A user's role decides what they can do. Their assigned environments decide what they can see. This article covers the second.
Why this is separate
Audit data is not uniformly sensitive. An HR environment and a logistics environment may both be connected to EaseLog while needing very different audiences.
Assigning environments per user lets you give somebody the audit data they need without giving them all of it.
Assign environments
When inviting a user, the panel shows two lists:
List Contains Assigned Environments The environments this user will be able to see. Unassigned Environments Everything else.
Figure 1. The Invite New User panel, showing Name, Email Address, the Role dropdown, and the Assigned and Unassigned Environments lists used to grant per environment access.
Select the add control on an environment in Unassigned Environments to move it across.
A new invitation starts with No environments assigned yet, so you grant access deliberately rather than by default.
What an unassigned environment means for that user
They do not see it. It is absent from their Environments page, from the Environment picker on the Dashboard, and from their Recently Viewed list. Its audit data is not theirs to read.
Deciding what to assign
Ask what the person's job actually requires.
- A compliance colleague investigating one business area needs that area's environments, not every one.
- An administrator maintaining connections generally needs the environments they maintain.
- Somebody auditing the whole organisation may legitimately need all of them.
Assign what the role requires and no more. It is easy to add an environment later, and awkward to explain why somebody had access to audit data they had no reason to see.
Changing assignments later
Environment assignments are not fixed at invitation. You can change them afterwards from the Users & Roles page.
Review them when somebody changes team or leaves a project. Access granted for one piece of work has a way of outliving it.
Note
An Admin still only administers the environments assigned to them. The role sets the depth of access, the assignments set the breadth.