SECF0040 - Maintain System User Note Type Restrictions

Purpose

To restrict user access to Note Types

SubSystem

Security

Normally Run By Administration specialist
Anticipated Frequency As required
Structure  Blocks Person
Person Note Type Restriction Tab
Enrolment Note Type Restriction Tab

This form is used to restrict an individual user’s access to different Note Types.

The Note Types available to a user and the operations that can be performed on accessible Notes Types is determined by the cumulative effect of restrictions applied at the Security Role Level and the User Level (this form). Enrolment Note Types may be subject to additional restrictions through Organisational Unit Restrictions.

If a user does not have access to particular note, either :
- because it is an enrolment note for a study element in a course owned by an org unit that the user doesn't have access to (i.e. via SECF0032), or
- because it is restricted at the user's role level (i.e. via SECF0041), or
- because it is restricted at the user level (i.e. via this form),
then no evidence of its existence will appear to the user in the relevant Note form or any of the Inquiry forms, or via SQL query.

To understand more about the cumulative effect of these Note Type Restrictions, see Note Type Restrictions.

This form is accessed from the Maintain System Users form (SECF0021).

The Person block contains:

  • Person ID
  • Sex
  • Date of Birth

The Person Note Type Restriction Tab contains:

  • Note Type
  • Description
  • Insert check box
  • Update check box
  • Delete check box
  • Restricted Select check box

The Enrolment Note Type Restriction Tab contains

  • Note Type
  • Description
  • Insert check box
  • Update check box
  • Delete check box
  • Restricted Select check box

Rules/Notes:

 

The Person block displays previously recorded user details. Query functions cannot be performed in the Person block.

Use this form to restrict access to Note Types for an individual user. These restrictions act together with restrictions imposed through the User's Security Role(s). Where a Note Type restriction is applied to an Enrolment Note Type, further restrictions may apply to the user through Organisational Unit Restrictions.

For a particular note type:

  • deselecting the Insert checkbox removes the ability of the user to add a note of the particular note type
  • deselecting the Update checkbox removes the ability of the user to modify a note of the particular note type
  • deselecting the Delete checkbox removes the ability of the user to delete a note of the particular note type

Selecting the above checkboxes allows the user to perform the operations.

The Restricted Select Allowed checkbox works differently. When selected, it permits the user to view only data associated with the Note Types recorded in this form. When deselected, the user can view data for any Note Type allowed by their Organisational Unit Restrictions and Security Role(s) but can only perform operations as indicated by the other checkboxes.

Rules/Notes:

Person Note Types and Enrolment Note Types are displayed in alphabetical order.

Selecting an Update, Insert or Delete checkbox enables a user to perform that function for the Note Type. Deselecting a checkbox will stop a user from being able to perform the function.

Selecting a Restricted Select Allowed checkbox for any note type restriction record causes the Restricted Select checkboxes for all records to be selected. Inquiry access is then restricted to the Note Types recorded here.

Adding restrictions to a User reduces the access inherited from their security role(s). Access cannot be increased beyond that specified by their security role(s). For example, if the role prevents deletion, setting the delete indicator in this form will not allow the user to delete.

A record cannot have all three of Update, Insert, Delete, checkboxes set unless the Restricted Select check box is also selected .

The reverse also applies, that the above check boxes should all be unchecked before saving.

When a note type restriction is applied to a user, the Effective Note Restrictions for that user (overall restrictions taking into account Restrictions on that user and also restrictions on the role(s) that they have been granted) are redetermined and:

  • If their is a conflict in the user's restrictions (i.e. Note Types from within the same Note Type Group have different Restricted Select values) then a warning will display and log records will be created that can be viewed in GENF0001.
  • If there is an overlap in the user's restrictions (i.e. Different Note Type Restrictions applied to a Note Type) then no warning is displayed, but log records (overlap) are created and can be viewed in GENF0001.

The Effective Note Restrictions applying to a particular user can be viewed using SECF0043.

Person Notes are viewed in ENRF3070.

Enrolment Notes may be Student Course Attempt Notes, Student Unit Set Attempt Notes or Student Unit Attempt Notes.

Student Course Attempt Notes are viewed in ENRF3080.

Student Unit Set Attempt Notes are viewed in ENRF3081.

Student Unit Attempt Notes are viewed in ENRF3082.

 

Last Modified on 31 May, 2006