Extended Use Case
    • 6 Minutes to read
    • Dark
      Light

    Extended Use Case

    • Dark
      Light

    Article summary

    This article illustrates with an extended example how to organize product access and report rights via user management.


    Preface

    For our example, we focus on a department with two users:

    • User A: A product manager who requires access to specific product-related data from the German shop account (“Shop GER”). User A needs:

      • Access to Mapp Intelligence is limited to analyses in the “E-Commerce” section.

      • READ ONLY access to reports in the “Online Marketing Reports” category.

      • Full control over their private reports, including the ability to view, create, share, edit, and delete them.

    • User B: An online marketing manager who needs broader access. User B requires:

      • Full access to all analyses in Mapp Intelligence.

      • Full control over the “Online Marketing Reports” category, including viewing, creating, sharing, and editing/deleting reports.

      • Full control over their private reports.

    Key Concepts Introduced in this Article:

    • Private Reports: These are reports not assigned to any category. They remain visible only to the creator and administrators.

    • Categories: Categories determine which users can access specific reports and under what permissions (e.g., view-only, edit/delete).

    • Roles: Roles manage access rights for products, reports, and categories. A user’s permissions are determined by combining the rights of all roles assigned to them (max privilege principle).

    This guide walks through setting up the required roles and categories to fulfill these requirements.


    Step 1: Create users

    As a first step, the logins for User A and User B must be created.

    This is done at User Management > Users.

    Create two new users. Fill in the basic user information and - if desired - set a password expiration date. Do not assign any rules yet.


    Step 2: Manage product access with roles

    Roles have to be set up to manage access to Mapp products.

    This is done at User Management > Roles.

    As role rights are added up when a user is assigned to multiple roles, each role will cover only one specific aspect.

    To organize the product access, we have to create two roles - one for each user:

    • Role 1 (User A): Limits access to Mapp Intelligence to analyses from the section E-Commerce.

    • Role 2 (User B): Grants access to all analyses, that are available in Mapp Intelligence.

    Because both users must work with data from the German shop, the corresponding account, "Shop GER," has to be assigned to both roles.

    A) Setting up role 1 (User A)

    First, we create a role that limits product access to the E-Commerce analyses from Mapp Intelligence in the account "Shop.”

    1. Choose an appropriate name for the role and add a description.


    2. Assign the account "Shop GER" to the role.


    3. Select "Intelligence" as an accessible product in the account configuration.


    4. Assign User A to the role.


    5. In the rights management, set the slider to "Custom". Check only "E-Commerce" for top-level menu access.”

      This restricts access to the E-Commerce section of Mapp Intelligence. All analyses grouped there are available. Specific analyses can be selected or unselected via the second and—if necessary—third levels.


    6. Save the role.

      As only product access is managed with this role, report access can be left deactivated.

      Also, this user does not need to change custom metrics or formulas:

    B) Setting up role 2 (User B)

    The second role to be set up grants access to all analyses available in Mapp Intelligence for the account "Shop GER".

    1. Choose an appropriate name for the role and add a description.


    2. Assign the account "Shop GER" to the role.


    3. Select "Intelligence" in the account configuration.


    4. Assign User B to the role.


    5. In the rights management, set the slider for "Intelligence" to "Full".

      This grants complete access to all analyses available in Mapp Intelligence.

    6. Save the role.

      As only product access is managed with this role, report access can be left deactivated.


    Step 3: Manage report rights with roles and categories

    A) Setting up report categories

    Categories must be created to manage access to specific reports. This is done at User Management > Categories.

    For managing the access to Online Marketing Reports, a corresponding role "Online Marketing Reports" has to be set up: 

    Additional Information:

    • Categories assigned as view-only will appear greyed out in the interface and cannot be edited or assigned by the user.

    • Private reports are not assigned to any category and remain accessible only to the creator and users with “Full Access” rights to reports.

    • Users with Create permissions can assign their reports to accessible categories but cannot modify or remove categories assigned by others.

    • Users with Categorize permissions can manage categories, including assigning, editing, or deleting them.

    B) Setting up a role, that allows viewing, creating, sharing, and editing/deleting of private reports (User A and User B)

    This is done at User Management > Roles.

    Both users should be able to view, create, share, and edit/delete reports, that are not assigned to any report category (-> private reports). The rights for doing so are managed via a role, that is assigned to them.

    1. Choose an appropriate name for the role and add a description.


    2. Assign the account "Shop GER" to the role.


    3. Select "Intelligence"  in the account configuration.

      Even though access to Mapp products is managed via the roles created in Step 2, Intelligence has to be selected as an accessible product for this role, as access to the report section necessarily requires access to Mapp Intelligence.


    4. Assign User A and User B to the role.


    5. In the rights management, set the slider to "No".

      Explanation: Rights for accessing Mapp Intelligence analyses are managed via the roles created in Step 2. Therefore, this role should not grant additional menu access.


    6. Set Report access to Active and the Access level to Edit/Delete. Do not assign any categories.

      Result:

      • Users with this role can view, create, share, and edit/delete reports but cannot assign them to a report category.

      • These reports remain private and are only accessible by the users and administrators.


    7. Save the role.

    C) Setting up a role, that allows viewing the category "Online Marketing Reports" (User A)

    This is done at User Management > Roles.

    User A should have view-only access to reports in the “Online Marketing Reports” category.

    1. Choose an appropriate name for the role and add a description.


    2. Assign the account "Shop GER" to the role.


    3. Select "Intelligence"  in the account configuration.

      Even though access to Mapp products is managed via the roles created in Step 2, Intelligence has to be selected as an accessible product for this role, as access to the report section necessarily requires access to Mapp Intelligence.


    4. Assign User A to the role.


    5. In rights management, set the slider to “No” for menu access.

      Explanation: Rights for accessing Mapp Intelligence analyses are managed via the roles created in Step 2.


    6. Set Report access to Active and the Access level to View. Assign the category “Online Marketing Reports” to the role.

      Result:

      • User A can view reports in the assigned category.

      • Categories assigned as view-only will appear greyed out and cannot be modified or reassigned by User A.


    7. Save the role.

    D) Setting up a role that allows viewing, creating, sharing, and editing/deleting reports in the “Online Marketing Reports” category (User B)

    This is done at User Management > Roles.

    User B should have full access to reports in the “Online Marketing Reports” category.

    1. Choose an appropriate name for the role and add a description.


    2. Assign the account "Shop GER" to the role.


    3. Select "Intelligence" in the account configuration.

      Even though access to Mapp products is managed via the roles created in Step 2, Intelligence has to be selected as an accessible product for this role, as access to the report section necessarily requires access to Mapp Intelligence.


    4. Assign User B to the role.


    5. In rights management, set the slider to “No” for menu access.

      Explanation: Rights for accessing Mapp Intelligence analyses are managed via the roles created in Step 2.


    6. Set Report access to Active and the Access level to Edit/Delete. Assign the category “Online Marketing Reports” to the role.

      Result:

      • User B can view, create, share, and edit/delete reports in the assigned category.

      • User B can also manage the category itself if Categorize permissions are assigned.


    7. Save the role.


    Was this article helpful?


    ESC

    AI Assistant, facilitating knowledge discovery through conversational intelligence