About access rights and privileges

2026-07-23Last updated

Access rights and privileges define what a user or user group can do within your system, and which parts of your system they have access to. Users are granted a basic set of access rights and privileges by the role they are assigned when their profile is created.

Access rights

Access rights control which partitions a user can access. They can be inherited from user groups, or replaced at the member (user or user group) level according to the following rules:
  • Access rights for partitions are inherited from parent user groups.
  • Inherited access rights can’t be revoked.
  • Access rights not granted to a user group can be granted to the members of the user group.
  • Granting access rights for a partition to a user or user group also grants access rights to its child partitions.
  • Revoking access rights for a parent partition from a user or user group also revokes access rights to its child partitions. An exception is when those access rights are inherited from parent user groups.
  • Revoking access rights for a child partition from a user or user group doesn’t revoke the access rights for its parent partition.

Privileges

Privileges control which actions a user can perform in the partitions they have access to. They can be inherited from user groups, or replaced at the member (user or user group) level according to the following rules:

  • A privilege that is allowed at the group level can be denied at the member level.
  • A privilege that is denied at the group level is automatically denied at the member level.
  • A privilege that is undefined at the group level can be allowed or denied at the member level.
  • When a user is a member of multiple user groups, the user inherits the most restrictive privilege settings. This means that Deny overrules Allow, and Allow overrules Undefined.
Note:
The default role privileges cannot be modified.

Privilege exceptions for partitions

Along with the privileges defined by their role or parent group, users also have a set of privileges for every partition in which they are an authorized user.

Privileges granted or denied at the partition level are considered exceptions and replace the basic privileges. They can be different for each partition the user has access to.
Note:
Only Administrative and Action privileges, plus the privileges over public tasks, can be overwritten at the partition level.

The manage partition memberships option

By default, only administrators can configure partitions. To allow a user to move entities from one partition to another, they must have access to both partitions. They must also have the associated Add/Delete <entities> privileges for each entity type they are moving.

If you don’t want to grant the full Add and Delete privileges to the user but still want to allow them to move entities between partitions, you can enable the Manage partition memberships option from the user's Advanced configuration page.

Privilege troubleshooter

To help you better understand what your users can do, Genetec™ Configuration desktop includes a Privilege troubleshooter. The Privilege troubleshooter is a tool that helps you investigate how user privileges and access rights are allocated in your system. With this tool, you can discover:
  • Who has permission to work with a selected entity
  • What privileges are granted to selected users or groups
  • Who has been granted a privilege, has access to a specific entity, or both

You can access this tool from the bottom of the Privileges page.