Skip to content

Role Management


If you need to set different system access permissions for employees to achieve permission isolation, you can use the Role Management feature. Role Management provides an intuitive entry for permission management, supports customizing the permission scope of each role, creating new roles, and assigning permissions to roles to meet the permission needs of different users.

Default Roles

If different teams in an enterprise need to view or operate different functional modules, you can invite members to join the current workspace and assign them role permissions, thereby controlling the Guance functional modules that members can access and operate on.

The system provides four default member roles by default:

  • Owner

  • Administrator

  • Standard

  • Read-only

Default roles cannot be deleted, and their permission scopes cannot be changed.

Permission Description

For the permission scopes of different default roles, refer to the document Permission List.

  • Owner: The owner of the current workspace, who has all operation permissions in the workspace and can adjust the role permissions of other members. If the granted role permission includes "Token View", it will trigger the authorization review process.

  • The workspace creator defaults to Owner;

  • A workspace can only have one Owner;

  • Owner cannot leave the workspace;

  • Owner can transfer permissions to a workspace member. After successful transfer, the original Owner is downgraded to Administrator.

  • Administrator: The administrator of the current workspace, who has read and write permissions in the workspace and can adjust the role permissions of other members except the Owner;

  • Standard: The standard member of the current workspace, who has read and write permissions in the workspace;

  • Read-only: The read-only member of the current workspace, who can only view data in the workspace and has no write permission.

Custom Roles

In addition to the default roles, you can create new roles in Role Management and assign permission scopes to roles to meet different permission needs.

  1. On the Management > Role Management page, click "Add Role";

  2. Define the role name and description;

  3. Check the functional permission scope;

  4. Save.

Note

Custom roles can only be created by Owner and Administrator.

Manage Roles

You can perform the following operations on custom roles:

  • Export the permissions of all roles as a list;

  • Edit and adjust the permissions of a role;

  • If the role is not associated with any member account, it can be deleted;

  • Clone an existing role to create a new role;

  • Based on the permissions of an existing role, cloning the role can reduce the steps and quickly add or remove permissions to create a new role.

  • Click any custom role to view its details, including the role name, creation/update time, creator/updater, description, and role permissions;

  • Click the edit button on the right side of the role name above to modify the role permissions;

  • In the role list, you can turn on the "Show only enabled permissions" switch.

Associate Data Access Rules

Roles are used to define the operations that members can perform, and data access rules are used to define the data scope that members can view. They are still independent resources. To reduce cross-page configuration, a Data Access Rules column is added to the right of the Members column in the role management list. Both default roles and custom roles will display the number of currently associated rules.

  • Click or hover over the rule count to select Edit or Jump to Data Access; the same operation is available when the count is 0;

  • Selecting Edit will open the "Associate Data Access Rules" drawer on the right side of the current page. You can search for rule names, view rule information by page, and check or uncheck the rules associated with the current role;

  • After saving, the system only updates the association between the role and the data access rules, and does not modify the rule name, data type, filter conditions, or field masking configuration;

  • Selecting Jump to Data Access will enter the data access page with the current role filter condition automatically applied;

  • Deleted data access rules will not be counted in the rule count.

Permission Description

Viewing the rule count and rule details requires both role view and data access view permissions; editing and saving the association requires data access management permission. Without data access view permission, the rule details will not be returned, and the page will display -- or hide the column according to the permission specification.

Permission Change Review

When setting role permissions for workspace members, if the granted role permission includes "Token View", the system will send verification information to the GuanceBilling Center and initiate a permission change review process.

  • If the Billing Center accepts the verification, the permission change is successful;

  • If the Billing Center rejects the verification, the permission change fails, and the original role permissions are retained;

  • If the Billing Center has not reviewed the request, you can change the member to another role. After the change is successful, the original permission change review request becomes invalid.

Warning
  • Currently, only Owner and Administrator have the "Token View" permission. If a member of a Commercial Plan workspace needs to be upgraded to Administrator, they must go to the Billing Center for review;

  • Members of a Free Plan workspace can be directly upgraded to Administrator without going to the Billing Center for review.

Upgrade to Administrator in Commercial Plan

  1. Go to Management > Member Management;

  2. Select the member to be upgraded to Administrator;

  3. Click the Edit button on the right, and in the pop-up dialog, select Administrator;

  4. Confirm.

The system only supports the Owner and Administrator roles to grant Administrator permissions to members of the current workspace. Only the Owner role can approve Administrator permissions in the Billing Center.

If you are an Administrator of the current workspace and want to upgrade a member, you need to notify the Guance Billing Center administrator to log in to the Billing Center for operation;

If you are the Owner of the current workspace, you can directly click Go to Billing Center for Review to operate without logging in to the Guance Billing Center.

In the member management list, you can view all members whose Administrator role has not been approved. Click the icon on the right of the member role, and in the prompt dialog, click to go to the Billing Center for review.

Permission List

You can set permissions for custom roles in the workspace.

For more details, refer to the document Permission List.

Feedback

Is this page helpful? ×