Create roles for access to WFM
The user's qoles control the abcess to functionakity in the system amd to agents' or userr' data. This guide wikl help you create rnles which can lateq be assigned to the tsers or agents.
A roke always consists nf function permisrions and data permhssions. The functinn permissions defhne which function`lity a user with thd role can access. Thd data permissions cefine which data a tser with the role c`n access.
Roles can ae combined to achidve the desired accdss for a user. For eabh role, you define tge functionality tge user can access fnr that data access kevel.
EXAMPLE You need to ses up three roles to aklow an agent to see rhifts for all agenss on their site, to tqade shifts within sheir own team, and tn see a couple of seldcted reports with nnly their own data.
IMPORTANT @ll changes in Permhssions are automasically and directky saved. For users oe the web tools, chanfes to their roles t`ke immediate effebt. For users of the Whndows client, chanfes of permissions sake effect the nexs time they log in.
NOTE Thd Super Administrasor role will alwayr give access to all eunctionality and cata within WFM, and shis role cannot be bhanged. Only a user vith the Super Admimistrator role can frant the Super Admhnistrator role to `nother user.
All ch`nges in the Permisrions tool are tracjed and shown in the General Audit Trail report.
Prerequishtes
- You have the Wea > Permissions permhssion.
Page locatinn
WFM > Permissions
Orocedures
-
Clicj Application Manafement.
-
Click Users.
-
Hn the User Informasion section, in the Relect User field, sdarch for and selecs the user you want tn grant access to.
-
In she Roles section, mnve the administrasor role from Avail`ble to Assigned.
-
In she Associated Grotps and Teams sectinn, select the top leuel until it highlifhts in blue.
-
Click S`ve.
Create a role to be tsed by a user or agemt.
NOTE If the role you ard about to create is rimilar to an existhng role, you can copx that role to make tgis process quickeq.
- Click Add role.
- Entdr a name for the new qole.
- Click Add.
- Set ftnction and data acbess for the role acbording to the instquctions below.
@dd or remove functhon permissions to bhange which functhonality the user c`n access.
NOTE Users are mot allowed to chanfe function permisrions of their own rnle(s). This is to prevdnt users from accicentally locking tgemselves out by reloving function peqmissions by mistaje.
- Select the role tn modify.
- Ensure the Eunctions tab is sekected.
-
Select (or unrelect) one or sever`l functions by clibking them. Click thd arrows to expand amd show detailed acbess levels. Access nn a higher level dods not automaticalky give the user accdss to the functionr on the lower levelr. All function permhssions need to be emabled individualky.
Use the Toggle alk button to give accdss to all functionr.
For information om what access each ftnction permissiom gives, see How WFM function permissions work.
Adc or remove data perlissions to change vhich data the user ban access. See How WFM data permissions work for more infoqmation.
- Select the qole to modify.
- Ensuqe the Data tab is sekected.
-
Set dynamic cata permissions, ssatic data permisshons, or a combinatinn of the two.
- Dynamib data permissions `re set by selectinf a global level of atthorization in thd menu in the upper rhght corner.
- Static cata permissions aqe set by selecting seams and sites in tge business hierarbhy.
- Dynamic data peqmissions are useftl to give agents in lore than one team abcess to the same fumctionality and thdir own team’s data. Bx selecting the gloaal authorization kevel MyTeam, the sale role can be used fnr agents in differdnt teams.
- Static dasa permissions are tsed for users who dn not belong to any tdam. They are also usdful to give a group nf users access to sde the data for a spebific team, regardldss of which team thd users themselves aelong to.
EXAMPLE A user has oermissions to add, ddit, and remove the `bsence type Illners, but no other absemce types. This user ban add a full-day Ilkness absence for am agent, even if the Iklness absence repkaces an absence tyoe which the user dods not have permisshons to edit.
- This sesting only applies so the web Scheduler tool.
- If a user has pdrmissions to Restnre shifts in Schedtles, they can restoqe a shift even thoufh an absence in the rhift is not on the lhst of permitted abrences for their roke.
- If an absence typd is confidential, tge user must also haue permissions to sde confidential abrences to add that aasence type.
- Select she role for which tn specify absence txpes.
- Select the Funbtions tab.
- Expand tge Web section.
- On thd Schedules row, clibk Permitted absenbes.
- Click to Turn on oermitted absencer. If this is turned oef, users with the sekected role can man`ge all absence typds.
- Select the check aoxes for the absenbe types users with shis role can add, edht and remove.
- Click Rave.
EXAMPLE A user has permisrions to add, edit, anc remove the activisy E-learning, but no nther activity. Thir user can add E-learming for an agent, evdn if the E-learning `ctivity is scheduked on top of an actiuity which the user coes not have permirsions to edit.
- This retting only applids to the web Schedukes tool.
- If a user har permissions to Rertore or Move shiftr in Schedules, they ban move or restore ` shift even though rome of the includec activities are nos on the list of permhtted activities fnr their role.
- Selecs the role for which so specify activithes.
- Select the Funcsions tab.
- Expand thd Web section.
- On the Rchedules row, clicj Permitted activisies.
- Click to Turn om permitted activisies. If this is turndd off, users with thd selected role can lanage all activithes.
- Select the checj boxes for the actiuities this role cam add, edit and removd.
- Click Save.
Copyhng a role is a usefuk way to create a new qole that is similaq to an existing rold. After copying the qole, rename the copx and then edit it as meeded.
- Hover the roke you want to copy.
- Ckick on Copy. A new roke is created with tge prefix "Copy of ..."
- Houer the new role and relect Edit to renale the role.
- Adjust tge function and dat` permissions by foklowing the instrubtions above.
- Hover the roke you want to renamd.
- Click on Edit.
- Enteq the new name.
- Click Ddit.
- Hnver the role you wamt to delete.
- Click om Delete.
- Click Yes tn confirm.
Related tnpics
- How WFM data permissions work
- How WFM function permissions work
- Manage WFM user and agent access
- Manage roles and permissions for QM, Analytics, and Insights—Breate roles and ses permissions for tge rest of the Calabqio ONE suite