Workgroups

Workgroups are used to control users' access to functions and configuration settings in a Planning Space tenant (most of these functions are application-specific, while a few are common to all of the Planning Space applications).

You can add or remove user accounts from membership of a workgroup using the Workgroups interface.

The effects of belonging to a workgroup are determined by the roles that a workgroup is allowed to use. These role permissions are set in the Roles management interface.

Two workgroups are created by default for a new tenant:

  • Administrators: this workgroup has access to all functions and all configuration settings for the tenant. By default, only Administrators can create or manage the user accounts, workgroups and roles of the tenant (but these roles can also be assigned to new workgroups).
  • Everyone: all users are automatically members of this workgroup. By modifying the roles which Everyone is assigned to, you can control which features of the Planning Space applications are made 'public' and available to all users.

For version 16.5 Update 20 and later: A third default workgroup SecurityAdministrators will be defined in a new tenant. This workgroup is granted the role 'Security/Security'. By default it does not have any user members. The workgroup name can be modified.

To access workgroup management, click Security in the Navigation menu, and Workgroups in the Security top menu.

Note: You can only access this screen if you are logged in as an Administrator user, or if you are using a user account which is granted the role 'Security/Security'.

Screenshot-PS-Security-Workgroups

You will see the names and descriptions of the existing workgroups for the tenant.

For version 16.5 Update 13 and later: Workgroup names can be changed at any time, using the edit pane (except for 'Administrators' and 'Everyone').

In earlier software versions, workgroup names cannot be changed after creation.

Create a new workgroup

Click the New workgroup button to create a new workgroup:

Screenshot-PS-Security-Workgroups-create-new

In the edit pane, type in a name, a short description, and an optional comment. Workgroup names can only contain alphanumeric characters, underscores (no spaces), and full stops; names can be up to 128 characters and must start with a letter.

Workgroup members: Use the tick boxes next to the user account names to set the initial user membership of the workgroup.

Click the Save button to create the new workgroup.

For version 16.5 Update 12 and later: you can make a new workgroup as a copy of an existing workgroup by selecting one workgroup and clicking the Copy workgroup button.

'External Group' setting

Only for version 16.5 Update 12 and later: The External Group field is used in the configuration of automatic provisioning of tenant user accounts. See the Planning Space 16.5 Deployment Guide.

'License Profile Workgroup' setting

Only for version 16.5 Update 16 and later: The License Profile Workgroup checkbox is used to mark a workgroup for use with License Profiles, which can be used to control and prioritize users' access to Planning Space product licenses. License profiles can only be managed by IPS Administrators. See the Planning Space 16.5 Deployment Guide.

Edit a workgroup

To edit the settings for an existing workgroup, click a workgroup name to open its edit pane. For example:

Screenshot-PS-Security-Workgroups-edit-General

The workgroup that is being edited will be highlighted in blue. Click the X button at the top right corner to close the edit pane.

There are two control buttons, which become activated when you have made an edit. Click the Save button to save the changes that you have made. Click the Discard changes button to undo any unsaved changes.

General tab: Use the tick boxes next to the user account names to add or remove user members of the workgroup. You can also edit the Description.

Roles tab: Modify which roles this workgroup is allowed or denied (see Roles).

User membership editing

Only for version 16.5 Update 12 and later: The Invert Selections button Invert Selections performs an inversion between selected and unselected users (this is useful, for example, in the case of switching Dataflow document permissions between a specified list of allowed users and a list of denied users).

Note for these software versions the user membership is displayed in a separate Users tab.

The Copy from workgroup... button can be used to set user membership based on the settings in other workgroups. Clicking the button opens a panel showing a list of workgroups (use the Search field to filter workgroups by name sub-string matching). Select one or more workgroups; a list of user accounts will appear. The dropdown selector switches between All selected workgroups (logical AND), which means that users will only be selected when they are members of all of the selected workgroups, and Any selected workgroups (logical OR), which means that users will be selected when they are a member of one or more of the selected workgroups.

Delete a workgroup

To delete a workgroup: click a workgroup name and click the Delete button. Then click Delete in the confirmation dialog.

'Export as CSV' workgroup data

Click the Export as CSV button to export a file that contains the details of all of the workgroups, and their Allowed and Denied roles.

Note for version 16.5 Update 7 and later the role names are prepended by the application name (e.g., 'PlanningSpace Dataflow-Dashboard Map'). For earlier versions role names are not prepended and can be ambiguous when the same role name is used for different applications.