User Rights on Entity dimension
application database > User Rights > Restrictions
Entity and task setup¶
Rights on the Entity dimension are defined by organisational hierarchy. Users may have different rights for different data collection processes affecting the following :
- on Entities and nodes: they allow the administrator to define, for each user, the Entities/nodes for which data can be viewed and/or entered and submitted.
- on tasks: they allow the user, for the Entities they are enabled on, to perform only the assigned tasks (e.g. entering data in a specific form, executing a certain data processing etc.). For more details on Entity-specific workflow, see Business Workflow concepts.
Entity dimensions permission are defined according to the logic that any editable/submittable Entity/node is automatically also visible. So:
- whatever activity a user may perform on an Entity, its visibility is automatically implied.
- whatever activity a user may perform on a node, visibility of the node and all underlying Entities is automatically implied.

IMPORTANT: By default, a new user is restricted on Entities (i.e., they have no viewing rights on any Entity) and unrestricted on tasks. The administrator can later assign specific task-level restrictions within Workflow Models, in accordance with the limitations defined at the Entity level.
Rights definition
Entity rights can take the following values:
| Value | Description |
|---|---|
| Unrestricted in insertion, submission and display | The user can enter data and/or submit each Entity and node that is part of the current process. They also have visibility rights for all Entities in the elements list. Note With this setting, it is not necessary to specify restrictions for each organizational hierarchy involved in a data collection process. |
| Restricted | Default value. The user only has viewing and possibly data entry and submission rights on the Entities and nodes indicated in the Entity Rights window, which can be reached via the Define link. It is also possible to define submission and/or operational tasks that the user can manage. Additionally, workflows and steps the user is allowed to work on can be defined. |
| By Area profile | The user's restrictions match those of the set Area Profile. |
| Restricted in insertion and submission, but not restricted in display | - The user has data entry and submission rights only on the Entities and nodes specified in the Entity rights window. - These restrictions do not affect data visibility. |
| Restricted in Insertion, Submission or Display by Area profile | The user has data entry and submission rights only on the Entities and nodes specified in the Entity rights window. The visibility rights on the user's Entities match those of the Area Profile. Note It is possible to further restrict the visibility rights of a user who inherits the area profile. In this case, the system will intersect the Entities of the Area profile with those defined in the window accessible by the Define link |