Documentation

User Roles and Permissions

Table of Contents

Overview

QReserve utilizes a flexible Role-Based Access Control (RBAC) model to manage user capabilities.

It is important to note that the vast majority of your users will likely remain at the standard User level. The Roles and Permissions system described here is intended for a select few trusted super-users, managers, or administrators who require elevated privileges to manage resources or act on behalf of other users.

This system allows you to assign specific Roles to these trusted users (or groups) and, optionally, apply granular Restrictions to fine-tune exactly which resources or users they can interact with.

Primary Site Roles

QReserve has three primary site roles with the vast majority of users being assigned the User role and then, if necessary, augmented with additional secondary roles.

User

A User is the base level user role and will make up most site members.

Users can do the following:

  • Search and join sites;
  • View and reserve resources (with the appropriate permissions);
  • Search resources across QReserve's research network;
  • View a history of personal approvals, reservations, and training;
  • Edit their personal profile.

Moderator

A Moderator is the next level user role and can help with the management of sites.

Moderators can do everything Users can do plus the following:

  • Edit reservations of other users in the site;
  • Bypass certain reservation restrictions;
  • Access all reports in administration;
  • Manage site users;
  • Manage training records;
  • Manage resources.

Administrator

An Administrator is the highest level user role and has full control over sites.

Administrators can do everything Moderators can do plus the following:

  • Manage site integrations;
  • Manage site forms;
  • Manage site settings;
  • Manage site subscriptions;
  • Delete sites.

Secondary Roles

Core Concepts

To configure access effectively, it is helpful to understand the three layers of the system:

  1. Roles: A Role is a specific function or capability (e.g., "Reservation Editor" or "Maintenance Viewer").
  2. Permissions: Each Role contains a set of Permissions (e.g., "Can create reservations" or "Can view reports"). These are automatically included when you select a Role.
  3. Restrictions: A Restriction limits the scope of a Role. For example, you can give a user the "Reservation Editor" role (allowing them to book on behalf of others) but add a restriction so they can only manage bookings for a specific User Group.

How Permissions Combine

The system is additive.

  • If a user is assigned multiple roles (e.g., one assigned directly and one assigned via a User Group), they receive the combined capabilities of all assigned roles.
  • If a user has two roles—one with a restriction (e.g., "Manage Group A Only") and another with no restrictions (e.g., "Manage Everything")—the role with the broadest access takes precedence.

Available Secondary Roles

Roles are categorized by their function. Note that standard users implicitly have permission to manage their own reservations; the roles below are primarily for managing other users or site-level configurations. This list covers all currently available secondary roles.

Site User Roles

These roles delegate user administration without changing the user's primary site role.

Role Description
Site User Manager Allows the user to add, import, edit, deactivate, reactivate, and remove site users, and manage other users' membership in existing User Groups. Includes access to the site user and group lists and user management details. Does not allow changing primary site roles, assigning secondary roles, creating or editing User Groups, or changing the manager's own group memberships.
Site User Permission Editor Allows the user to add, change, and remove secondary roles and their restrictions for other individual site users. Does not allow changing their own secondary roles. Includes access to user, group, resource, and tag lists needed to configure roles. Requires Site User Manager. Does not allow changing primary site roles or the roles assigned to User Groups.
Test User Runner Allows the user to create bot and test users and log in as eligible test users in the site. Requires Site User Manager. Only test users with the primary User role can be assumed; portal test users cannot be assumed through this site role.

Site User Manager includes editing site-specific user details, such as notes, custom properties, account numbers, and billing addresses. Editing an account's name requires user-management authority in every site the account belongs to; editing its email also requires that the account has never logged in. Existing protections for Moderator and Administrator accounts still apply, including restrictions on removing or deactivating them.

Dependencies: Assign Site User Manager to the same user or User Group before assigning Site User Permission Editor or Test User Runner. Inheriting Site User Manager from another group does not satisfy a dependency for a role assigned directly to a user. Remove the dependent roles before removing Site User Manager.

Scope: All three site user roles apply across the site and do not support restrictions to particular users or User Groups. Assigning one to a User Group determines who receives the role; it does not limit which users they can manage.

Delegation: Site User Permission Editor can grant any available secondary role to other users, but cannot add, change, or remove their own roles. Test User Runner does not override this self-edit restriction. Site User Manager can place other users into existing groups that carry elevated roles. Test User Runner can create test users in those groups and use their inherited roles by logging in as them. Review the roles assigned to your groups when delegating user management or test-user access.

Administration Roles

These roles control how elevated users can administrate your site.

Role Description
Live Maps Editor Allows the principal to create, edit, and delete live maps in your site.

Report Roles

These roles control access to reports and actual usage records.

Role Description
Activity Report Runner Allows the user to access activity reports, including capacity and heat map reports.
Custom Report Runner Allows the user to view and run custom reports set up in your site, including access to report filters.
Actual Usage Editor Allows the user to view actual usage reports and create, edit, delete, and bulk import actual usage records.

Reservation Roles

These roles control how elevated users interact with bookings and resources.

Role Description
Admin Form Fields Editor Allows the user to fill out and edit custom form fields that are marked as "Administrator Only." Standard users cannot see or edit these fields.
Reservation Editor Allows the principal to create, edit, and delete reservations on behalf of other users. It grants the ability to view the full site user list to select a "Reserved For" owner.
Reservation Editor (No Transfer) Allows creating reservations and viewing, editing, and deleting reservations within the assigned scope. This role does not grant the ability to create reservations for other users or transfer a reservation to another user, and does not include access to the site user list. Other assigned roles can provide additional capabilities.
Reservation Viewer Strict read-only access. The user can view all details of reservations across the site but cannot make changes.
Reservation Forcer Allows the principal to bypass standard reservation restrictions (such as maximum duration limits, opening hours, or user quotas).
Template Editor Grants the ability to create, edit, and delete Template Reservations, which are often used for recurring setups or quick-add workflows.
Required Form Fields Skipper Allows the user to bypass form fields that are marked as "Required" during the booking process.

Maintenance Roles

These roles are specifically for managing downtime, repairs, or service logs.

Role Description
Maintenance Editor Allows the principal to create, edit, and delete maintenance bookings. Reservation access is not required.
Maintenance Viewer Read-only access to view maintenance logs and details.

Resource Roles

Role Description
Private Resource Files Viewer Allows the user to view resource files that are marked private. Can be restricted to specific resources or resource tags.

Synaccess Roles

These roles control access to Synaccess devices and power outlets.

Role Description
Synaccess Editor Allows the user to manage Synaccess devices and outlets.
Synaccess Reservable State Editor Allows the user to change the state of Synaccess outlets linked to resources. Can be restricted to specific resources or resource tags.

Using Restrictions

When assigning a role, you can leave it "Unrestricted" (access across the site) or apply a supported "Restriction" to limit the scope.

Note: Not all roles support restrictions and not all restrictions apply to all permissions within a role.

Multiple applicable restrictions combine with OR: matching any one is sufficient. For example, selecting both a User Group and a resource does not require a reservation to match both. Restrictions also do not narrow supporting access such as the full site user list included with Reservation Editor.

Restriction Types

Restrictions allow you to define whose reservations a manager can interact with or which resources their role applies to.

  1. Created by / Reserved for User:
    • The role applies only when the reservation was created by (or is reserved for) a specific individual.
  2. Created by / Reserved for User Group:
    • This is the most common configuration for team leads or department managers. It grants permission to manage reservations, but only if the reservation belongs to a member of a specific User Group.
  3. Resource:
    • The role applies to a specific resource.
  4. Resource tag:
    • The role applies to resources with a specific tag.

Reservation and maintenance roles support different combinations of these restrictions. Admin Form Fields Editor and Required Form Fields Skipper support creator and reserved-for restrictions; Template Editor supports creator and resource restrictions. Private Resource Files Viewer and Synaccess Reservable State Editor support resource restrictions only. Administration, report, site user, and Synaccess Editor roles do not support restrictions.

Configuration Examples

The following scenarios illustrate how to combine Roles and Restrictions for different organizational structures, whether in a corporate office, a research lab, or a shared facility.

Scenario 1: The Department Manager / Team Lead

Goal: A manager needs to be able to edit or move bookings made by their specific team members, but they should not have access to change bookings made by other departments.

  • Role: Reservation Editor
  • Restriction: Apply "Reserved for user in user group". Select the Manager's specific team/department group.
  • Result: The Manager can now edit/delete/move any booking belonging to their staff.

Scenario 2: The Executive Assistant

Goal: An assistant needs to place bookings on behalf of a Director, but does not need to manage the schedule for the rest of the company.

  • Role: Reservation Editor
  • Restriction: Apply "Reserved for user" and "Created by user" to the Director.
  • Result: The Assistant can log in and create and edit bookings listed for the Director and edit any reservations the director created.

Scenario 3: The Equipment Technician

Goal: This staff member is responsible for repairs. They need to block off resources for service so regular employees cannot book them, but they do not manage user schedules.

  • Role: Maintenance Editor
  • Role: Reservation Viewer (Optional, to see when resources are free)
  • Result: They can create maintenance blocks to prevent bookings during downtime.

Scenario 4: The Schedule Manager

Goal: Full access to manage all aspects of the schedule.

  • Configuration: Assign Reservation Editor, Maintenance Editor, Reservation Forcer, and Admin Form Fields Editor.
  • Restriction: None.

Scenario 5: The Site User Coordinator

Goal: A coordinator needs to onboard users, maintain their site details, and manage membership in existing groups.

  • Role: Site User Manager
  • Restriction: None; this role applies across the site.
  • Result: The coordinator can manage site users without becoming a Moderator. Add Site User Permission Editor if they also need to assign secondary roles, or Test User Runner if they need to create and log in as test users. Each additional role requires Site User Manager on the same user or User Group.

Best Practices: Using User Groups

While you can assign roles to individual users, we highly recommend assigning roles to User Groups whenever possible.

  1. Create a User Group (e.g., "Facility Managers", "Level 2 Techs", "Team A Leads").
  2. Assign the Roles and Restrictions to the Group.
  3. Add users to the Group.

The users will automatically inherit all roles assigned to the group. This ensures consistent permissions across your site and simplifies onboarding.