Role-based access control (RBAC) lets you control what each user can do in Lifecycle Manager. Assign ScalePad-provided or custom access roles, grant individual permissions, and manage which clients users can access through Client Groups.
Access to a Lifecycle Manager feature can depend on four layers:
- Your account has access to the feature.
- The client has the required Lifecycle Manager license, if applicable.
- The user has permission to perform the action.
- The user can access the client through their Client Groups.
For example, permission to update initiatives does not provide access if the feature is unavailable to the account, the client does not have the required license, or the client is outside the user’s Client Groups.
Who can use this feature?
Lifecycle Manager administrators and users with the required Users permissions can manage access. The available actions depend on the permission:
- Create: Create access roles.
- Read: View user and role information.
- Update: Change roles and another user’s permissions.
- Delete: Delete custom roles and revoke user access.
Account administrators have full Lifecycle Manager access. You cannot change your own permissions.
What you’ll need
- The user must already exist in your ScalePad account.
- The user must have an Active, Invited, or Suspended status to edit their permissions.
- You must have access to Account Settings > Users.
Understand access roles and permissions
An access role is a collection of permissions that you assign to one or more users. You can assign more than one access role to a user. Lifecycle Manager combines the permissions from all assigned roles with any direct permissions assigned to that user.
Permission actions
Permissions use four actions:
- Create: Create an object.
- Read: View an object.
- Update: Edit an object.
- Delete: Delete an object.
Write permissions include read access. When you select Create, Update, or Delete for an object, Lifecycle Manager selects Read automatically. If you clear Read, Lifecycle Manager clears the other actions for that object.
ScalePad-provided roles
Lifecycle Manager includes these ScalePad-provided roles:
| Role | Access |
|---|---|
| Administrator | Full access, including users and permissions. |
| Editor | Can create and edit Lifecycle Manager data. |
| Manage Basic Settings | Manage account, client, hardware, and report settings. |
| Place Orders | Place orders. |
| Viewer | Can view Lifecycle Manager data. |
ScalePad-provided roles are shown with the Type ScalePad. You cannot edit or delete these roles, but you can duplicate one to create a custom role as a starting point.
Custom roles
Custom roles let you create an access role for a specific job function. A custom role must have a name and at least one permission. You can also add a description to help other administrators understand the role’s purpose.
When you update a custom role, Lifecycle Manager applies the change immediately to every user assigned to that role.
Capabilities
Some actions are managed as capabilities instead of Create, Read, Update, and Delete permissions:
- Manage Licensing: Allows the user to manage Lifecycle Manager licensing.
- Manage Orders: Allows the user to place and manage orders.
Permission catalog
The access role permission matrix includes 29 objects:
| Group | Objects |
|---|---|
| Clients | Client Dashboard, Client Groups, Client Settings, Contacts, Meetings, Notes, Tasks |
| Planning | Advisor, Agreements, Assessments, Budgets, Deliverables, Goals, Initiatives, Playbook Runs, Playbooks |
| Templates | Agreement Templates, Assessment Templates, Deliverable Templates, Goal Templates, Initiative Templates, Roadmap Templates, Task Templates |
| Assets | Hardware, Hardware Settings, Software |
| Administration | Account Settings, Report Settings, Users |
All objects support Create, Read, Update, and Delete except Advisor, which supports only Read and Update. The Budgets permission controls the standalone Budget Forecast page. Fees on an initiative use Initiative permissions.
Assign an access role to a user
- Open the account menu and select Account Settings.
- Select Users.
- On the Users tab, select the user’s row.
- Under Access roles, select Add role.
- Select one or more roles.
- Select Save changes.
A user’s effective permissions include permissions inherited from assigned access roles and any direct permissions assigned to the user. Select Review individual permissions to view or change direct permissions.
Changing a permission supplied by an assigned access role removes that role. Saving legacy inherited permissions converts them to direct assignments so access is preserved.
Create a custom access role
- Open the account menu and select Account Settings.
- Select Users, then select the Roles tab.
- Select Create custom role.
- Enter a required Role name and an optional Description.
- Select at least one permission.
- Optionally enable Manage Licensing or Manage Orders.
- Select Create role.
Use the permission matrix to select Create, Read, Update, or Delete for each object. You can also use the All column to grant every available action for an object.
Edit, duplicate, or delete an access role
Edit a custom role
- Open the account menu and select Account Settings.
- Select Users, then select the Roles tab.
- Select the custom role you want to edit.
- Update the role name, description, permissions, or capabilities.
- Select Save changes.
Changes apply immediately to every user assigned to the role. You cannot edit a ScalePad-provided role.
Duplicate a role
Open the role and select Duplicate. You can duplicate a ScalePad-provided or custom role and use it as the starting point for a new custom role.
Delete a custom role
Open the custom role and select Delete role. Deleting a role removes the permissions it granted from assigned users and cannot be undone. You cannot delete a ScalePad-provided role.
Manage client access with Client Groups
Access roles control what a user can do. Client Groups control which clients the user can see.
- Create a Client Group under Account Settings > Groups.
- Add the clients that the group can access.
- Add the users who need access to those clients.
Users can access clients assigned to their Client Groups. Clients that are not assigned to any Client Group remain visible to all users. If you delete a Client Group, its clients become visible to all users again.
Client Groups do not replace feature permissions. A user must have both the required permission and access to the client to complete an action.
Revoke a user’s access
- Open the account menu and select Account Settings.
- Select Users.
- On the Users tab, select the checkbox beside each user whose access you want to revoke.
- Select Revoke Access.
- Confirm the action.
You can revoke access from a maximum of 100 users at a time. You cannot revoke your own access. Lifecycle Manager also prevents you from revoking access from the last remaining user or administrator.
Troubleshoot access issues
If a user cannot see a page or complete an action, check each access layer:
- Confirm that the account has access to the feature.
- Confirm that the client has the required Lifecycle Manager license, if applicable.
- Confirm that the user has the required Read, Create, Update, or Delete permission.
- Confirm that the user can access the client through a Client Group.
Depending on the feature, Lifecycle Manager may hide an unavailable page or action, disable an action, or redirect an inaccessible link.
Any questions?
Reach out to the Lifecycle Manager support team by submitting a support ticket.