Roles and Permissions

Role Permissions

Beyond its purpose of managing workflows and responsibilities, the Role and Invitation system performs the critical behind-the-scenes function of setting and removing permissions.

The iLiv system tracks and stores a detailed history of every invitation, broken down into discreet steps. Some steps trigger the granting of permissions to read or write specific pieces of data. Other steps revoke previously granted permissions.

iLiv uses a role-based system to grant permissions for accessing and managing the data stored in each Performance.

There are four main ways that you can interact with a Performance:

  • as a Performance Admin
  • with an Active Role
  • as a Super-Observer of an Owner Group
  • as a Member of an Owner Group

An Owner Group is defined as the Group that owns the Performance. It is often, but not always, the same Group that owns the Composition that has been instantiated into that Performance.

Here's a breakdown of how the different role types can interact with a Performance, and what each permission level means.

Performance Admins

Performance Admins have the highest level of control on an individual Performance.

How to Become an Admin:

  • You are invited by another current Performance Admin.
  • You created the Performance.

Performance Admins:

  • Have full editing rights for all aspects, including Roles, Timelines, Events, Attributes, Notes, and Documents.
  • Control who is invited to or removed from Roles.
  • Can create or delete Events and Timelines.
  • Can assign any Role to an Event or Timeline.
  • Can add, read, modify, or delete any Note or Document (except for Documents whose audience is set to the most resticted level).
  • Can mark any Event as "done."

Non-Admin in an Active Role on a Performance

If you are a non-Admin that has an active Role on a Performance, your editing permissions are focused on the Events or Timelines to which you are directly responsible.

  • You can only mark "done" on Events for which you are responsible.
  • You can only modify or delete Notes or Documents on Events or Timelines to which you are directly responsible.
  • You can only modify Attribute values on Events or Timelines for which you are responsible.
  • For Events or Timelines that do not include your Role, you have Reader permissions for any attached Notes, Documents, or Attributes. However, you cannot make any changes to these items.

Limitations:

  • You cannot invite anyone to a Role.
  • You can only accept your own invitations to Roles or choose to leave an assigned Role.

Group Admins

Group Admins have the highest level of control on an individual Group. They are responsible for managing the memberships and designating members to additional roles within the Group.

Group Admins:

  • have full control over who is invited to or removed from the Group.
  • can accept Performance Role invitations on behalf of the Group.
  • can create a Performance using a Group Composition.
  • can designate other members as Composers, Super-Observers, or Admins.

A Super-Observer is a high-level role within a Group that grants permission to read any Document or Attribute on any Performance owned by their Group.This is intended for someone who may be in a management level position who may need access to all the Group documents or attribute data but would not necessarily have an active Role on every Performance.

A Composer is someone who has been authorized to create Compositions on behalf of the Group. Only Composers will have access to iLiv Composer.

Non-Admin Members of a Group

If you are a member of a Group but are not an Admin of that Group, your permissions are primarily for viewing.

  • You can only accept your own invitations to join the Group or choose to leave it.
  • You cannot make any modifications within the Group itself.

You have limited Reader permissions on any Performance that your Group owns. This means you can view the Performances and their Events and Notes, however, you cannot make any changes. Crucially, you cannot read any Documents or Attribute data associated with these Performances.

Document Permissions

The Audience feature gives users the option to limit who can read the contents of a document. There are 3 settings:

  • anyone with a Role on the Performance (default)

  • anyone with a Role on the Timeline or Event (or Performance Admin)

  • only people with a Role on the Event (that the document is attached to)

As a Performance Admin, you can change the Audience setting on any document even if you can't see the content. Group Super-Observers can see any document regardless of the Audience setting (but cannot make any edits).

To change the Audience setting on a Document:

  • open the Document foldout
  • use the Audience dropdown menu to select one of the options
  • click the Save button at the bottom of the foldout

Visual Guide

A Visual Guide to Permissions within Performer:

Action Performance Admin Active Role Owner Group Super-Observer Owner Group Member
Read any Event or Timeline
Create/Modify/Delete an Event/Timeline if Role is assigned to the Event/Timeline n/a n/a
Read any Note
Create/Modify/Delete a Note if Role is assigned to the Event/Timeline n/a n/a
Read any Document (Default Audience) n/a
Read a Document (Limited Audience) if Role is assigned to the Event/Timeline n/a
Read a Document (Restricted Audience) if Role is assigned to the Event if Role is assigned to the Event n/a
Create/Modify/Delete a Document if Role is assigned to the Event/Timeline n/a n/a
Read any Attribute n/a
Modify an Attribute if Role is assigned to the Event/Timeline n/a n/a