Organization Roles

An Organization Role is a named set of permissions. What a user may do in your Organization is decided by the role they hold, so a role is how you give somebody permissions.

Two users doing the same job hold the same role. When the job changes, you change the role once and it changes for everyone holding it.

Seeing your roles

  1. Go to your Organization home page.

  2. Click the "Organization Roles" card.

You will see the roles for your Organization and how many users hold each one.

Adding a role

Click "Add Organization Role". You will be asked for:

Name

What the role is called. Names must be different from each other within your Organization. Choose something that says what the person does, such as "Study Builder", rather than listing the permissions.

Description

What the role is for, so that somebody choosing a role knows which one they want.

Permissions

What holders of the role may do. These are grouped as Administration, URLs, Reporting and API.

A new role is held by nobody until you give it to somebody on the Organization team page.

Changing a role

Open the role from the list to change its name, description or permissions.

Important

Changing a role's permissions changes what every user holding it can do, straight away. The Users tab shows who that is. If you want to change one person only, put that person on a different role instead.

You cannot remove "Administer Permissions" from a role you hold yourself. Doing so would take the permission away from you at the same moment, and no page would be left that could give it back. Ask another administrator, or move yourself to a different role first.

Deleting a role

A role that nobody holds can be deleted. A role somebody holds cannot: move its holders to another role first. The Users tab shows who holds it.

The permissions

Permission

What a holder may do

Administer Permissions

Change the Organization permissions of users here, including their own. This does not give any of the other Organization permissions; a holder who needs one gives it to themselves. It does give access to every URL in the Organization, so that the person who manages permissions can reach the URLs they are managing them for.

Manage Import Scripts

Create, change and delete Import Scripts.

Manage Icons

Add and change the Organization's Icons.

Create URLs

Create URLs and Vaults for the Organization.

Delete URLs

Delete URLs and Vaults belonging to the Organization.

Rave Settings

Manage Medidata Rave URL settings.

Vault Settings

Manage Veeva Vault settings.

Reports

View Organization Reports.

User API

Use the user permissions API.

API Tokens

Create and manage their own API tokens.

Holding "Administer Permissions" does not give a user the other permissions in this table. Someone who administers permissions and also needs to delete URLs holds a role that has both.

Giving somebody "Administer Permissions" also gives them every permission on every URL in the Organization. That happens whether you choose a role for them on the Organization team page, or add the permission to a role other people already hold, in which case every holder of that role gets it.