Creating and Editing User Roles for Disclosure Management

Last modified on 2024-02-14

Overview

Different user roles can be assigned for Lucanet Disclosure Management in the Lucanet CFO Solution Platform for each user who is activated for the solution. User roles define what permissions a user has for certain areas in Disclosure Management. For example, they allow you to assign role assignment permissions and read and write permissions for individual documents, or the permission to change the status of individual process steps.

Opening Role Management for Disclosure Management

Role Management can be opened via the function bar, and is displayed as follows:

Displays the Role administration functional area The 'Role Management' area
Types of User Role for Disclosure Management

The following different types of user role exist in Disclosure Management:

  • Global roles
    Global roles can be used to assign solution-wide, cross-document permissions, e.g. administrator rights for documents, import functions, system settings, and role assignment within Disclosure Management.
  • Document roles
    Document-specific roles can be used to assign permissions at the document level, e.g. read and write permissions for documents, chapters, periods and validations, or the permission to import data or change the status of individual process steps.

 

For a detailed description of the permissions and how to assign them by assigning individual roles to users, see the following chapters.

Before a user can be assigned a role in Disclosure Management, they need to be activated for Disclosure Management in the User Management section of the Lucanet CFO Solution Platform:

  • If a user is assigned the role of Administrator for Disclosure Management in the User Management section of the Lucanet CFO Solution Platform, this user will automatically receive the Global Administrator role within the Disclosure Management solution, together with all the associated solution-wide, cross-document administrator rights. At least one user with the Administrator role for Disclosure Management must be created.
  • If a user is assigned the role of User for Disclosure Management in the User Management section of the Lucanet CFO Solution Platform, this user will not receive any kind of special role at first. Different permissions can only be assigned to a user if they are first assigned a user role by a Global Administrator.
Managing User Roles for Disclosure Management

Role management is split into three areas: Users, Global roles and Document roles:

The Users area shows the users that have been activated for Disclosure Management in the User Management area of the LucaNet Cloud Platform (see Creating and Editing Users for the Lucanet Cloud Platform), together with the roles they have been assigned for Disclosure Management. The area is displayed as follows:

Displays the ‘Users’ workspace The 'Users' Workspace

This area serves as an overview, and cannot be edited. Users are assigned their individual roles in the Global roles and Document roles areas.

In the Global roles area, you can use predefined roles to assign solution-wide, cross-document permissions.

The workspace is displayed as follows: 

Displays the Global roles workspace The 'Global roles' workspace
Permissions for Global Roles

The permissions that can be assigned with a global role are listed on the right-hand column in the Role Permissions area.

The following permissions can be assigned with the available global roles:


Role

Permissions for the role


Global Administrator

  • ReadAllDocuments: Read all documents
  • EditAllDocuments: Edit all documents
  • DeleteAllDocuments: Delete all documents
  • ReadRoles: View roles
  • SettingsGlobal: Edit global settings
  • AssignGlobalRoles: Assign global roles
  • ImportAdministration: Manage data imports
  • AssignDocumentRoles: Assign document roles

If a user is assigned the role of Administrator for Disclosure Management in the User Management section of the Lucanet Cloud Platform, this user will automatically be assigned the role of Global Administrator.


Global­Document­­administrator

  • ReadAllDocuments: Read all documents
  • EditAllDocuments: Edit all documents
  • DeleteAllDocuments: Delete all documents

Global Settings­administrator

  • SettingsGlobal: Edit global settings

Documentrole Administrator

  • AssignDocumentRoles: Assign document roles
  • ReadAllDocuments: Read all documents
  • ReadRoles: View roles

Assigning Users a Global Role

To assign a global role to a user:

 

  1. In the Global roles column, select the user role you want to assign to a new user.
  2. In the Assigned users area, click +.
  3. In the displayed dialog, select the user you want to assign to the role.
  4. Save the settings.

 

In the Document roles workspace, you can use predefined roles to assign the following permissions:

  • Document-level permissions, e.g. read and write permissions for individual documents, chapters, periods and validations
  • Workflow-based permissions for changing the status of individual process steps within a workflow

 

The workspace is displayed as follows:

Displays the workspace ‘Document roles' The workspace 'Document roles'
Permissions at the Document Level and Workflow-Based Permissions

The permissions that can be assigned using predefined roles at the document level are listed in the Document roles area, in the right-hand column, under Role Permissions.

You can also view an overview of the permissions a user with the corresponding role has for changing a status within a predefined workflow. To do this, click the Info icon in the Workflow-based permissions area. 

Note: In LucaNet 24.1, only the default workflow is available. User-defined workflows will only become available with a later version of Lucanet.

The following permissions can be assigned with the available document roles:

Role

Permissions for the role


Document Admin­istrator

Document-level permissions
  • ReadAllChapters: Read all chapters
  • EditAllChapters: Edit all chapters
  • DeleteAllChapters: Delete all chapters
  • ReadAllExcelFiles: Read all Excel files
  • EditAllExcelFiles: Edit all Excel files
  • DeleteAllExcelFiles: Delete all Excel files
  • EditAllReportData: Edit all report data
  • ReadAllReportData: Read all report data
  • CommentReportData: Delete all report data
  • ReadAllWordFiles: Read all Word files
  • EditAllWordFiles: Edit all Word files
  • DeleteAllWordFiles: Delete all Word files
  • ReadAllDocument­Variables: Read all document variables
  • EditAllDocument­Variables: Edit all document variables
  • DeleteAllDocument­Variables: Delete all document variables
  • ChapterUnlocking: Unlock chapter
  • LayoutAction: Perform layout action
  • ReadPeriods: Read periods
  • EditPeriods: Edit periods
  • DeletePeriods: Delete periods
  • ReadAllLanguages: Read all languages
  • EditAllLanguages: Edit all languages
  • DeleteAllLanguages: Delete all languages
  • ReadAllValidations: Read all validations
  • EditAllValidations: Edit all validations
  • DeleteAllValidations: Delete all validations
  • StatusChangesFrom: Make status changes
  • StatusChangesTo: Make status changes
  • CopyDocuments: Copy documents
  • EditDocumentSettings: Edit document settings
  • ReadAllResult­Documents: Read all result documents
  • EditAllResult­Documents: Edit all result documents
  • DeleteAllResult­Documents: Delete all result documents
  • ResultDocuments­­FromOtherUser: Open other users’ result documents
  • ResultDocuments­History: Open result document history
  • ImportData: Import data
  • EditXBRLMapping: Create XBRL mapping
  • ReadDocument: Read a document activated for the user
  • EditDocument: Edit a document activated for the user
  • DeleteDocument: Delete a document activated for the user

 

Workflow-based permissions

The graphic below shows the permissions that are assigned to users with the Document Administrator ;role, irrespective of the current status of the document in the workflow:

 

Shows a graphic containing the workflow-based permissions for the Document Administrator role. The file types the user can access are displayed, together with the status changes the user can make within the workflow. Workflow-based permissions for the Document Administrator role

Document Data Importer

Document-level permissions
  • ReadAllChapters: Read all chapters
  • ReadAllDocument­Variables: Read all document variables
  • EditAllDocument­Variables: Edit all document variables
  • ReadPeriods: Read periods
  • EditPeriods: Edit periods
  • DeletePeriods: Delete periods
  • ReadAllLanguages: Read all languages
  • EditAllLanguages: Edit all languages
  • ReadAllValidations: Read all validations
  • EditAllValidations: Edit all validations
  • DeleteAllValidations: Delete all validations
  • CopyDocuments: Copy documents
  • ReadAllResult­Documents: Read all result documents
  • EditAllResult­Documents: Edit all result documents
  • DeleteAllResult­Documents: ;Delete all result documents
  • ResultDocuments­FromOtherUser: Open other users’ result documents
  • ResultDocuments­History: Open result document history
  • ImportData: Import data
  • ReadDocument: Read a document activated for the user

 

Workflow-based permissions

The graphic below shows the permissions that are assigned to users with the Document Data Importer role, irrespective of the current status of the document in the workflow:

 

Shows a graphic containing the workflow-based permissions for the Document Data Importer. The file types the user can access are displayed, together with the status changes the user can make within the workflow. Workflow-based permissions for the Document Data Importer role

Document Editor

Document-level permissions
  • ReadAllChapters: Read all chapters
  • ReadAllDocument­Variables: Read all document variables
  • EditAllDocument­Variables: Edit all document variables
  • ReadAllLanguages: Read all languages
  • EditAllLanguages: Edit all languages
  • ReadAllValidations: Read all validations
  • EditAllValidations: Edit all validations
  • DeleteAllValidations: Delete all validations
  • CopyDocuments: Copy documents
  • ReadAllResult­­Documents: Read all result documents
  • EditAllResult­­Documents: Edit all result documents
  • DeleteAllResult­Documents: Delete all result documents
  • ResultDocuments­FromOtherUser: Open other users’ result documents
  • ResultDocuments­History: Open result document history
  • ReadDocument: Read a document activated for the user
  • EditDocument: Edit a document activated for the user
  • ReadPeriods: Read periods
  • EditXBRLMapping: Create XBRL mapping

 

Workflow-based permissions

The graphic below shows the permissions that are assigned to users with the Document Editor role, irrespective of the current status of the document in the workflow:

 

Displays a graphic containing the workflow-based permissions for the Document Administrator role. The file types the user can access are displayed, together with the status changes the user can make within the workflow. Workflow-based permissions for the Document Editor role

Document Quality Manager

Document-level permissions
  • ReadAllChapters: Read all chapters
  • ReadAllDocument­Variables: Read all document variables
  • ReadAllLanguages: Read all languages
  • ReadAllResult­Documents: Read all result documents
  • EditAllResult­Documents: Edit all result documents
  • DeleteAllResult­Documents: Delete all result documents
  • ResultDocuments­FromOtherUser: Open other users’ result documents
  • ResultDocuments­History: Open result document history
  • ReadDocument: Read a document activated for the user
  • ReadPeriods: Read periods
  • EditXBRLMapping: Create XBRL mapping

 

Workflow-based permissions

The graphic below shows the permissions that are assigned to users with the Document Data Quality Manager role, irrespective of the current status of the document in the workflow:

 

Displays a graphic containing the workflow-based permissions for the Document Administrator role. The file types the user can access are displayed, together with the status changes the user can make within the workflow. Workflow-based permissions for the Document Quality Manager role

Document Reader

Document-level permissions
  • ReadAllChapters: Read all chapters
  • ReadAllDocument­Variables: Read all document variables
  • ReadAllLanguages: Read all languages
  • ReadAllResult­Documents: Read all result documents
  • EditAllResult­Documents: Edit all result documents
  • DeleteAllResult­Documents: Delete all result documents
  • ResultDocuments­FromOtherUser: Open other users’ result documents
  • ResultDocuments­History: Open result document history
  • ReadDocument: Read a document activated for the user
  • ReadPeriods: Read periods

 

Workflow-based permissions

The graphic below shows the permissions that are assigned to users with the Document Reader role, irrespective of the current status of the document in the workflow:

 

Displays a graphic containing the workflow-based permissions for the Document Administrator role. The file types the user can access are displayed, together with the status changes the user can make within the workflow. Workflow-based permissions for the Document Reader role
Assigning Document Roles to Users

To assign a document role to a user:

  1. In the Document roles column, select the user role you want to assign to a new user.
  2. In the Assigned users area, click +.
  3. In the displayed dialog, select the following items:
    • The User and the Role you want to assign to them
    • The Document year for which you want to assign the role, where applicable.
      Notes:
      • Once you have selected a year, the document list that follows will only show documents whose reporting date is in the selected year.
      • If you do not select a year, all the available documents will be displayed.
  4. In the document list, select the document(s) for which you want to assign the role to the selected user.
    Note: To make it easier to find the document, you can enter the document name in the Document Name field. 
  5. Save the settings.