Section | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Excerpt | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Access Control List User Interface
Open the Access Control wizard by
Form designers as well as users with the publisher role are authorized to configure access control. The Access Control wizard makes the following permissions available for forms/flows:
Dynamic ACLsTemplates provide the ability to dynamically determine and restrict access to submissions/ task audit trails when assigning Access Control permissions. Templates are like variables in your form that can be filled in by the user, populated by a business rule or from a back end system. Any item on the Access Control screens contained in curly braces is a form template and will be replaced with the value of the associated control. For example, the list below contains a fixed role (reviewer) and one dynamic template based role - {AcctMgrRole} : In the example discussed below, templates are used to navigate the flow to the correct employee in the Accounting department and to define user lists to dynamically control access.
Who can start the form/flowSetting this permission determines who is allowed to create form/flow submissions. The choices for Form/Flow visibility are:
Who can edit the form/flow
Form and flow owners (designer users that created the form/flow) can give other users (designers/non-designers) the capability to edit form/flows. This is particularly helpful if a designer user takes a leave of absence or leaves the company. The "backup designer" has the ability to make changes to the form/flow without having to download the form/flow(s) from the owner's account to the backup designer's account. The "backup designer" also can view related submissions by clicking on the Submission or Legacy Submission icons. The ability to edit submissions is granted by a different permission.
Users given this permission access the shared form/flow from the Shared Items tab even if they have the frevvo.designer role assigned to them. They can only edit the form/flow that was shared with them. They will not have the ability to create new forms/flows from the Shared Items tab. The ability to make changes to a form/flow is not available from Shared Items on the Important Items menu in a space. To assign users the ability to edit forms/flows, follow these steps:
Users that have been granted the editing permission, access forms and flows that have been shared with them via the Shared Items tab on their Home Page. It will not work from the Shared Items selection in a Space or any other embedded scenario. The Who can edit the form/flow permission does not apply if you are running with Confluence. Confluence users share form/flow editing by specifying the Forms Editor group on the /wiki/spaces/frevvo91/pages/901493435 screen. Users who will be sharing the editing function must be assigned to the specified group. A browser notification message displays if the user who has been granted permission to edit forms/flows tries to modify their own ACL. will not allow the "backup designer" to remove themselves from the ACL list. Who can view submissionsThe designer can assign permission to view form/flow submissions to specific roles/users. Any user with view access can view submissions in read-only mode. Submission deletion is not allowed. Templates can be used to dynamically determine at runtime which users and roles are allowed to view submissions. To assign permission to view submissions, follow these steps:
Who can edit submissionsThe designer can assign permission to edit form/flow submissions to specific roles/users. Any user with edit access can view, edit and delete submissions in the SUBMITTED, ABORTED or ERROR states. Submissions in the PENDING, SAVED or WAITING states can only be deleted by the tenant admin, flow admin or designer user that created the flow. Refer to the Deleting Submissions for more information. Templates can be used to dynamically determine at runtime which users and roles are allowed to edit submissions. To assign permission to edit submissions, follow these steps:
Who can access the audit trail - Flows OnlyThe audit trail is accessed on a user's Task List by clicking the View Task History icon. Roles/Users granted this permission will see theView Task History icon on tasks in their task list. To assign permission to view the audit trail, follow these steps:
Who can administer the flow - Flows OnlyThis permission lets a user abort, reassign and reset tasks that are not assigned to them. These administrative tasks are no longer restricted to tenant admins. The designer can delegate these tasks to additional users/roles by assigning them in the Who can administer the flow section of the Access Control dropdown. Any user/roles listed here will be considered a Flow Administrator. As such, the Modify Task icon on a task in the task list will be displayed. Tenant admins and designer users get the Modify Task icon by default. To assign user/roles as Flow Administrators, follow these steps:
User jerry has been designated as a flow administrator for the Expense Report but not for the Time Sheet workflow. When Jerry logs into , his task list will appear as shown: The Modify Task dialog allows a 'flow admin' to execute any one of abort/reassign/reset functions. When searching for tasks, if a flow is chosen, and the user is a flow admin for it, then all tasks for that flow display. If no flow is selected, then all tasks, even those that the flow admin has not participated in, plus tasks for which the user is a flow admin will display. |
Shared Items
Submissions
All users granted Submission Access, either by user id or because they have a granted role, will see the Shared Item tab on their Home Page. Click on the Action menu and select Submissions or Submissions (legacy) icons to view/edit them.
...
The functions needed to edit forms/flows are only displayed when users given the permission access the Shared Items tab from their Home Page if they are a designer or by clicking the icon on the Task List. The ability to make changes to a form/flow is not available from Shared Items on the Important Items menu in a space.
Warning |
---|
Just a reminder, edit permissions should not be given for production forms or flows. Please see the Admin Best Practices Guide. |
The functions provided to edit forms/flows from the Shared Items tab, do not include the option to delete or copy them. Deletion of a form/flow is not available to the "backup designer". Forms/flows can be copied by the download/upload functions. The backup designer has the ability to run the Refresh Searchable Fields process to update previous submissions with changes made to Searchable Fields by clicking on the Action Menu and selecting Refresh Search Fields. This process can be run for a for a particular form or flow.
...
The designer for the company creates an Expense Report workflow that displays the Expense Report form as the first step, then routes the request to the employee's manager (Jerry). If Jerry approves the expenses, then the workflow is routed to Sue, Jack or Jill based on the project category.
...