Organizing Your Workspace

Setting up the global manager to grant permissions

The final two lessons in this chapter look at how to set access control and permissions in your TAO instance –  in other words, how to ensure that each user is doing the right thing in the right place. 

Gwen, as global manager, is the person who sets the permissions for different workspaces. To set the permissions for a given library, or section of a library, she needs to select the folder in question in that library, then click on the Access Control button in the button bank below it. An information page containing the access permissions for that particular folder will open on the screen.

Before setting up the permissions each user should have for the various work folders which are now available, though, Gwen first needs to configure the root folder of each library. 

By default, the root folder (the top level folder) in any library is managed by the Back Office role. Several other roles (including item author and test author) automatically inherit this role (for other reasons), so in practice, therefore, users who have been assigned the role of item or test author also have automatic access to the whole library.

To change this, Gwen needs to adjust the permissions for these root folders before doing anything else. She can do this by first giving grant permission to the Global Manager (i.e. herself) and then taking it away from Back Office. In the image below you can see the permissions before she makes any changes (this is the root folder of the Items library, but the same goes for any other).

Default permissions for the root folder 'Item'

 

Permissions can be granted in two ways: either to individual users, or according to role. We’ll need both of these later, when setting up access rights for different users, but for the moment Gwen just needs to add the role of Global Manager using the Add role(s) box, and then remove the role Back Office from the list of roles with access permissions with the yellow Remove button..

Now she can start to grant permissions to the relevant users (either all item authors, or just specific ones) for each folder in the Item library.