The access model
Access in Nobly Insight is controlled in layers, each answering a different question. Together they decide who can run the platform, who can work with which documents, and who can see individual sensitive records.A quick rule of thumb: application permissions are for administrators configuring the system; document access rights are for everyday users doing their work; security keywords narrow access to individual records on top of both.
Permissions are granted to user groups
Application permissions are always granted to user groups, never to individuals directly. A user’s effective permissions are the combination of everything granted to every group they belong to. To give one person a capability, add them to a group that has it — or grant the capability to a group they’re already in. This keeps access manageable: you reason about a handful of groups instead of every individual user, and membership changes take effect immediately.Permission tiers
Most permission areas come in tiers that build on each other:
Because the tiers are cumulative, you grant one tier per group for an area — granting Manage automatically gives that group View, and Admin gives both. Deleting is deliberately reserved for the Admin tier, so a group can be allowed to create and edit configuration without being able to delete it.
Where to read next
Application permissions
The full catalogue of permissions, grouped by area, and exactly what each tier grants.
Managing permissions
Grant and revoke permissions for user groups on the Permissions screen.
Single sign-on & federation
Sign in with your own identity provider over OpenID Connect, and drive Insight group membership from your directory.
