In Alfabet, responsibilities are documented via the concept of roles , whereby each role is based on a preconfigured role type or a custom role type defined by your company. In contrast to an authorized user who has read/write permissions, a person assigned a role for an asset will not have read/write permissions based on the role definition. The role is primarily for documentation purposes to provide information about stakeholders interested or responsible for the asset. If the user should have read/write permissions, they must either be the authorized user of the asset or assigned to an authorized user group associated with the asset.

Alfabet provides out-of-the-box role types that enable you to understand who is responsible for your IT assets in your IT portfolio. Additional role types that are relevant for your company can also be added.

In order for users to be able to specify roles for an object, you must create role types and assign them to the relevant object class. Only the role types that have been configured for the object class of the selected object will be available for the role definition. A role type may be defined for either a person and/or organization. The configuration of the role type will also determine whether only one person or organization or multiple persons or organizations may be defined per role type for the selected object. Administrative users can define role types on the Alfabet user interface..

Administrators can now override role type settings through class settings, allowing role behavior to be tailored for specific combinations of object classes and user profiles. This makes it possible to define how roles are assigned and managed on a per-class basis rather than relying solely on global role type definitions. Role type overwrites offer configuration options not available via the Alfabet user interface

Greater flexibility in access management. Access management settings support more advanced configuration options. Alongside general editability and visibility settings, administrators can define conditions that determine whether a role is editable or visible. These conditions can be based on property values of the object for which the role is defined or on characteristics of individual users, enabling more granular access control.

Class setting-based role type assignment. Role type assignments to property groups can be configured via class settings. When a property group assignment is defined both in the Role Type and in class settings, the class-specific configuration takes precedence. Configuring property group assignments in class settings provides the additional benefit that the assigned role types participate in the property group ordering defined within the same class configuration.

  1. Go to the Presentation tab.
  2. In the explorer, expand the nodes Class Settings > the object class you would like to edit > the class settings you would like to edit.
  3. Right-click the Role Types node and select Modify Role Type Behavior.
  4. The new role type modification will be added as the last child node of the Role Types node with a random role type assignment. Click the node and select the relevant role type in the Role Type attribute.

    Each role type can only be added once to the Role Type node. If you do not find the role type in the drop-down list, there is already a modification for this role type. Change the existing role type modification node.

    If you see a warning symbol in front of one of the existing role type overwrites, the role type has been deleted or removed from the relevant object class via the configuration on the Alfabet user interface.

    11-13_RoleTypeconsistencycheck 

    To check class settings for inconsistency in role type configuration, you can also use the Check Consistency option of the class settings node. The consistency check lists all inconsistencies in the role type configuration in a pop-up window.

  5. Set the attributes as required:
    • Caption: Define a caption that will be displayed for the role type on the Alfabet user interface.
    • Hint: Define a tooltip that will be displayed for the role type on the Alfabet user interface.
    • Access in User Interface: Define whether the user can assign a role for the role type (WriteAccess ), whether the role type is visible read-only (ReadAccess ) or whether the role type is completely hidden (NoAccess).
    •  Visibility Conditions: If you want the role type to be visible under specific circumstances only, you can create a condition configuration object that is testing whether the specific circumstances apply. You can then select the condition object in this attribute. The role type will be visible if the condition applies. For example, a role type shall only be visible for users in user group B. The condition checks the user group configuration for the current user at runtime and hides the role type if the user is not member of user group B.

      Visibility conditions cannot provide visibility if the Access in User Interface attribute is set to NoAccess . You can only restrict visibility based on conditions if the Access in User Interface attribute is set to either WriteAccess or ReadAccess.

    •  Editability Conditions: If you want roles to be editable under specific circumstances only, you can create a condition configuration object that is testing whether the specific circumstances apply. You can then select the condition object in this attribute. Open the editor and click the field in the Use column of one or multiple conditions to select them. Users can only assign roles for this role type if the condition applies. For example, only users with a specific role for the object shall be able to assign roles based on the current role type. The condition checks the roles the current user has for the object at runtime and the property will be read-only if the user does not have the required role.

      Editability conditions cannot provide editability if the Access in User Interface attribute of the role type specifies ReadAccess or NoAccess . You can only further restrict editability based on conditions if the Access in User Interface attribute is set to WriteAccess.

    •  Property Group: Select the property group the role type shall be displayed in.

      Role types can also be assigned to property groups via the editor for assignment of the role type to the object class in the Class Configuration functionality on the Alfabet user interface. If a role type has been assigned to a property group during role type assignment to the object class, the role type will be displayed after the object class properties and is not included in sort capabilities for the property group. If you assign the role type to the property group in the class settings, you can change the sort order of both object class properties and role types in the class setting overwrites for the property group.

    • Hide Selector: Set this attribute to True if you want to hide the Advanced Search link in the drop-down list in fields for the definition of the role.
    • Selector Definition: If your configuration includes more than one selector for the Person or OrgaUnit object class, you can change from the default selector that opens when a user clicks the Advanced Search link in the drop-down list in fields for the definition of the role.

      Check the settings of the role type prior to changing the selector. If the role type is configured to allow both person and organization specification, do not change the editor. There is a special editor for this case that should not be overwritten. If users can assign the role to either users only or organizations only, make sure you are selecting a selector for the correct object class.