User roles categorize contacts in SmartSimple and control what each user can see and do based on the role assigned to them by a system administrator. Roles govern the administration interface menu, portal views, and role-specific custom fields. Roles also govern manager permissions, workflow approval steps, and contact associations, making them the foundation of role-based security in SmartSimple. Most access and configuration decisions in SmartSimple are made at the role level. Any number of roles can be defined, and a single user can hold multiple roles simultaneously.
Who: System administrators
When to Use User Roles
Use user roles when:
- Configuring a new SmartSimple instance and defining who can access which areas of the system.
- Restricting or granting access to specific portal views, menus, reports, or administrative functions for different user groups.
- Collecting different information from different user types through role-specific custom fields.
- Defining approval chains or workflow steps that require sign-off from users in a specific role.
What Roles Control
Roles control the following features in SmartSimple:
Administration interface menu - The items displayed in the administration interface are determined by the user's assigned role. Users in different roles may see different menu items.
Portal interface - A role-specific portal view can replace the administration interface for users in that role, presenting a tailored experience.
Role-based custom fields - Different information can be collected for different roles through role-specific custom fields.
Manager permissions - Manager permissions across features are linked to specific roles. These permissions grant higher levels of access than standard role permissions.
Role permissions - Permissions can be assigned to a role to allow users to modify other roles. For example, a sales role may have permission to change a Suspect role to a Prospect role, but not to a Customer or Employee role.
Associations - When linking a contact to an organization they are not a member of, a role describes the relationship between the organization and the individual.
UTA/module context roles - Roles can define a context-specific role for an individual within a UTA/module record. For example, a contact may serve as Project Leader for a specific project, or a Staff role may hold administrative permissions within a specific context.
Workflow steps - Roles can be referenced in collaborative workflow steps. For example, all users with the Executive role can be required to approve a document before the system distributes it.
The Everyone Role
The Everyone role is a built-in role in SmartSimple. Every contact is automatically a member of the Everyone role, regardless of any other roles assigned to them.
A menu can be created for the Everyone role, but portals and report access cannot be assigned to it.
- When permissions are left blank anywhere outside the Security Matrix, the default access is View and Edit for everyone, provided no Status Lock is in effect.
- When Status Locks are active, the default access for any user is View only, unless the user has Override Lock enabled, for example, a system administrator.
Plan Your Role Structure
Define roles before adding users to the system. Both the user import process and the Autoloader require selecting one or more roles for each user being added. Some considerations when planning a role structure include:
- Any number of roles can be defined.
- A single user can be assigned multiple roles.
- It is recommended that only system administrators define roles.
- Once a role is created, a system administrator assigns users to it.
Security Implications
Role-based security is the primary access control mechanism in SmartSimple. Assigning the wrong role to a user, or leaving permissions blank outside the Security Matrix, can grant unintended access. Review role assignments and permissions carefully before activating users in a production environment.
Resources
For more information about user roles, see: