# Rights Profiles in Novulo

**URL:** https://community.novulo.com/t/rights-profiles-in-novulo/117
**Category:** Wiki
**Tags:** implementation
**Created:** [April 24, 2024, 10:55am UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117 "2024-04-24T10:55:17Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Joost](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.novulo.com/joost/32/87_2.png) [@Joost](https://community.novulo.com/u/Joost)
#### Post date: [April 24, 2024, 10:55am UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117/1 "2024-04-24T10:55:18Z")

</div>

Every Novulo Application contains Rights Profiles.

This functionality allows you to control access to all parts of your application, on two levels:

1. [GUI-level](https://community.novulo.com/t/rights-profiles-in-novulo/117#rights-profiles-at-gui-level-1)
2. [Database level](https://community.novulo.com/t/rights-profiles-in-novulo/117#database-rights-5)

# Rights profiles at GUI level

The GUI level controls what menu’s, pages, tabs, forms, grids and buttons you can see in the application.

The Database level controls, for each record type, if you can view, add, edit or delete the records, down to field level. Access on database level applies to all methods to access the application, including access through REST API, Export or Import.

Every user is linked to 1 Rights Profile. For more information in combining rights profiles, see [Rights profiles - merge functionality](https://community.novulo.com/t/introduction-of-merge-rights-profiles-functionality/202).

Rights profiles can be found in every application at Application Maintenance \> Users \> Rights Profiles.

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/d390a3eddbc846f9ecaea0560b4de69319a4e229.png)

By default, every application has an Administrator profile, which has all rights.  
Administrator then can add additional profiles.

When you open the profile, you see both levels of access:

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/67f3f70c021c5a97861d5880f28959f4ba9249d3.png)

Nested under root, the GUI level has the name of your application. The Database level is listed under Database.

As this is the Administrator profile, all access is granted, as shown with the green checkmark: ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/eb898dc831240f32752218a7469a2de63be41183.png)

For all levels:

1. Changes in the Rights Profiles are stored immediately - there is no “Save” button
2. Changes come into effect the first time a user logs in after a change. Users who are logged in are not affected automatically. Changes to your own profile are applied immediately, except for _adding_ database rights.

Within the rights profiles, it’s explicitly stored if the access level has been set, irrespective of the level.

When an application is updated and new fields or buttons are added, these are set to the ‘no information’ level and are _red_.

Users don’t get access to new features by default; administrators can easily recognize which parts need assessment.

The Administrator profile is an exception: this profile will always get access to all new functionality.

## Novulo Rights profiles at GUI Level: basics

On the GUI Level, you see the Toolbar, and then all menu’s that you also have at the “All apps” menu.

When you open a menu in the GUI level, you see all elements that are listed here.

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/5b3c74559a11583f0ffe8df234a3d3a5371a45b1.png)

For each level in the menu, you are able to change Visibility from Yes to No.

On the right side, there is are a few options to assist you in the process:

1. Set no rights for selected subtree - applies to every element below
2. Set all rights for selected subtree - applies to every element below
3. Copy settings from other profile

This applies to all aspects in the tree.  
The checkbox ‘only for missing nodes’ will make that the selection only applies to the ‘red’ nodes, the items that have been added since the last release and are not explicitly assigned.

### GUI level: details page

In the set-up of Novulo, all pages are primiraly defined in the Settings and Overviews pages.  
Pages can then be accessed through various menu’s.

For example, the generic _Products_ page can be accessed through “Sales \> Sales products” and “Purchase \> Purchase products”. They show the same page, but are filtered on specific characteristics.

Through the menu’s Sales \> Sales products and Purchase \> Purchase products, you only have the Menu item, grid and grid buttons.

Every page is defined only once, and this can than typically found through Application Maintenance, and then the specific Views or Settings page. The views they are in correspond with the views menu’s and the Architect Model.

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/983972bfe2ef4279ab99b278bdf795ab48efb5fe.png)

_Exception: General Views and Management Views are displayed under “Management” to the users, but are separate in the profiles._

In this example, Products are in General Views. When clicking here, the individual forms and rows are all displayed,

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/ce104060048b8ddc50c6f253030091d34741c056.png)

The pages that are listed under “More” menu, are at “Tabbed panel” in the Rights profiles.

## New rights

As mentioned above, when an application is updated with additional functionality, the new pages, forms and rows are marked as new and have no access by default.

Nodes that are new need to be checked by the System Administrator to grant or reject rights.

**Best practice:** always make sure to check all new rights after a release

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/0f20e3f67805a0604834c390ae2e9d304630064a.png)

As you can see, new nodes and parts of nodes are clearly indicated in red. On the right side, you see the elements of the new node.

The buttons “Previous new node” and “Next new node” are useful to navigate quickly through all nodes without needing to manually search and expand the tree.

# Database rights

Database rights are at the core of the Novulo Data handler and affect all access to the data of the application. They are integrated with every part of the application, including export, import and REST.

Database rights are set at Record type or Database table level.

## Database rights per record type (table)

In the database tree, you see all tables. There are 4 columns displaying the table access rights.  
When you click on a table, you see the rights displayed with the three radio buttons.

![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/eb898dc831240f32752218a7469a2de63be41183.png) Access  
 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/4e053e5988ef573d402b87e4c52746e964cc35cc.png) No access  
 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/3abb258bb9685bc7d17b436db6451cabf6a8f254.png) Conditional acess

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/08cdf2059ed59a0ab5fd0eb19b294e64e71d0acf.png)

**Access** defines if you can view the record at all. When you have no access, you can’t do anything with this record: it doesn’t just block viewing, it also blocks Adding, Deleting and Editing.

**Add, delete and edit** define the rights to add, delete and edit records of this type.

**Conditional** makes it possible to grant rights only to records with a specific condition, based on the information of the record.

Tables in **red** are tables that have never received rights yet. By default, they have no rights.

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/2e20fbd9ddb7aa230b8a914b63b3543a802cd726.png)

## Database rights per field (column)

When clicking on a table, the application shows all fields in the table.

For the fields, rights can be set on Visible and Editable. Just like with the table, rights can be set to.

1. Yes
2. No
3. Conditional

 ![image](https://canada1.discourse-cdn.com/flex008/uploads/novulo/original/1X/3e8bd35d8d852894934e921415bc024881266152.png)

Table access is always strong than field access. If you don’t have Access rights to the table as a whole, individual rights on fields level are discarded.

---

<div class="post-metadata">

### Author: ![patrick.tunnissen](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@patrick.tunnissen](https://community.novulo.com/u/patrick.tunnissen)
#### Post date: [August 8, 2024, 3:22pm UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117/4 "2024-08-08T15:22:27Z")

</div>

How can I set an entire directory tree to read-only, without changing all permissions, but only setting it to read-only?

---

<div class="post-metadata">

### Author: ![Joeri](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.novulo.com/joeri/32/428_2.png) [@Joeri](https://community.novulo.com/u/Joeri)
#### Post date: [November 12, 2024, 9:33pm UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117/5 "2024-11-12T21:33:40Z")

</div>

I’d like to know this as well! @Joost

---

<div class="post-metadata">

### Author: ![RobinVelthof](https://avatars.discourse-cdn.com/v4/letter/r/90db22/32.png) [@RobinVelthof](https://community.novulo.com/u/RobinVelthof)
#### Post date: [November 13, 2024, 3:14pm UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117/6 "2024-11-13T15:14:27Z")

</div>

What are best practises when to choose between setting visiblity at GUI level and database level. What are the exact differences?

- Setting a visiblity at GUI level means that you as the user cannot see the field on the record itself, but are still able to see it’s value when adding it as a column on an overview page (e.g.)
- Setting a siviblity at database level mens that you as the user are not able to see the value of the field in matter

So when setting a database field as invisible but setting it visible at GUI level means you can see the field but the value will be shown as null, even though in reality it may not be null.

---

<div class="post-metadata">

### Author: ![MMancino](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@MMancino](https://community.novulo.com/u/MMancino)
#### Post date: [June 18, 2025, 9:10am UTC](https://community.novulo.com/t/rights-profiles-in-novulo/117/7 "2025-06-18T09:10:55Z")

</div>

I would also like to know how can we set read-only rights for certain trees of the application. Doing it manually it’s a big effort and definitely not an enjoyable task
