Axel Raboit EI

Accounts, roles and privileges

Everyone sees what concerns them: rights are granted screen by screen, not in bulk.

Giving someone access should not mean giving them everything. In Aurora an account carries a role and a list of privileges, and the side menu shows only what is open to it.

What can be set

  • Privileges per screen and per action: view, create, edit, delete.
  • An email invitation, with the account created disabled if needed.
  • Email verification and password reset.
  • An audit log: who changed what, and when.
  • The ability to stand in an account to check what it sees.

So a client can write without touching the settings, and their intern can write without being able to publish.