Skip to main content

Restrict access by entity

Version note: Source material dates from 6 July 2022 and shows GMS v2.1.0. Navigation and permission names may differ in newer versions.

Access Control: Overview · Create and manage roles · Assign roles to users · Restrict access by entity · Permission catalog


Entity restrictions narrow accounts and locations visible to user. They never grant actions; assigned roles still authorize actions.

Training video

Download original MP4 — Configure entity restrictions

Restrict access by entity

Entity restrictions narrow accounts and locations visible to user. They do not grant actions; assigned roles still control allowed actions.

Account restrictions

  1. Open user and select Entity Restriction.
  2. Select Accounts.
Account entity restrictions
Account entity restrictions — GMS v2.1.0
ModeEffect
AllowUser may access only selected accounts.
RestrictUser may access every account except selected accounts.
DisabledNo account restriction; user may access all accounts permitted by roles.
  1. Choose operating mode.
  2. Select accounts included by that mode.
  3. Select Save.

Example: To allow only Greenwald Midwest and Greenwald South, choose Allow and select those two accounts.

Location restrictions

  1. Select Locations.
  2. Choose account whose locations should be configured. Account list remains complete so restrictions can be prepared before account becomes available to user.
Select account for location restrictions
Select account for location restrictions — GMS v2.1.0
  1. Choose Allow, Restrict, or Disabled. Modes behave same as account restrictions.
  2. Select locations included by chosen mode.
Location entity restrictions
Location entity restrictions — GMS v2.1.0
  1. Select Save.

Effective access

Effective access = combined role permissions, limited by account and location restrictions.

For example, user with Reports permission restricted to two accounts may run reports only for those accounts. Entity restrictions are optional; role assignment is mandatory.

Do not assign Admin broadly. Admin permits destructive actions and should remain limited to trusted, verified administrators.