Access Control
Version note: Source material dates from 6 July 2022 and shows GMS v2.1.0. Navigation and permission names may differ in newer versions.
Access Control: Overview · Create and manage roles · Assign roles to users · Restrict access by entity · Permission catalog
GMS access control determines both what a user may do and where the user may do it.
| Control | Purpose | Required? |
|---|---|---|
| Roles | Combine permissions that authorize actions. | Yes. Every user must retain at least one role. |
| Entity restrictions | Limit accessible accounts and locations. | No. Apply when user scope must be narrowed. |
Effective access = combined role permissions, limited by account and location restrictions.
Training video
Choose a task
- Create and manage roles — create, edit, clone, or delete roles.
- Assign roles to users — add or remove roles and understand combined permissions.
- Restrict access by entity — limit accounts or locations with Allow and Restrict modes.
- Permission catalog — reference permission groups from 2022 source.
Security guidance
- Grant only permissions and entity access required for user’s job.
- Reserve Admin for verified administrators.
- Review effective access after assigning multiple roles.
- Test changes using non-production or demo customer data before production rollout.