Security Settings in the Security tab of the Universal Tracking Application (UTA)/module Configuration Settings configure access control for the entire UTA/module, including visibility, administrator access, and advanced role-based security at the record and field level.
Security Settings
Security Settings control the Security Matrix and related association-based access rules for Level 1, Level 2, and Level 3 records.
| Setting | Description |
|---|---|
| Enable Security Matrix | Activates advanced access control, enabling granular control over how different roles interact with Level 1, Level 2, and Level 3 records. Opens the Security Matrix configuration interface. |
| Use Association Roles for Activity and Level 3 Activity when Security matric is enabled | When the Security Matrix is enabled, uses a contact's association role, rather than their system role, to determine record access at Level 2 and Level 3. |
| Use Activity Contact/Company Association for Security Matrix | Evaluates the contact or company associated directly with the Level 2 record, rather than inheriting from the Level 1 association. |
| Use Level 3 Activity Contact/Company Association for Security Matrix | Evaluates the contact or company associated directly with the Level 3 Activity record, rather than inheriting from the Level 1 association. Same as the Level 2 equivalent, applied at the Level 3 level. |
| Enable Association Role Field Access | Uses association roles, rather than system roles, to determine field-level access. |
| Enable Contact Association Filter | Controls which associated contacts are visible to a user based on their association role. Reveals a Contact Association Filters configuration link. |
| Enable Organization Association Filter | Controls which associated organizations are visible. Reveals an External Record Association Filters configuration link. |
| Enable Email Role Restriction | Restricts who a user can email within the UTA/module based on their role. Reveals an Email Restriction configuration link. |
| Disable "Roles That Can Set Status" Restriction | Allows workflows or submit buttons to bypass status security settings. Use with caution. |
| Feature and Function Permissions | Configure visibility and access for specific UTA/module features (for example, copy, delete, import buttons) by role. |
| Field Permission Matrix | Configure read/write/hidden access to custom fields per role and per status combination. |
| Inherit Level 1 Status Lock | Whether Level 2 and/or Level 3 records inherit the status lock from their parent Level 1 record. Options are Disabled, Level 2 Only, or Level 2 and Level 3. |
Role Permissions
Role Permissions are multi-select role pickers that grant specific capabilities to chosen system roles.
| Setting | Description |
|---|---|
| Application Access | Roles that can see and use this UTA/module. If a role is not listed here, the UTA/module will not appear in their navigation menu. |
| Administrator Access | Roles with administrative configuration access within this UTA/module. |
| Override Type Branch Restriction | Roles that can bypass type-branch restrictions when navigating records. |
| Edit Timesheet Rate | Roles that can edit billing rates on timesheet entries. Visible when Professional Services is enabled. |
| View Timesheet Rate | Roles that can view billing rate information on timesheets. |
| Anonymize Record Lock Owner | Roles for which the identity of the record lock holder is hidden from other users. |
| Override Record Lock | Roles that can force-unlock records currently locked by another user. |
| Level 1 Creation on Organization Profile Access | Roles that can create Level 1 records from the External Record profile. Requires that feature to be enabled on the Level 1 tab. |