In this help doc: how access to an account works — users, roles, and user groups, and how permissions are assigned.
User Management is where an account manages its internal team members and their access to the ViaSpaces platform. Access combines three things: roles define what a user may do, user groups apply roles and access to several users at once, and workspaces scope which documents a user sees. User Management is opened from Nastavenia.
Používatelia #
The Používatelia section manages the individual people in the account. Each user is invited by email and given roles, user groups, and workspaces that set what they can do and see.
Inviting a user #
Invite a user with Invite. The invitation sets the user’s access in steps:
- Enter the email address, and select user groups and roles.
- Optionally, select the workspaces, projects, and partners the user can access.
- Review and send the invitation.
The invited user accepts or rejects access to the account. Until they accept, they appear with an invited status.
The user list #
The Users tab lists everyone in the account with their email, name, roles, assigned workspaces, groups, and status (for example, Active or Inactive).
Managing users #
Each user can be viewed, edited, or deleted. Editing a user changes their roles, user groups, and workspaces, which changes their permissions and access across the account.
(screenshot: Users tab with the list and the Invite dialog)
User Groups #
User groups organize users into teams or departments, so permissions and access are managed for many people at once instead of one by one.
A group holds:
- Používatelia — the members of the group, who take on the group’s access.
- Roles — the permissions granted to the group.
- Workspaces — the workspaces the group can reach.
- Subgroups — other groups nested inside this group, for a layered structure.
- Optional Settings — custom permission filters that refine field-level access with a predicate.
(screenshot: Groups tab and the Add Group dialog)
Roles #
Roles are a fixed list. They are assigned to users and groups, and the Roles tab is an informational listing — each role with its description and the users and groups that hold it. Most roles follow a Contributor and Reader pattern: a Contributor creates and edits within an area, a Reader only views it. A role can include other roles, inheriting their permissions.
| Role | What it allows |
|---|---|
| Administrator | Everything. Access to every module and feature in the account, including account information. |
| Security.Administrator | Full access to Workspaces and User Management. At least one user must always hold this role. |
| Accounting.Manager | Full access to Accounting, plus read access to documents and master data. |
| Document.Contributor | Create and edit documents: Create New Document, Document Editor, Documents, Upload Document, Dashboard, and the Bin (excluding permanent delete). Includes read access to master data. |
| Document.Reader | View documents only. Home (excluding Invitations) and Dashboard (excluding New Document, Upload Document, and Export). Drafts appear in the list but not in the Document Editor. |
| MasterData.BusinessPartner.Contributor | Create and edit business partners, send registration links, and manage Home Invitations. |
| MasterData.BusinessPartner.Reader | View business partners only. |
| MasterData.Item.Contributor | Create and edit Items in Master Data. |
| MasterData.Item.Reader | View Items only. |
| MasterData.Project.Contributor | Create and edit Projects in Master Data. |
| MasterData.Project.Reader | View Projects only. |
| Template.Administrator | Full access to Templates. |
| User | The base role. My Reminders, Reminders, personal notification settings, and Leave Feedback. Every role includes it. |
Note: Roles are informational here — they are viewed and assigned, not edited. The list of roles is fixed.
(screenshot: Roles tab listing each role with its users and groups)
Workspaces #
A workspace is an access boundary inside the account: users and groups assigned to a workspace see the documents assigned to it. Workspaces let each team work with only its own documents, and they are shared with partners when a business card is accepted. Creating and managing workspaces is covered on the Workspaces page.
Reporting Access #
Editing a user, group, or role changes access across the account. A user’s roles, groups, and workspaces are shown on their record, so it is possible to see who has access to what.