--- title: "Permission Management" type: OpenSpec status: Draft domain: OneAccess --- # Permission Management ## Requirement Definition The Permission Management module is used to maintain Access Rights Groups. It defines: 1. Which modules and functions can be accessed by users in a group. 2. Which applicable actions (Add, Change, View, Delete, Approve/Reject, Copy, View History, Save as Template) can be performed by users in each function within each module. ## Process Flow ### Trigger - A new user group is defined, requiring permission assignment. ### Pre-Conditions - Users must have access rights to the Permission Management module to view, add, or edit permission records. ## Business Rules - The system checks and displays available modules/functions for each user based on: - **A**: Permissions assigned directly to the user. - **B**: Permissions assigned to the user's permission group. - **Total User Permission (C)** = Combination of A and B. ### Data Schema #### General Information | Field Name | Description | Logic Type | Constraints / Rules | |---|---|---|---| | Role | The unique identifier of the permission group. | String (10) | Required. | | Role Name | Text describing the Permission Group Name. | String (100) | Required. | | Permission Type | The type of permission assignment. | Enum | Required. Values: Particular User, User Group. | | User | Select one or more users for this role. | Array of User IDs | Required if Permission Type is "Particular User". | | User Group | Select one group for this role. | String (User Group ID) | Required if Permission Type is "User Group". | | Description | Text describing the Role. | String (200) | Optional. | #### Module Permissions *A hierarchy of modules containing the list of available functions (Top-level and Second-level modules).* | Field Name | Description | Logic Type | Constraints / Rules | |---|---|---|---| | View | Allows viewing data available in the function. | Boolean | | | Create | Allows creating data in the function. (Includes "Save as draft" implicitly). | Boolean | | | Edit | Allows updating data in the function. | Boolean | | | Delete | Allows deleting data in the function. | Boolean | | | Copy | Allows copying available data in the function. | Boolean | | | Approve | Allows approving/rejecting data in the function. | Boolean | | | History | Allows viewing data history (activity log). | Boolean | | | Template | Allows saving records as a template. | Boolean | | #### Access Rights Fields (Field-Level Permissions) | Field Name | Description | Logic Type | Constraints / Rules | |---|---|---|---| | View | Allows viewing the specific field on the screen. | Boolean | | | Editable | Allows modifying the value of the specific field. | Boolean | | ## Post-Conditions - Records are automated for approval upon creation/modification. ## Exception Flow - If input data fails validation, the action is canceled, and the operation fails.