and permissions:

From the Admin menu, click Access Control. The Roles table lists the currently available roles.

Roles are made up of zero to many Role Permissions which are used to grant, manage and/or revoke access to certain aspects of ReportMagic. A user may be associated with zero to many Roles as shown if you scroll down to the Role Memberships table.

Creating a Role

To create a new role:

  1. In the Roles pane, click Create
  2. Add a unique name for the role, a useful description and choose whether it is a default role. All default roles will be assigned to all users created in future
Creating Role Permissions

To create permissions for a role:

  1. Scroll to the Role Permissions pane and click Create
  2. In the bottom box, choose the required role from the dropdown list
  3. Enter a name and description then choose the Type of permission required
    • Area based permission types switch an entire feature on or off (for example, a menu item) and Read and Write do not apply to this.
    • Connection permission types (from v3.10 onwards) allow an Admin to control access to a Connection (i.e. whether the Connection is accessible to specific non-Admin regular users). This also requires Connection Roles and Role Permissions to be created (and put users into those Roles, via Role Memberships) which then limit the Connection(s) concerned. More details can be found in Connection Role Security
    • Folder permission types relate to folders - type a string or search for the relevant folder in Files. Any restrictions here may affect the use of Schedules
      • Read allows viewing of the contents of the folder and its subfolders
      • Write allows writing to the folder and subfolders. Tip: If your user will be executing Schedules manually, they will need write access to the Schedule's output folder.
      • Execute is reserved for the future and currently does nothing for Folders
    • ReportSchedule permission types are Regex-based and match on Schedule names. Access to the Report Schedules area is required in order to see any Schedule. For any Schedule that matches the Regex:
      • Read allows viewing of the Schedule
      • Write allows writing (i.e. editing and saving) to the Schedule
      • Execute allows the running of the Schedule
  4. Choose the Role to which this permission applies then click Save.
  5. Repeat this process for each Area, Folder and Report Schedule permission that you may need. For example you might wish to create roles for Service Management with access to Report Schedules and Files.

Note: Role Permissions are additive. Unless a permission is specified, there is no access. Where permissions are set across multiple roles or permissions, the enabling of access will always override the revocation of it should there be contradictory permissions set.

Changing a user's Role Membership
  1. To change a user's Role Membership:
  2. From the Admin menu, click Access Control
  3. Scroll down to the list of users
  4. Next to the required user, double-click the cross or check mark to change it:
About Role Memberships
  • Only regular users are shown in the Role Memberships table, because Administrators have access to all of ReportMagic
  • A user promoted to Administrator will no longer have any associated roles and no longer appears in the Role Memberships table
  • An Administrator demoted to regular user will be automatically assigned the default role(s) and will appear on the Role Memberships table once approved
  • Users can be associated with zero, one or many Role Memberships
  • A user with no Role Memberships has no access to any ReportMagic features except those available to non-logged in users, for example Help
  • If you unapprove a user, any Role Memberships associated with the user are removed.
  • A new but not yet approved user can have Role Memberships assigned in advance of approval

Using the Access Setup Wizard

Setting up access control by hand, as described above, gives you complete control over Roles, Role Permissions and Role Memberships, including writing your own Report Schedule name patterns. The Access Setup Wizard is a much simpler way to achieve the same results for most everyday tasks - no patterns to write, and no need to understand how Roles, Role Permissions and Role Memberships fit together first.

To open it, from the Admin menu, click Access Control, then select the Access Setup Wizard tab (alongside Roles, Role Permissions and Role Memberships). The tab explains, in plain English, what new users are automatically given access to today, then offers five guided actions:

  • Inspect user access - see exactly what a user can see and do, and why
  • Health check - scan your current setup for problems and fix them
  • Create a role - set up a role with areas, folders and schedules
  • Restrict users from folders - stop selected users accessing selected folders, keeping their other access intact
  • Duplicate access - create a new role based on an existing role or user, then adjust it

As elsewhere in Access Control, Tenant Admins always see and can do everything themselves - the wizard is for managing what everyone else can do, and Administrators are never listed as candidates to restrict or add as members.

Inspecting a User's Access

Use this to check, or explain, exactly what a particular user can see and do, and why.

  1. Click the Inspect user access card.
  2. Choose a user.

The panel then shows:

  • Which menu areas they can access
  • A folder tree showing what they can read, what they can read and write, and what they cannot access at all. Turn on Show only what this user sees to hide everything else, so the tree matches exactly what they see themselves
  • Which Report Schedules they can see and edit, and for each one, whether they can run it - and if not, which requirement is missing

Hover over any item to see which Role and Role Permission is responsible for it. This is a read-only report - nothing here changes any user's access.

Running a Health Check

Over time, an access control setup can develop problems that are easy to miss - for example, a Report Schedule permission that no longer matches anything because the schedule was renamed, or a folder permission pointing at a folder that has since been deleted. The Health Check finds and fixes these.

  1. Click the Health check card. It scans automatically and lists anything it finds, in plain English, with a suggested fix.
  2. Click the fix for any issue you want to resolve. Fixes are applied one at a time so you can see progress.

Typical things it looks for include Report Schedule permissions that no longer match any schedule, folder permissions pointing at deleted folders, users who are not in any role (so they cannot see anything), roles with no members or no permissions, and roles that grant a folder or schedule without the matching menu area (so members have access they cannot actually reach). If nothing is wrong, it simply tells you so.

Creating a Role with the Wizard

This steps you through creating a new role without needing to write a Report Schedule pattern by hand:

  1. Name - give the role a name and, optionally, a description.
  2. Areas - tick the menu areas this role should have access to. If you grant a folder or schedule in a later step, its matching area (Files, or Report Schedules) is ticked for you automatically, since a user cannot use something they cannot reach the page for.
  3. Folders - choose folders and, for each, whether members can just view it or also add and edit files in it.
  4. Schedules - either pick specific schedules, or choose schedules whose name starts with some text (useful for a whole family of schedules, including ones added later), then choose whether members can see, edit and/or run them.
  5. Members - choose specific users, or switch on Everyone to make this a default role that every current and future user gets automatically.
  6. Review - check the summary, then click Create.

The wizard then creates the role and applies each permission and membership one at a time, showing progress as it goes. If anything fails partway through, you will see exactly what succeeded and what did not, with the option to retry.

Restricting Users from Folders with the Wizard

Because access control only ever grants access, stopping selected users seeing a folder normally means reworking their roles by hand. This wizard does that for you:

  1. Users - choose the users to restrict.
  2. Folders - choose the folder(s) they should no longer be able to access.
  3. Review - the wizard works out which of each user's roles currently grant the restricted folder(s), and proposes a new, narrower role that keeps everything else they currently have - other folders, menu areas and schedules - just without the restricted folder(s). Check the plan, then apply.

Note: your default role is never changed by this - affected users are moved to a new role instead, so nobody else is affected. Because the new role lists folders explicitly, restricted users will not automatically get access to brand new top-level folders created later; add those separately if needed.

Duplicating an Existing Role or User's Access

Use this when you want to give someone the same access as an existing role or user, then tweak it - for example, a new starter who should have almost the same access as an existing team member.

  1. Source - choose to copy from an existing role, or from a user (which combines everything all of that user's roles grant them).
  2. Name - defaults to "Copy of <source>", but can be changed.
  3. Areas, Folders and Schedules - pre-filled from the source; add or remove as needed.
  4. Members - choose who should be in the new role. This starts empty; members are not copied from the source.
  5. Review - check the summary, then click Create.

The source role or user is never changed - this only ever creates a new role.

Reconnection

Reconnection

Reconnection

timed out

timed out

Attempt of

Reload
An unhandled error has occurred. Reload 🗙