General Question created by nathan1 6 years ago

We're having an issue with the roles of some users that are in multiple security groups. For example, when looking at the access tab for one of the users, edit, delete, list and view are all set to 'Group' access for most modules (which is what their access should be). This particular user is in a total of four security groups, and each group has different roles associated with it. For one of the roles for this user, edit, delete, list and view are set to 'Owner' access for a lot of the modules. When accessing the modules in Sugar, the user has 'Owner' access, instead of 'Group'. Could the multiple security groups be causing an issue with their access?

    Yes, there are a couple of settings that come into play here. Strict Rights and Additive Rights. In your case it sounds like the Owner access is only being applied for specific records. This would indicate that Strict Rights is turned on. What that means is that the rights will be applied for an individual record based on the actual groups assigned to the record. So the user's more restrictive, Owner access group is assigned to that record then instead of the more open Group access group.

    If that is not desired then you can either turn off Strict Rights or also assign one of the other groups to the record. It should then give the greatest rights of all records then (assuming Additive Rights is enabled).

