Security roles in Fusion are intentionally flexible to allow schools to create custom roles that suited their specific scenarios. This means, there is no concept of hierarchy, where one role is above or below another. Instead, users are able to perform tasks based on the role(s) they have been assigned. Previously, when a login belonged to a role that had the ‘Edit logins’ permission, when creating or editing logins they would be able to assign any of the existing roles to that login.

While this works for the vast majority of clients, where the school IT staff and/or the kitchen manager would be assigned as administrators and they would manage the logins, some schools wanted other users, such as supervisors, to be able to manage logins too. However, this caused a potential loophole where a user could be part of a role that had fairly limited permissions, but because it has the ‘Edit logins’ permission, they could make any logins an administrator, or even create a new login for themselves and make this account an administrator, circumventing the restrictions in place.

The process of allocating which roles can be assigned is the same as assigning which permissions a role has;

  1. Select the role from the list of roles
  2. On the right hand side of the screen, locate the ‘Can allocate these roles’ section
  3. Select the roles that this role can allocate when editing/creating logins
Last modified: 20 March 2023

Feedback

Was this helpful?

Yes No
You indicated this topic was not helpful to you ...
Could you please leave a comment telling us why? Thank you!
Thanks for your feedback.

Post your comment on this topic.

Please do not use this for support questions.
https://www.crbcunninghams.co.uk/support

Post Comment