Managing Role Administration (Device Access) for Business Apps

Before you begin

You must configure Device Access in addition to Console Access. For more information about Console Access, see Creating and Managing Users Within Roles.

About this task

Business apps require users to sign into their devices when opening the application. The business app logs the user's activities with their validated account to ensure that actions such as approvals belong to the user.

Screenshot of Device Access page

Managing Roles

About this task

The Device Access tab's Roles sub-panel displays the available roles to which you can assign visibility for private app components. Each role can contain any number (including 0) of device users and device user groups. Each role has a set of SOTI Snap permissions for each of the private app components. By default, there is always an Admin role that SOTI Snap automatically assigns to all new app components. You can not edit or delete this role.

Device Access: Roless

From the Device Access tab's Roles sub-panel, you can:

  1. Select New Role to create a new role, see Creating a New Role for details.
  2. For a created role, you can select to:
    • Edit the role's name.
    • Duplicate the role and its permissions. (The role's member users and groups are not duplicated.)
    • Delete the role. You must confirm the deletion.
  3. For a role, select the role to access it's Users, Groups or Permissions sections.
    Important: When you make any changes to a role, it is immediately reflected in the device's SOTI Snap Device Agent.
    • Users: Displays all the device users for this role. For any user, select to:
      • Assign a role. Select Assign Role to configure the all the roles this user is a member of. This includes the current role.
      • Remove a user. Select Remove User to remove the current user from this role.
    • Groups: Displays all groups of device users for this role. For any group, select to:
      • Assign a role. Select Assign Role to configure all the roles this group is a member of. This includes the current role.
      • Remove a group. Select Remove Group to remove the current group from this role.
    • Permissions: Displays this role's permissions to all existing app elements. You can customize this role's permission as needed. For more details, see Permissions.

Creating a New Role

About this task

When you create a new device access role, you must select its members (device users and device user groups) and customize it with relevant permissions. Once created, you can assign these roles to app components.

Procedure

  1. In the Role Details section, enter a name for the role in the Role Name field.
  2. Select Next.
  3. In the Permissions section, assign the role's respective permissions for all existing app components (app elements).
    • For form-based app components (Form, Workflow, AI Form Builder):

      • View: Role members can view submitted form records.
        • My Records: The role member can only view their own submitted form records.
        • Device Records: The role member can view all submitted form records from the device they are using.
        • You can also add and then select other filters. See Filtering & Sorting for more details.
        • If you enable more than one filter, you can choose the default filter from the Set as Default drop-down menu. The chosen filter is the one that SOTI Snap Device Agent automatically uses for the device user.
      • Create: Role members can fill in form details and submit form records.
      • Edit: Role members can edit a submitted form record.
      • Delete: Role members can delete a submitted form record.
    • For non-form-based app components (Page, Webpage):

      • View: Role members has visibility of the app element.
  4. For the Assign Users and Groups section:
    • For the Environment Type field, choose the publishing environment that you must publish in order for the role's member to receive the role's permission.
      • Production
      • Test
    • For the Assign Users field, select to add a new device user to this role.
    • For the Assign Groups field, select to add a new device group to this role.

What to do next

Assign the role to private app components or hamburger menu items with enabled Authentication. See Toggle the Roles That Can Access the App Component for details. Once assigned, the role's members (device users and device user groups) has visibility to them.

Managing Users

Adding Users to Device Access

About this task

To configure users for access to business apps, perform the following:

Procedure

  1. Open the Apps view, and beside the published app whose access you want to update, select More > Manage Access.
  2. In the Device Access tab, select Role Administration button, then select the Users sub-panel.
  3. Select the Assign User button. The Assign Users window opens.
  4. Go to the search field. Enter and select the name of the user(s) you wish to add.
  5. For the Role(s) dropdown menu, assign at least one role for the name(s) you added.
  6. Select Add.

Results

The added users are now present in the All App Users list.

Removing Users from Device Access

About this task

To remove user access to business apps, perform the following:

Procedure

  1. Open the Apps view, and beside the published app whose access you want to update, select More > Manage Access.
  2. In the Device Access tab, select Role Administration button, then the select Users sub-panel. A list of all app users appears in the panel to the right.
  3. Beside the name of the user you want to remove, select More. Select Remove User.
  4. In the Remove Selected User(s)? confirmation window, select Remove.

Results

From the All App Users list, SOTI Snap removes the user.

Managing Groups

Adding Groups to Device Access

About this task

To configure groups for access to business apps, perform the following:

Procedure

  1. Open the Apps view, and beside the published app whose access you want to update, select More > Manage Access.
  2. In the Device Access tab, select Role Administration button, then select the Groups sub-panel.
  3. Select the Assign Group button. The Assign Group window opens.
  4. Go to the search field. Enter and select the name of the group(s) you wish to add.
  5. For the Role(s) dropdown menu, assign at least one role for the name(s) you added.
  6. Select Add.

Results

The added groups are now present in the Directory Groups list.

Removing Groups from Device Access

About this task

To remove group access to business apps, perform the following:

Procedure

  1. Open the Apps view, and beside the published app whose access you want to update, select More > Manage Access.
  2. In the Device Access tab, select Role Administration button, then select Groups sub-panel. A list of all directory groups appears in the panel to the right.
  3. Beside the name of the group you want to remove, select More. Select Remove Group.
  4. In the Remove Selected Group(s)? confirmation window, select Remove.

Results

The group is now removed from the Directory Groups.