Skip to main content

Manage document store and user permissions

Manage permissions to documents/reports within SelectHR.

H
Written by Harry Ledger
Updated over 2 months ago

The document store is used to store all files uploaded to the SelectHR system. This includes any files uploaded via the file links functionality and Crystal Reports.

To successfully upload to or download from the document store, assign the relevant permissions to users for the document store folder in which the file is or will be located.

File links and their document store folders

All areas of SelectHR have what is referred to as a parent key. The easiest way to think of this is that the area you're uploading to in file links has the same primary key as its name. Some examples are included below:

File Links location

Folder the document is uploaded to

Details

Person

Career History

Employee

Appointment History

Employee

Absence History

Absence

Training History

Training

You can find all these folders under one root folder called SelectHR.


Permissions available for assignment and their role

There are two types of permission you can actively assign to a user within a document store folder.

Permission setting

What each permission allows a user to do

None (no permission selected)

  • Nothing.

Read Only

  • View and download documents in the folder.

Read Only
with
Update & Delete

  • View and download documents in the folder.

  • Update existing documents in the folder.

  • Upload new documents to the folder.

  • Delete existing documents from the folder.


Recommended permissions

While the document store has a basic expected use, each of our customers utilises the document store in their own way, so it's not possible to give complete instructions on what permissions to assign.

We do however, recommend that you assign document store permissions at the group level, rather than on an individual user basis. This allows you to set up the permissions just once, and as long as the user is in that group, they automatically have the correct permissions.

User group

Recommended permissions

Onboarding

  • If the onboardee is not expected to upload any files, use Read Only.

  • If the onboardee is expected to upload files, use Read Only and Update & Delete.

Everyone

  • If the users aren't expected to upload any files, use Read Only.

  • If the users are expected to upload files, use Read Only and Update & Delete.

Manager

  • If the manager is not meant to upload documents to File Links, use Read Only.

  • If the manager is meant to upload documents to File Links, use Read Only and Update & Delete.

HR

  • Read Only and Update & Delete.


Permissions via groups

The document store pulls from the lowest permissions assigned to the document store folder and the user account, Read Only being the lowest level of permission.

For example, your manager users are typically assigned to both the Manager group and the Everyone group.

On the SelectHR folder in the document store, the Everyone group has Read Only permissions, whereas the Manager group has Read Only and Update & Delete permissions.

As a result, the manager isn't able to upload any files to the file links of an employee.


Best practice for assigning Update & Delete

Use existing Manager and HR groups to allow your managerial and HR users to upload to the document store.

Managerial and HR users should belong to just one group, depending on their role. The Everyone group typically has Read Only permissions assigned.

To ensure the Managerial and HR users retain access to the Self Service menu set when removing them from the Everyone group, assign the Self Service menu set to the relevant Manager or HR group:

  1. Within the Admin Tool, select Security, Groups.

  2. Double-click the group.

  3. Use the Menu Set drop-down and select the required menu set (for example, Self Service (v3.2)).

  4. Next to the name, select the check box.

  5. Select the required role (for example, Self Service).

  6. Click OK.

📌 Note: The order in which the menu sets are selected determines the default menu set for all the users of that group, as long as no additional menu sets are added.


Assign Update & Delete permissions to the SelectHR folder

To allow managerial and HR users to upload to File Links anywhere in the system, follow these steps:

  1. Log in to the Administrator Tool.

  2. Click Document Store.

  3. On the left side panel, right click on the SelectHR Folder and select Properties.

    • Note: Click the padlock icon if the folder is shown as locked to unlock it.

  4. Click Add.

  5. Click the Type column header - this sorts all groups to the top of the list.

  6. Single click the relevant group, and click OK.

  7. Single click the group you just added to the list, and select Update & Delete.

  8. Click OK.


Assign different permissions to specific subfolders

To restrict which areas the managerial staff can upload, disable Inherit Permissions on specific folders, which allows you to set a specific permission list for that folder.

As an example, managers need to upload everywhere in the system except for Training History. Checking their permissions at the group level on the SelectHR folder, they can upload to the Training folder in File Links.

To remove this access and keep the permissions on the other folders, remove the permissions specific to the Training folder within the SelectHR folder:

  1. Within the Administrator Tool, click Document Store.

  2. To locate the subfolders within the SelectHR folder, on the left side panel, click the plus icon to the left of the SelectHR folder.

  3. Right-click the Training folder, and then click Properties.

    • Note: Click the padlock icon if the folder is shown as locked to unlock it.

  4. Clear Inherit Permissions and then click Yes to the prompt.

  5. Single click the Manager group, and then clear Update & Delete.

  6. Click OK.

The above is only an example of one folder, but the same can be applied to any folder in the document store if you require a specific permission assignment.

Did this answer your question?