This role would restrict admins to mange users only in "their" groups.
We will potentially have hundreds of users and many admins to manage different departments. We can create groups but it looks like Admins will be able to see all users. If there's an ability to have people view only those in their groups, that would make it useful for Admins to manage their departments.
Capabilites would include
- View the group(s) and manage members for groups that they're assigned as a Group Manager
- For Group Manager to be able to create, edit, delete and share launchers with members of managed Groups
- Restrict access to view, create, edit, delete campaign owned or created by members of their groups.
- No access to API (Administrator role only)
Another capability I would add is one to limit Admin email approval notifications to only come from collaborators in that group -- not from everyone in that workspace.
Thanks @loc that is highly valuable input.
Promoting this to our features board as we pursue the analysis.
Best,
David
David, attached is what I feel would be helpful. Another way to create this would be to have menu of permissions and when you add a person you can check what they can do vs. a blanket user role that has all these permissions. However, I feel that this might be hard to manage if you have a lot of users but it does have a lot of flexibility. I added another role called Approver--this is more like an attribute you can add to a collaborator or it could be a stand-alone as well.
Thanks for your input Loc.
This makes sense. For now permission levels for Admins vs Collaborator are account wide. We'll look into making this more granular in the future.
I would assume this requires a new role where an "Owner" of the account could initially create all groups, end then the Group Administrator could manage his own group?
Also could you please highlight the permissions you would need for that Group Administrator:
- Create new Users?
- Create new Groups?
- Edit Group name and description?
- Create sub Groups?
- Add members to Groups?
- Remove members from groups?
- Promote a member to a Group Administrator?
- Do you need permissions for Group Administrator to also manage Launcher or do you need it to be distinct?
Thank You!