The UTA/Module Security Matrix controls how users interact with records in a UTA/module and its associated entities, defining what each role can deny access, view, add, edit, delete, or assign at every data level: Level 1, Level 2, and Level 3.
Rather than giving all users the same access, the UTA/Module Security Matrix lets you tailor permissions by role. For each role, you can configure access independently at each level, so a user might have full access at Level 1 but view-only access at Level 2. You configure the UTA/Module Security Matrix for a UTA/module in three parts: enable the feature, assign access roles, and set role-based permissions at each data level.
Who: Global administrators
When to Use the UTA/Module Security Matrix
Use the UTA/Module Security Matrix when:
- When different user groups need different levels of access to records within the same UTA/module.
- When you need to control which users can view, add, edit, delete, or assign records based on their role.
- When some users should see only records they own or are assigned to, while others need broader access.
Enable the UTA/Module Security Matrix
Before configuring permissions, the UTA/module must be created and the UTA/Module Security Matrix feature enabled.
- Click the Menu icon in the upper navigation bar, and then select the relevant UTA/module from the Applications drop-down menu.
- Click the Configuration Settings gear.
- Click the Security tab.
- Toggle Enable Security Matrix on, and then click Save.
Set Access Role Permissions
Only roles listed in the Access Role Settings box appear in the UTA/Module Security Matrix. Roles must be selected in Access Role Settings before permissions can be configured for them.
- On the Security tab, locate the Access Role Settings box.
- Select the relevant roles that should have access to the UTA/module.
- Click Save.
- Click Security Matrix. The Security Matrix window opens.
Configure Level Permissions
The UTA/Module Security Matrix has a separate tab for each data level (Level 1, Level 2, and Level 3). Configure permissions at each level independently. The same set of roles appears on every tab.
- On the Level 1 tab, configure the permissions for each role. For each role, select the appropriate engagement type (All, Owner, Assigned, Organizations, or Person) for each permission column (Deny, View, Add, Edit, Delete, or Assign).
- Click Save.
- Click the Activity Access tab (Level 2).
- Configure the same set of roles and permissions for Level 2 items.
- Click Save.
- Click the Activities tab (Level 3).
- Configure the same set of roles and permissions for Level 3 items, and then click Save.