Introduction

Managing user access and permissions efficiently is vital for maintaining the integrity and security of the administrative functions on SCVIEW. This guide facilitates the proper handling of user roles, from creation to customization, ensuring administrators have clear and structured steps to manage these processes effectively.


A. Problem statement

Overseeing individual user permissions can be inefficient and prone to errors, especially without a streamline process for setting up user accounts and defining roles within an organization.


B. Solution

SCVIEW addresses these concerns by providing a robust User Manager Page that allows admins to add or edit user permissions seamlessly. This platform supports a range of authentication types and fine-grained control over permissions, streamlining administrative tasks and enhancing security protocols.


Step 1: Ensure Admin Access

  • Ensure you have Admin permissions to access user settings. Contact your organization's site administrators if access is needed.

Step 2: Access User Manager

  • Click Admin > Users on the main navigation bar.

Step 3: Add or Edit Users

  • To add a user, click "Add". To edit an existing user, select the user and click "Edit".


Image: Users Action Button Bar


Step 4: Fill Required Fields

  • Complete all fields marked with a '*'. Choose the relevant Auth Type (Classic or SSO options like Google, Microsoft, OneLogin).


Image: Detail Tab

Step 5: Set User ID

  • For Classic Auth, use a combination like the first initial and last name (e.g., cstein). For SSO, use the user's email address.

Image: Auth Type Dropdown

Note: When using Google, Microsoft, or OneLogin as the Auth Type, you will need a 
valid email address or the system will not allow you to save the user. Format example: testuser@domain.com


Step 6: Password Management

  • If using Classic Auth, enter a temporary password and enable 'Force Change Password'. For SSO, password fields will not be available as authentication is managed by the third-party service.
Note: Passwords are validated against the requirements set by administrators. If the 
password is not considered valid, an error message will display listing each requirement 
that was not met.


Image: Detail Tab Password Reminder Text


Step 7: Select Home Screen and Rights

  • Home Screen - Designates the user's landing page upon logging into SCView.
  • Rights
    • Allow Admin - Gives the user access to the Admin section of the main navigation bar.
    • Allow Import - Gives the user access to online indexing capabilities.

Step 8: Department, Report, and Annotation Setup

  • Department - Departments added here become selectable values for the user when filling out Leave Requests, Time Sheets, and other module documents where Department matters.
  • Report View - Set a list of Departments. For each Department set, the user gains Unrestricted (ability to access the documents of others) permissions to documents with that Department. The user will still require other permissions to a specific document type in order to see and manipulate others' submissions.
  • Image Annotations - Upload images that the user can use in conjunction with the annotations feature. 


Image: Editing a User


Step 9: Group Setup

The Detail tab is complete. Click the Groups tab to continue setting up the user.


The Groups tab has a single purpose, which is to assign and unassign Groups for the user currently being edited. Groups are assigned permissions, much like a user; if a user is part of a Group, then it inherits the Group's permissions. This makes Groups a fast and easy way to set up permissions that need to be assigned in bulk.


Image: Groups Tab

Step 10: Doc Types Setup

The Groups tab is complete. Click the Doc Types tab to continue setting up the user.


Please note that the Doc Types tab does not display information while setting up a new user. If setting up a new user, consider Saving and then immediately Editing that user to make the Doc Types tab display information correctly.


The Doc Types tab displays every document type present in the database, as well as a grid of permissions to be applied to those document types.


Permissions

  • Search - The user has the ability to Search for the listed document type.
  • View - The user can view documents of the listed type. This is a foundational permission and is required to use the other permissions present.
  • Print - The user can print documents of the listed type.
  • Email - The user can email documents of the listed type.
  • Edit - The user can edit documents of the listed type.
  • Create - The user can create new documents of the listed type.
  • Append - The user can append pages to documents of the listed type. This is an extension of the Edit permission, and most applications of Append require that the user also have Edit.
  • Annotate - The user can apply annotations to documents of the listed type.
  • Delete - The user can delete documents of the listed type.
  • Unrestricted - The user can apply his other permissions for the listed document type to documents of that type created by other people. For example, Unrestricted + View + Print allows the user to see and print documents made by other people.


Image: Doc Types Tab

Step 11: Payroll Setup

The Doc Types tab is complete. Click the Payroll tab to continue setting up the user.


  • Employee ID - This is the user's Employee ID in USPS.
  • State ID - This is the user's state ID that is associated with state certifications.
  • IPDP Admin - If enabled, the user has IPDP Admin powers. Most notably, this includes the ability to add hours to an IPDP plan by fiat and the ability to assign multi-user activities. Both of these functions bypass the usual approval process.
  • Time Sheets - If enabled, the user can access their time sheet. If Manual Entry is enabled, then the user can edit the time sheet from that page. If Manual Entryis not enabled, then the user's only recourse is to use the punch clock function on MyDashboard.
    • Payroll Period - Set the payroll period that governs the user.
    • Overtime - Set whether the user has no Overtime, Weekly overtime, or Weekly + Daily overtime.
    • IP Filter - Restrict access to Time Sheets if the user is not on the input IP. This allows administrators to ensure that employees are at a specific location or using a specific tool to clock in.
  • Leave - If enabled, the user has access to the Leave module.
    • Leave Account Code Entry - The user can input account codes when making a Leave Request that includes associated costs.
    • Leave Input For Others- When enabled, gives the user the ability to create Leave requests for other employees in a Department in the user's Report View list; other user must have an Employee ID
    • Default Sub Required - Sets the default value of the Substitute Needed field in a Leave request (Yes = yes, No = no, and Unset = use the most recent choice)
    • Non-Contract Days - The maximum amount of non-contractual time off the user can take
  • Manage Employees - If enabled, the user has access to the Manage Employees module.
  • Manage Job Listings - If enabled, the user can manipulate job listings in the Hiring module.
  • Invite to SmartSub - Sends an invite to the user to be regular staff, a substitute, or both in SmartSub. Unusable when setting up a user.


Image: Payroll Tab


Step 12: FIS Setup

The Payroll tab is complete. Click the FIS tab to continue setting up the user.


  • Expenditure Accounts
    • Allow Over Budget - If enabled, the user can submit using an expenditure account that has insufficient funds.
    • Allow Balance View - If enabled, the user can see how much money is left in an expenditure account.
    • Show Account Code - If enabled, the user can see the account code for an expenditure account.
  • Expenses - If enabled, the user has access to the Expenses module.
  • Requisitions- If enabled, the user has access to the Requisitions module.
    • Approval List - Input specific vendors from the list of approved vendors if it is desired to limit the user to only those vendors listed.
    • Deliver To List - Input specific vendors from the list of approved vendors if it is desired to limit the user to only those vendors listed. 
  • Ext. Name / Ext. Password- Input the user's USAS credentials here. This is optional. If the user has Account Filters defined in USAS, this will carry those filters into SCView.
    • Test - Tests that the USAS credentials are correct.
    • Confirm Pass - Input the USAS password again here.
  • Home Vendor ID / Work Vendor ID - If a Vendor in USAS is input, it will show as a Home or Work location option when the user fills out a Mileage expense form.
  • Checks
    • AP - Set the visibility and printability of AP checks for the user.
    • Payroll - Set the visibility and printability of Payroll checks for the user.
  • AR Invoices- If enabled, the AR Invoices module is accessible.
    • Manage Customers - If enabled, the "Manage Customers" button displays on the AR Invoices page. It is used to add customers to the Available list when filling out an AR invoice.
  • Receipts- If enabled, the Receipts module is accessible.
    • Show Account Code - If enabled, the account code charged is visible.
  • Refunds - If enabled, the Refunds module is accessible.
  • Financial Dashboard - This sets the user's level of access in Financial Dashboard: User, Poweruser, or Admin. Admin is more powerful than PowerUser, which is more powerful than User. Please note that Financial Dashboard access operates under an accumulative design. When assigning access, give the user all levels of access under the top one being granted. For example, a PowerUser should also be given User access, and an Admin should be given everything.


Image: FIS Tab


Step 13: Save User Settings

  • Click "Save" to apply the settings. All changes must be saved to take effect.


C. Best Practices

To maintain an organized and functional SCVIEW environment, use consistent naming conventions for User IDs and systematically review user permissions regularly. Ensure authentication types match the user's workflow and security requirements, and always use the 'Force Change Password' feature for Classic accounts to enhance security.


D. Troubleshooting

If you encounter issues while adding or editing users, ensure that all required fields are properly filled and that there are no errors in the User ID or authentication type selections. For persistent problems or system errors, consult the SCVIEW support documentation or contact technical support directly for assistance.


E. Related articles

User Manager: Add and Edit


Conclusion

 The SCVIEW User Manager Page streamlines the process of adding and editing users, thereby enhancing the administrative efficiency and ensuring robust security management within the system. By following these guidelines, admins can effectively manage user access and permissions, adapting swiftly to the changing needs of their organization.