Department-Based Administration Permissions
Summary
Allow administration permissions to be assigned or restricted by Department in addition to the existing Location-based permissions.
Current functionality
OnLocation user roles determine what a user can and cannot do within the application. For many administration roles, access is then controlled by Location.
The current permission model can therefore be understood as:
User Role = what the user can do
Location = where the user can do it
For example, an Administrator can be assigned as either:
Global – manage all locations in the account
Limited – manage only the locations assigned to them
A similar Global/Limited structure is used across a number of other roles, including Induction Manager, Reports Manager, Sign In/Out Manager, Triggers Manager, Identity Manager and OnPass Manager.
Reference: Employee user roles explained — MRI OnLocation Help.
Customer pain point
This Location-based structure works well when a location represents the appropriate level of responsibility. However, some organisations have multiple departments operating within the same OnLocation location.
For example, a single site may contain:
Operations
Maintenance
HR
Warehouse
A manager may be responsible only for Operations, but if Operations and the other departments are all configured under the same OnLocation location, the current permission model does not provide a further Department-level restriction.
As a result, assigning an administration role to that location may provide access more broadly than the manager actually requires.
This can make it difficult for organisations to delegate administration to individual department managers while maintaining appropriate separation of access.
Requested functionality
Consider extending the existing Location-based permission model to support Department-level permissions where appropriate.
The desired structure would be:
User Role → Location → Department
For example:
Induction Manager → Main Site → Operations
This would allow an organisation to give an Operations manager the appropriate administration role while restricting their access to the relevant department within the location.
The intention is not to replace Location-based permissions, but to provide an additional level of granularity for organisations where Location is too broad a boundary for their operational structure.
Reference: 07345540
-
Jenny Nabunat
commented
Further addition from the case info:
Benefits would include:
Department managers and supervisors could send and monitor inductions for their own teams.
Access would be limited to their department rather than the entire site.
Improved accountability and ownership of departmental inductions.
Easier reporting and audit preparation, as departments could manage and review their own induction records.
Reduced reliance on a small number of site-wide administrators.